PII protection for every AI

Stop your team leaking

into AI.

Personal data in your team's prompts and documents becomes tokens like [EMAIL_1] before it reaches any AI, then it's restored in the reply. The model never sees raw data. Neither do we.

No card · 7-day free trial · nothing sensitive ever stored

Live · watch the shield redact in real time
1 · Your team types
Sarah Chen
sarah@acme.com
+1 415 555 0132
card 4111 1111 1111 1111
IBAN GB29 NWBK 6016 1331 9268 19
2 · What the AI sees
[PERSON_1]
[EMAIL_1]
[PHONE_1]
card [CARD_1]
IBAN [IBAN_1]
3 · The reply comes back with the real values restored automatically - your team never sees a token.

Works everywhere

One shield. Every AI.

Every major model and chat tool, through one engine.

Claude ChatGPT Gemini Kimi Mistral Grok DeepSeek Groq Perplexity Llama Cohere

Six ways in

Switch it on in minutes.

Pick your model, copy the config, you're protected. The same redaction engine sits behind every route.

01 · Gateway

One base-URL change

Point any app, SDK or OpenAI-compatible CLI at the shield with your own provider key. It redacts, forwards to Claude, and restores the reply. BYOK or fully managed. Claude Code uses the plugin instead - card 06.

02 · Browser extension

Paste one key

Paste your workspace key into the popup once - no gateway or provider setup - and the shield works right inside the AI you already use.

  • Masks what you type in the chat box before you hit send, and restores the real reply in place
  • Redacts whole documents before you upload them
  • Works across Claude, ChatGPT, Gemini, Grok, DeepSeek, Copilot and more
Add to Chrome
03 · MCP server

One command

Add the shield to Claude as a connector. Any agent gets redact, detect_pii + coverage tools, on demand from chat. Tools you call - use the gateway or the plugin to redact automatically.

04 · Document redaction

Files, format-preserving

Drop in a document - the shield strips PII and hands back the same file, layout intact. Scanned pages and images are read with OCR.

WordExcelPowerPointPDFImages · OCR
Redact a document
05 · Hosted connector

Your own systems, nothing to install

Everything above needs a config file on somebody's machine. This does not. Add your ATS, CRM or helpdesk in your dashboard and we hand you one web address to paste into Claude's Connectors screen. Claude talks to the shield; the shield talks to your system - so the records that come back are already [PERSON_1], and a token Claude sends back becomes the real value again on the way out, so lookups still work.

  • Connect several systems and they arrive through one address, sharing one set of tokens - the same person is the same token everywhere
  • Sign in with OAuth where the vendor supports it, so there is no key to go hunting for
  • Works in claude.ai in the browser and in the desktop app. No developer, no config file
NotionLinearSlackJiraYour ATS
See how it works
06 · Claude Code plugin

Local hooks, no key in flight

Claude Code must not go through the gateway - on a subscription it would send your claude.ai account token to it. The plugin redacts tool output on your machine before Claude sees it, and restores the real values before Claude writes to disk. Prompts and @-mentions containing PII are blocked, because Claude Code does not let a hook rewrite a prompt.

claude plugin marketplace add aerynquarmby/pii-shield-plugin
claude plugin install pii-shield@piishield
0
models supported
0
PII types + custom
0
bytes of PII we can read
0
ways to integrate
New · Flagship

See what's already leaked.

Leak Audit looks backwards - showing management exactly what personal data employees have already pasted into AI, per seat - encrypted to a key only your workspace holds. Then a daily monitor keeps watch automatically.

  • Per-seat breakdown - who leaked what, and how often, by PII type.
  • Encrypted per-tenant - values are sealed with AES-256-GCM; optional tenant-held end-to-end keys mean even PII Shield can't read them.
  • Reveal is owner/admin-only and every reveal is written to an audit log.
  • Automatic daily scan - Enterprise uses Anthropic's Compliance API; every plan can use the extension's history scan.

Zero-trust by design

We never see your data.

A shield nobody on the outside can see through - including us. Self-host it in your own cloud and we have zero operator access at all.

Never stored · never seen
  • Your prompts, messages or documents
  • Raw personal data we could read - names, emails, IDs, cards, IBANs, IPs (Leak Audit keeps only ciphertext sealed to your key)
  • The token↔value map (in memory for the request, then gone, unless you switch on restoring redacted documents - then it is sealed to your key and we still cannot read it)
All we keep
  • Counts of PII masked, by type - logs are counts-only
  • Timestamp, model, status - for usage & billing
  • Encrypted at rest with AES-256-GCM; self-host for full isolation
AES-256-GCM Self-host · zero operator access GDPR / CCPA-aligned Pursuing ISO 27001 / SOC 2

Built for organisations

One shield, every level.

From the whole platform down to a single seat - everyone sees exactly what they should, and nothing they shouldn't.

Operator

Cross-tenant health

The platform view: fleet-wide status and usage across every company - counts only, never a byte of PII.

Corporate · tenant

Your own dashboard

Each company is an isolated tenant with its own seats, coverage rules, custom terms, billing and Leak Audit.

Employee · seat

Scoped view

Every seat gets its own key and a view scoped to just their own activity - protected the moment they start typing.

Simple pricing

A fraction of your AI bill.

Pick a term and your seats - see exactly what you'll pay. Longer commitments save more. You keep your own model billing; you only pay for the shield.

Free trial
$0
250 requests or 7 days
3 connected systems
whichever ends first
Starter
$19/mo
100,000 requests / mo
10 connected systems
Team per seat
$50/mo
5 seats · 1,000,000 req/mo · $10/seat
25 connected systems
5seats
Enterprise
Custom
unlimited · self-hosted · SSO
unlimited connected systems

Every surface is on every plan — gateway, extension, MCP, connectors, documents and the CLI plugin. A plan buys requests and how many of your own systems you can connect, not features.

Prefer usage-based? ~$0.90 per 1,000 requests.

Ready in a day

Give your team AI
without giving away your data.

Create a free workspace, get your key, and shield every AI your team touches.

Start free