Paste anything into AI. Leak nothing.

PasteGuard catches API keys, passwords and customer data the moment you paste them into ChatGPT, Claude or Gemini, and swaps them for placeholders. The AI gets the question. It never gets the secret.

Free for individuals. Launching on Chrome, Edge and Brave. No spam, one email when it's ready.

Demo: a developer pastes a .env file with a Stripe key and a database password into an AI chat. PasteGuard replaces both with placeholders before sending, then shows the real values again in the AI's answer on the developer's screen only.

Why this exists

77% of employees paste data into AI tools, mostly from personal accounts IT can't see.1 About four in ten AI conversations contain something sensitive.2 And when an AI made up a package called huggingface-cli, a researcher registered the name and it was downloaded over 30,000 times in three months.3

Try it with a fake key.

This is the same detection the extension runs. It happens in this tab. Nothing you type here is sent anywhere.

What the AI receives

    

Nothing sensitive yet.

AI invents packages. Attackers register them.

Ask an AI for a library and sometimes it names one that doesn't exist. Attackers watch for those names, publish malware under them, and wait for someone to run the install command. It's called slopsquatting.

PasteGuard checks every install command in an AI answer against npm and PyPI and marks the ones that don't exist or appeared last week.

Registry

Your secrets never leave your laptop.

Not to the AI. Not to us.

Diagram: your clipboard passes through PasteGuard on your device. Secrets are replaced before the message reaches the AI. PasteGuard's servers receive nothing. Your browser Clipboard PasteGuard checks AI chat PasteGuard servers: nothing
  1. You paste. Anything: logs, a .env, a customer's email thread.
  2. PasteGuard checks it on your device. Keys, tokens, passwords, card numbers and emails get swapped for placeholders like PG_SECRET_1.
  3. The AI answers the question. Where it mentions a placeholder, your screen shows the real value again. The AI's copy of the chat keeps the placeholder.

Built to be trusted with your clipboard.

Some AI browser extensions have been caught copying people's chats.4 So PasteGuard is designed so it couldn't do that even if we wanted to.

Runs only on AI chat sites
It asks for access to the AI tools it protects, not to every site you visit.
Checks happen on your device
Detection is code inside the extension. It works with your Wi-Fi off.
Your prompts never reach our servers
The free version sends us nothing. The team version sends which AI tool was used and when, never what was typed.
Open source
The extension's code will be public on GitHub at launch, so anyone can check these claims.

Have an answer ready when a customer asks about AI.

Security questionnaires now ask which AI tools your staff use and how you stop data leaking into them. PasteGuard for teams gives you both answers.

  • Install it for everyone from Google Admin or Intune. It takes about 10 minutes.
  • See which AI tools and AI extensions your team actually uses.
  • Set rules per team: warn, swap for placeholders, or block.
  • Export an AI tool register and a monthly leak report for your auditor.

Join the team pilot

We're onboarding 20 teams, free until launch. We'll set it up with you on a 15-minute call.

Pricing

Planned prices at launch. Early-access members get the first founding offer.

Free

$0

For anyone who pastes into AI.

  • Secret detection and placeholders
  • Made-up package warnings
  • ChatGPT, Claude and Gemini
Get early access

Pro

$4 a month

For developers with their own rules.

  • Everything in Free
  • 40+ AI sites
  • Custom patterns for your company's keys
  • Sync rules across browsers
Get early access

Team

$4 per person a month

For companies that need proof. Free for up to 3 people.

  • Everything in Pro
  • Install for everyone from Google Admin or Intune
  • AI tool register and audit log
  • Monthly leak report for auditors
Join the team pilot

Founding members: lifetime Pro for $49, limited to the first 200 people on the list.

Questions

Can PasteGuard read my prompts?

The extension reads what you paste into AI chat sites so it can check it, the same way a spell checker reads what you type. The check happens on your device and nothing is sent to us. The team version reports which AI tool was used and when, never the content.

What does it detect?

API keys for AWS, OpenAI, Anthropic, Stripe, GitHub, Slack and Google, private keys, JWTs, database passwords, values assigned to anything named like a secret, card numbers and email addresses. Pro lets you add your own patterns.

Will the AI's answer still make sense?

Yes. The AI sees PG_SECRET_1 where your key was and answers normally. On your screen the placeholder is shown as your real value again, so you can copy the answer and use it.

How does the package check work?

When an AI answer contains an install command, PasteGuard looks up each package on npm or PyPI. If it doesn't exist, or it was first published recently and hardly anyone uses it, you get a warning next to the command.

Does it work in the ChatGPT or Claude desktop apps?

No. It's a browser extension, so it protects AI tools you use in Chrome, Edge or Brave.

Can I turn it off for one message?

Yes. Every warning has an option to send the original text, and you can allow a pattern so it stops asking.

Paste freely.