SURFACE 01 — THE HUMAN PROMPT · CONNECTED TIER

The paste is the perimeter.

A browser extension that checks employee submissions to ChatGPT, Claude, Gemini, Copilot, and Grok against policy before they reach the provider. The full prompt is evaluated over TLS and is not stored by the policy check. The coverage matrix below states exactly what is enforced today — per provider, per surface.

chat.provider.com — EMPLOYEE SESSION
summarize this excerpt from our airframe stress analysis: [ITAR-controlled technical data pasted here]
DENY Submission blocked before leaving the browser
policy: itar-cui-v41 · rule: configured_export_control_policy · receipt sha256:4be1…09f2 written
SUPPORTED WEB-AI SURFACES: CHATGPT · CLAUDE · GEMINI · COPILOT · GROK
Workplace photograph — the everyday boundary
PLATE P-08 — THE EVERYDAY BOUNDARY
AI Chat Firewall — inspect a supported prompt before submission. On a supported AI chat surface, an employee prompt is intercepted by the browser extension and checked over TLS against organizational policy before it reaches the AI provider. Allowed prompts reach the provider; violations are blocked with a reason shown to the employee. Only violation metadata is retained, not the full prompt. Managed pilots are available now.
FIG. A — INTERCEPTION AT THE BROWSER BOUNDARYCONTAINMENT.AI
FIG. 1 — ENFORCEMENT AT THE POINT OF USE
01
Real-time inspection
Text and pasted content on a supported surface are checked at submission time, before the AI provider receives them.
02
Immediate enforcement
Designed to block submissions that match your configured CUI, export-control, PII, or secrets policy before they reach the AI service, with a clear explanation to the employee.
03
Evidence as a byproduct
Every ruling writes an audit-ready, tamper-evident receipt — feeding the compliance program you already run.
FIG. 2 — THE DETECTION VOCABULARY

Policy needs words for what must not leave. These are ours.

EXPORT-CONTROL POLICY
organization-defined controlled-data rules
CUI
controlled unclassified information
HIPAA PHI
patient health information
SEC MNPI
material non-public information
PII
SSNs, identities, contact records
SECRETS & KEYS
API keys, tokens, credentials
SOURCE-CODE LEAKAGE
proprietary code & internals
PROMPT INJECTION
adversarial instruction patterns
Containment enforces the policy and detection configuration your organization supplies. It does not make export-classification determinations.
THE SAME DETECTORS RUN AT THE AGENT BOUNDARY — SEE AGENT GOVERNANCE.
FIG. 3 — PROVIDER COVERAGE MATRIX

Five providers, one enforcement path. Stated per surface.

PROVIDERENFORCED SURFACECOMPOSER INTERCEPTIONENFORCEMENTBROWSERS
ChatGPT chat.openai.com · chatgpt.com ProseMirror composer · Enter + send button BLOCK BEFORE SEND CHROME · FIREFOX
Claude claude.ai contenteditable composer · Enter + send button BLOCK BEFORE SEND CHROME · FIREFOX
Gemini gemini.google.com rich-textarea (Quill) composer · Enter + send button BLOCK BEFORE SEND CHROME · FIREFOX
Copilot copilot.microsoft.com textarea composer · Enter + send button BLOCK BEFORE SEND CHROME · FIREFOX
Grok grok.com (standalone app) textarea composer · Enter + send button BLOCK BEFORE SEND CHROME · FIREFOX
Typed and pasted content are evaluated together at submission time. Per-domain enforcement mode: block (default) or monitor — a violation allowed in monitor mode is logged.
Grok coverage is the standalone grok.com app; the x.com-embedded surface is out of scope. Additional internal domains are enforceable via policy-configured dynamic handlers.
Coverage is derived from the shipped extension’s per-provider content-script handlers · formal per-version test matrix: pending.
FIG. 4 — HOW A SUBMISSION IS RULED ON
STAGE 01
COMPOSER
typed + pasted content on a supported AI surface
STAGE 02
INTERCEPT
Enter key and send button captured before the request leaves the browser
DECISION
STAGE 03
EVALUATE
full prompt checked against policy over TLS · not stored by the check · fail-closed by default
STAGE 04
ENFORCE
allow, or block with a clear explanation · every ruling writes an audit receipt
RULING: ALLOW · BLOCK — DECIDED BEFORE THE PROVIDER RECEIVES THE PROMPT
FIG. 5 — HOW THE FIREWALL IS ENGAGED · MANAGED PILOT AVAILABLE

Start free today. Scale it managed.

CURRENT AVAILABILITY
A managed browser extension for AI chat governance — managed pilots can be scoped now.
✓ Supports ChatGPT, Claude, Gemini, Copilot, and Grok
✓ Fail-closed by default; an explicit per-domain fail-open choice is audited
✓ Free workspace: up to 15 users, prebuilt guardrails, 30-day audit history
Request a managed pilot