About ShieldWays

AI adoption is outpacing
data governance.

Teams paste customer records into ChatGPT, read API keys aloud in recorded meetings, and share screens with credentials in view — not because they are careless, but because the tools moved faster than the guardrails. ShieldWays is the guardrail.

What we build

ShieldWays is browser-native data loss prevention for the AI workplace. A lightweight extension scans prompts, pastes, and uploads before they leave the browser, detecting PII, financial data, secrets and API keys, source code, and custom patterns — then redacts, blocks, or warns according to your policy.

All of that happens on your machine. No proxy, no network appliance, no managed-device requirement, and no copy of your content on our servers. What we do record is a content-free audit trail — type, action, domain, timestamp — so security and compliance teams can prove controls were enforced without collecting the data those controls protect.

Founding principles

Privacy by architecture

Detection runs entirely on-device, inside the browser extension. There is no server-side scanning pipeline to trust, because there is nothing to send. Protection that depends on shipping your data somewhere else is not protection.

Content-free telemetry

Our audit events record only the detection type, the action taken, the domain, and a timestamp. The sensitive content itself is never transmitted or stored — the backend discards content fields by design, so a breach of our systems cannot leak what we protect.

Proof without a honeypot

Compliance teams need evidence that controls were enforced. We give them exactly that — "PII blocked on chatgpt.com at 14:32" — without creating a second copy of the very data the control existed to protect.

Fail closed, verify everything

Tier entitlements are signed server-side and fail closed to the free tier. Policies are signed and tamper-resistant, so users cannot quietly exempt themselves from controls their organisation set.

Who we are

We are a small, independent team of engineers who have spent our careers building browser software and security tooling. We keep the company deliberately lean so the product can stay opinionated: on-device first, content-free always. If you want to talk to us — about the product, a deployment, or anything else — we read every message.