ContextShield · Managed extension · Chrome and Edge

Your people keep going. The identifiers stop here.

Detection as it is typed into ChatGPT and Gemini. Local substitution with realistic synthetic data. Local restore in the reply. No vendor server in the data path.

Employee workstation
Detectors0 / 6
Received by the platform
Processing
The module above runs in the page, with no network call
How it works

Blocking AI never worked. Working around it did.

Conventional approaches either cut access or log the incident after the fact. Either way the employee under pressure opens the platform on a phone, and the information leaves anyway, this time outside your visibility.

ContextShield takes the problem from the other end. The work continues. Detection and substitution happen in the browser, before anything is sent.

Detection as you type

Analysis happens entirely on the workstation. No text is sent to a classification service, so no third party sees what the employee writes.

Synthetic substitution

A SIN becomes another plausible SIN, valid under Luhn. The model still understands the request.

Local restore

Original values return in the reply, on the workstation, with no round trip to a vendor.

Native coverage

Recognized with no configuration

Two platforms only, ChatGPT and Gemini. That is deliberate. We cover what we can demonstrate in front of your team.

EMAILDOMAINUSERURLFQDNIPv4IPv6PHONENAS / SINSSNCREDIT CARDCARD EXPIRYCVVPINBANK ROUTINGACCOUNT NUMBERSWIFTTAX_IDPASSPORTADRESSE CAAPI KEYPASSWORDDEVICE_ID

Any identifier outside this list falls under a customization module, priced case by case.

Deployment

Pushed by your fleet, not by us

The extension ships from the management tooling you already run. No vendor console to learn, no accounts to provision, no tunnel to open. Policy stays centralized on your side.

Microsoft Intune

Standard forced-install policy, no custom package.

GPO / Active Directory

Entry added directly to your existing GPO by your own IT team.

Jamf

Same managed policy model for macOS endpoints.

What your team does not have to do
No packageNothing to build or recompile
No serverNothing to host on the vendor side
No agentNothing installed outside the browser
No accountsNothing to provision seat by seat

The reporting dashboard, if adopted, is hosted on a server you own.

Demonstration

The same thing, filmed with no cuts

Thirty-six seconds. Typing, detection, substitution, send, reply, restore. No edit between the steps.

chatgpt.com
What this is not

We would rather tell you before your assessment

A vendor promising compliance puts you at fault. Here are the real boundaries, written so your privacy officer can quote them as is.

  • Legal classificationPseudonymization is reversible. Under Law 25 the data remains personal information. Exposure is reduced, the classification does not change.
  • ComplianceNo tool makes an organization compliant. ContextShield supports your obligations and documents a reasonable measure. Compliance remains yours.
  • PerimeterManaged browser only, on ChatGPT and Gemini. A personal device outside the fleet stays out of coverage.
  • Sector identifiersA format specific to your sector requires a dedicated customization module.
In production
Deployed across 50 seats at a Montreal para public institution.
Deployed through Microsoft Intune · 11 month term
Organization named on written authorization
Get in touch

A twenty minute walkthrough, on your own cases

Write to us with your context. We reply with an honest read of what the tool covers in your environment and what it does not.

communication@contextsecurity.ca
Context Security Inc. · Quebec, CanadaContextShield · Chrome and Edge