Browser protection · Available now

Protection on the AI websites your team already uses.

Guard4AI Browser Protection is a Chrome extension. It checks messages on supported AI websites, including ChatGPT, Claude, Gemini and Copilot, before they are sent, swaps sensitive details for realistic stand-ins, and shows the real details in the reply.

Fourteen days free, then from $14 a month.Business plans add the team dashboard.

Twenty seconds on ChatGPT.

A name and a mobile number, caught in the browser before the message is sent, and put back in the reply.

chatgpt.com
YOU

Draft a reply to Emma WalshSarah Chen confirming Thursday at 2pm. Her mobile is 0498 111 2220412 345 678 if the time needs to move.

AI

Hi EmmaSarah, Thursday at 2pm works — I’ve got it in the diary. If anything changes before then I’ll give you a call on 0498 111 2220412 345 678. See you then.

Show real dataShow what AI sees
Draft a reply to Sarah ChenEmma Walsh confirming Thursday at 2pm. Her mobile is 0412 345 6780498 111 222 if the time needs to move.
0:00 / 0:20

You hit send and Guard4AI stops the message inside your browser. It shows what it caught and why it matters, and swaps each value for a realistic stand-in. Nothing has left the page yet.

Protects more than names and numbers Guard4AI can detect 25 types of sensitive information before it reaches AI. Names Phone numbers Emails Bank details Passwords +20 more View all 25 Hide the list

The two the story used are lit.

For teams: one invite code.

Business plans connect every employee’s browser with one invite code, no logins. Choose the protection settings and lock them on, then see which kinds of sensitive information are caught and which AI tools are used. Never a prompt, and never an original value.

Team controls · available now

The dashboard, the rollout and exactly what an admin can and cannot see, in detail.

Browser protection questions

Yes. Fourteen days on any plan. You enter a card to start and it is not charged until day fifteen, so cancelling before then costs nothing. Cancel from your account under Manage billing, which opens Stripe’s portal. The full breakdown is on the pricing page.

Pattern matching, not a language model. Guard4AI knows the shape of a Medicare number, a TFN, a BSB, a card number and an email address, and it carries a large list of given and family names for spotting people. Your text is never sent to a model, ours or anyone else’s, to work out what is in it. That is what makes the local claim possible: there is no inference step to send it to.

Yes. Each real value gets one stand-in and keeps it. Sarah Chen is Emma Walsh in the first message and in the fortieth, and, in the browser extension, in next week’s conversation too, because the pairing is remembered on your device until you clear it. In the desktop workspace the pairing is kept per conversation, encrypted on the Mac. The AI sees a consistent person, so the conversation reads normally and follow-up questions work. Stand-ins are chosen to match too, so a name is replaced by a name of the same kind rather than something that reads as a placeholder.

The supported websites are ChatGPT, Claude, Gemini, Copilot, Grok, Perplexity, DeepSeek, Mistral, Le Chat, Meta AI, Poe, Qwen, HuggingChat, Character.AI, Cohere, Groq, Inflection, Pi, Phind, You.com, Jasper, Copy.ai, Rytr, Writesonic and Use.ai, and we add new ones as they launch. Guard4AI is a browser extension, so it covers those sites in your browser. The ChatGPT and Claude desktop apps run outside the browser, and outside Guard4AI.

PDFs, Word documents (.docx), and plain text, CSV, TSV, Markdown and log files, up to 30 MB each. Screenshots and photos in PNG, JPEG and WebP are read with text recognition, up to 24 megapixels.

Excel, PowerPoint, legacy .doc, Pages, Numbers, Keynote and archives are not read yet, and neither is a scanned PDF with no text layer or an iPhone HEIC photo.

Until then they are not a blind spot. Guard4AI stops the attachment and names the file for what it is, as in “Excel spreadsheet”, and tells you it has not been checked. Nothing goes up until you choose to send it, so you get to look at the file yourself first. A file Guard4AI cannot read is unchecked, not safe, and it never lets one look like a file that came back clean.

Guard4AI holds it, reads it, and decides. It stops the file for a narrow set: passwords and API keys, card numbers, BSBs and account numbers, tax file numbers, Medicare numbers, passports and licence numbers — the things that are never deliberately in a document you meant to share.

Names, addresses, phone numbers and health or legal wording are counted and shown to you, not blocked. A twenty-page contract has hundreds of them, and a warning that fires on every attachment gets clicked without reading.

For a document that reads as prose, Guard4AI can offer to send the text instead — masked the same way a typed message is, with the reply unmasked as usual. It only offers that when the extraction genuinely reads; forms, table grids and shuffled columns are refused rather than pasted as fragments.

Attach several files at once and they are decided together: if one is stopped, none are attached, and letting them through lets all of them through.

No. The file is read inside an isolated frame in your own browser, using libraries that ship with the extension. Nothing is uploaded and nothing is fetched. The bytes and the extracted text never leave that frame — the only thing that comes back out is a count per category.

On a workplace plan a stopped file adds to the same tally a typed message does: the category and the count. Never the value, the filename, or a word of the text.

No, and it never says it has. Text recognition reads what it can see, which is less than you can, so an image never gets a clean bill of health. If it finds something, it stops and waits. If it reads an image and finds nothing, it attaches it with a notice saying exactly that. If it cannot read the image properly, it stops and tells you so. Those three outcomes are worded differently on purpose.

From the desktop workspace: nothing. From the browser extension, your messages: nothing, ever. Detection runs in your browser, and the masking table lives on your device, so you can clear it whenever you want. What we do hold: your email and billing record if you create an account, and on a team plan the first and last name someone gives when they activate, a tally of catches by category and AI tool, which tools were used, and the broad type and outcome of files attached. Never the value, never the message, never a filename. On a personal licence, none of the team data exists at all. The privacy policy lists all of it.

Add browser protection to Chrome.

Looking for the secure AI workspace?