Guard4AI checks what you type into AI tools and catches sensitive details before they’re sent, so your team keeps the speed of AI without losing control of the data. It all happens on your own device; your text never reaches us.
Draft a payment confirmation for customer Sarah Chen. Her card number is 4950 4762 9042 6166 and her mobile is 0412 345 678.
Works on the AI tools you already use
New platforms are added as they launch
Staff adopted it faster than most businesses could put controls around it. Guard4AI adds a practical control around how it is used, without taking the speed away.
say their workplace has a policy or guidance for it
KPMG × University of Melbourne 2025 · globalGuard4AI checks for sensitive information before a prompt is sent, so staff can keep using the AI tools that make them productive.
Why Guard4AI →Protection that follows the employee.
Your approved enterprise AI account provides valuable controls. But those controls don’t automatically follow your team into other AI tools or personal accounts.
Guard4AI adds protection across supported AI websites.
Example company setup.
Details it detects and can replace are swapped for realistic stand-ins on the device. Other detected information is flagged for review before anything is sent.
Alongside your enterprise AI account, not instead of it. See how it works Review security & data handling
One message, start to finish. The AI gets a convincing fake; you read a normal answer wearing your real details.
Draft a reply to Emma WalshSarah Chen confirming Thursday at 2pm. Her mobile is 0498 111 2220412 345 678 if the time needs to move.
Hi EmmaSarah, Thursday at 2pm works — I’ve got it in the diary. If anything changes before then I’ll give you a call on 0498 111 2220412 345 678. See you then.
Show real dataShow what AI seesYou hit send and Guard4AI stops the message inside your browser. It shows what it caught and why it matters, and swaps each value for a realistic stand-in. Nothing has left the page yet.
You write your message as normal. Without protection, customer names, card numbers and mobile numbers could be sent directly to the AI.
Draft a payment confirmation for customer Sarah Chen. Her card number is 4950 4762 9042 6166 and her mobile is 0412 345 678.
Before the message reaches the AI, Guard4AI automatically swaps sensitive details for realistic replacements. It happens instantly in the background. Nothing changes about how you work.
Draft a payment confirmation for customer Emma WalshSarah Chen. Her card number is 4318 5502 7761 02844950 4762 9042 6166 and her mobile is 0498 111 2220412 345 678.
The AI replies using the realistic replacements. Guard4AI restores the real details only on your screen, so the response is ready to use. The AI never sees the originals.
Hi Emma WalshSarah Chen, your payment using card 4318 5502 7761 02844950 4762 9042 6166 has been confirmed. We’ll contact you on 0498 111 2220412 345 678 if anything changes.
The two the story used are lit.
Text you type or paste into 28 AI sites in your browser, including ChatGPT, Claude, Gemini and Copilot.
Files and images you attach. PDFs, Word documents, and text, CSV and Markdown files are read before they upload. Screenshots are read with text recognition. All of it happens on your own device.
The answer comes back with your real details in place. The AI only ever had the stand-ins; the swap back happens on your screen, so the reply is ready to use as it is.
Anything Guard4AI cannot read is stopped and named as unchecked, never dressed up as clean. You always know what it saw and what it did not, which is the part most tools leave you guessing at.
Choose how Guard4AI handles sensitive information.
Names, phone numbers, emails, addresses, Medicare numbers, TFNs, passwords and more.
Highlight anything the detector missed and mask it yourself. You decide what gets protected.
Once a message reaches ChatGPT, Claude or Gemini, it has left your immediate control. Guard4AI does its reading first, inside your browser. Your message text never reaches us: no server of ours processes it, no copy of a conversation exists on our side, and there is nothing for us to hand over. Not won't. Can't. The message itself still goes to the AI tool, because that is what sending it means; what changes is that the sensitive parts have been replaced before it does. A team plan sends tallies and a name: the name someone enters when they activate, the category of each catch and which tool it happened on, which tools were used, and the broad type and outcome of files attached. Never a value, never a message, never a filename. The privacy policy lists every byte.
