Teams paste customer records into ChatGPT, read API keys aloud in recorded meetings, and share screens with credentials in view — not because they are careless, but because the tools moved faster than the guardrails. ShieldWays is the guardrail.
ShieldWays is browser-native data loss prevention for the AI workplace. A lightweight extension scans prompts, pastes, and uploads before they leave the browser, detecting PII, financial data, secrets and API keys, source code, and custom patterns — then redacts, blocks, or warns according to your policy.
All of that happens on your machine. No proxy, no network appliance, no managed-device requirement, and no copy of your content on our servers. What we do record is a content-free audit trail — type, action, domain, timestamp — so security and compliance teams can prove controls were enforced without collecting the data those controls protect.
Detection runs entirely on-device, inside the browser extension. There is no server-side scanning pipeline to trust, because there is nothing to send. Protection that depends on shipping your data somewhere else is not protection.
Our audit events record only the detection type, the action taken, the domain, and a timestamp. The sensitive content itself is never transmitted or stored — the backend discards content fields by design, so a breach of our systems cannot leak what we protect.
Compliance teams need evidence that controls were enforced. We give them exactly that — "PII blocked on chatgpt.com at 14:32" — without creating a second copy of the very data the control existed to protect.
Tier entitlements are signed server-side and fail closed to the free tier. Policies are signed and tamper-resistant, so users cannot quietly exempt themselves from controls their organisation set.
We are a small, independent team of engineers who have spent our careers building browser software and security tooling. We keep the company deliberately lean so the product can stay opinionated: on-device first, content-free always. If you want to talk to us — about the product, a deployment, or anything else — we read every message.