Free
$0
For anyone who pastes into AI.
- Secret detection and placeholders
- Made-up package warnings
- ChatGPT, Claude and Gemini
PasteGuard catches API keys, passwords and customer data the moment you paste them into ChatGPT, Claude or Gemini, and swaps them for placeholders. The AI gets the question. It never gets the secret.
Free for individuals. Launching on Chrome, Edge and Brave. No spam, one email when it's ready.
Demo: a developer pastes a .env file with a Stripe key and a database password into an AI chat. PasteGuard replaces both with placeholders before sending, then shows the real values again in the AI's answer on the developer's screen only.
77% of employees paste data into AI tools, mostly from personal accounts IT can't see.1
About four in ten AI conversations contain something sensitive.2
And when an AI made up a package called huggingface-cli, a researcher registered the name and it was downloaded over 30,000 times in three months.3
This is the same detection the extension runs. It happens in this tab. Nothing you type here is sent anywhere.
Nothing sensitive yet.
Ask an AI for a library and sometimes it names one that doesn't exist. Attackers watch for those names, publish malware under them, and wait for someone to run the install command. It's called slopsquatting.
PasteGuard checks every install command in an AI answer against npm and PyPI and marks the ones that don't exist or appeared last week.
Not to the AI. Not to us.
PG_SECRET_1.Some AI browser extensions have been caught copying people's chats.4 So PasteGuard is designed so it couldn't do that even if we wanted to.
Security questionnaires now ask which AI tools your staff use and how you stop data leaking into them. PasteGuard for teams gives you both answers.
Planned prices at launch. Early-access members get the first founding offer.
$0
For anyone who pastes into AI.
$4 a month
For developers with their own rules.
$4 per person a month
For companies that need proof. Free for up to 3 people.
Founding members: lifetime Pro for $49, limited to the first 200 people on the list.
The extension reads what you paste into AI chat sites so it can check it, the same way a spell checker reads what you type. The check happens on your device and nothing is sent to us. The team version reports which AI tool was used and when, never the content.
API keys for AWS, OpenAI, Anthropic, Stripe, GitHub, Slack and Google, private keys, JWTs, database passwords, values assigned to anything named like a secret, card numbers and email addresses. Pro lets you add your own patterns.
Yes. The AI sees PG_SECRET_1 where your key was and answers normally. On your screen the placeholder is shown as your real value again, so you can copy the answer and use it.
When an AI answer contains an install command, PasteGuard looks up each package on npm or PyPI. If it doesn't exist, or it was first published recently and hardly anyone uses it, you get a warning next to the command.
No. It's a browser extension, so it protects AI tools you use in Chrome, Edge or Brave.
Yes. Every warning has an option to send the original text, and you can allow a pattern so it stops asking.