One invite code covers every browser, and a dashboard shows what is being caught: who, how much, what kind, and on which AI tool. Never the words.
Yes. Fourteen days on any plan. You enter a card to start and it is not charged until day fifteen, so cancelling before then costs nothing. Cancel from your account under Manage billing, which opens Stripe’s portal. The full breakdown is on the pricing page.
Pattern matching, not a language model. Guard4AI knows the shape of a Medicare number, a TFN, a BSB, a card number and an email address, and it carries a large list of given and family names for spotting people. Your text is never sent to a model, ours or anyone else’s, to work out what is in it. That is what makes the local claim possible: there is no inference step to send it to.
Yes. Each real value gets one stand-in and keeps it. Sarah Chen is Emma Walsh in the first message and in the fortieth, and in next week’s conversation too, because the pairing is remembered on your device until you clear it. The AI sees a consistent person, so the conversation reads normally and follow-up questions work. Stand-ins are chosen to match too, so a name is replaced by a name of the same kind rather than something that reads as a placeholder.
Twenty-eight sites, including ChatGPT, Claude, Gemini, Copilot, Perplexity, Grok, DeepSeek and Mistral, and we add new ones as they launch. Guard4AI is a browser extension, so it covers those sites in your browser. The ChatGPT and Claude desktop apps run outside the browser, and outside Guard4AI.
PDFs, Word documents (.docx), and plain text, CSV, TSV, Markdown and log files, up to 30 MB each. Screenshots and photos in PNG, JPEG and WebP are read with text recognition, up to 24 megapixels.
Excel, PowerPoint, legacy .doc, Pages, Numbers, Keynote and archives are not read yet, and neither is a scanned PDF with no text layer or an iPhone HEIC photo. Spreadsheet and slide deck support is coming soon.
Until then they are not a blind spot. Guard4AI stops the attachment and names the file for what it is, as in “Excel spreadsheet”, and tells you it has not been checked. Nothing goes up until you choose to send it, so you get to look at the file yourself first. A file Guard4AI cannot read is unchecked, not safe, and it never lets one look like a file that came back clean.
Guard4AI holds it, reads it, and decides. It stops the file for a narrow set: passwords and API keys, card numbers, BSBs and account numbers, tax file numbers, Medicare numbers, passports and licence numbers — the things that are never deliberately in a document you meant to share.
Names, addresses, phone numbers and health or legal wording are counted and shown to you, not blocked. A twenty-page contract has hundreds of them, and a warning that fires on every attachment gets clicked without reading.
For a document that reads as prose, Guard4AI can offer to send the text instead — masked the same way a typed message is, with the reply unmasked as usual. It only offers that when the extraction genuinely reads; forms, table grids and shuffled columns are refused rather than pasted as fragments.
Attach several files at once and they are decided together: if one is stopped, none are attached, and letting them through lets all of them through.
No. The file is read inside an isolated frame in your own browser, using libraries that ship with the extension. Nothing is uploaded and nothing is fetched. The bytes and the extracted text never leave that frame — the only thing that comes back out is a count per category.
On a workplace plan a stopped file adds to the same tally a typed message does: the category and the count. Never the value, the filename, or a word of the text.
No, and it never says it has. Text recognition reads what it can see, which is less than you can, so an image never gets a clean bill of health. If it finds something, it stops and waits. If it reads an image and finds nothing, it attaches it with a notice saying exactly that. If it cannot read the image properly, it stops and tells you so. Those three outcomes are worded differently on purpose.
Your messages: nothing, ever. Detection runs in your browser, and the masking table lives on your device, so you can clear it whenever you want. What we do hold: your email and billing record if you create an account, and on a team plan the first and last name someone gives when they activate, a tally of catches by category and AI tool, which tools were used, and the broad type and outcome of files attached. Never the value, never the message, never a filename. On a personal licence, none of the team data exists at all. The privacy policy lists all of it.