All ByteVerity trials Shadow AI · Browser Runtime

Govern the AI your employees already use

Shadow AI is a disclosure event at the moment of send — a pasted screenshot, a contract uploaded as a file, a spreadsheet of customers, source code, on a personal or free account whose terms let the provider train on it. You can't see it at the firewall. You govern it in the browser, at the release boundary, reading what actually leaves.

⬇ Download the demo package Install & use guide

The package is the managed Chrome/Edge extension + test files + offline verify tools. The guide opens in your browser — install unpacked and run the four moves below in ~10 minutes.

What the Browser Runtime does

Composer governance. Captures the prompt before submit, holds it for a verdict, releases it with sensitive fields tokenized / redacted / glossed — fail-closed.
Upload & attachment governance. Captures files before they leave; blocks crown-jewel documents by exact fingerprint so the bytes never leave the device.
Reads content, not filenames. Inspects inside PDF / Word / Excel / email, with OCR for scans and image/audio on the same plane.
Detects what matters. Secrets & API keys, PII / PCI / PHI, prompt-injection, and source code classed by disclosure tier.
Account hygiene & fleet discovery. Flags risky personal / free-tier accounts and maps which AI tools are in use across the fleet.
Proven by receipts. Every interaction yields a signed, offline-verifiable receipt of hashes and decisions — never raw content.

See it in four moves

  1. Paste a prompt containing an SSN into a web assistant → watch it tokenized in the composer before it's sent.
  2. Drag a designated crown-jewel document into the uploader → the upload is denied, the bytes never leave the laptop.
  3. Upload a Word file or screenshot that hides a secret → the content is read and the secret caught inside the file.
  4. Move the same policy from observe → enforce → it shifts from coaching to blocking, every interaction leaving a receipt you re-verify offline, with ByteVerity absent.

Dialed up as confidence grows

ObserveWatch only — build the shadow-AI map.
WarnCoach the employee in the moment.
EnforceBlock at the boundary — same policy.
The extension holds no keys and makes no policy decision. Your customer-domain gateway is the authority; the receipt is re-checkable with the vendor absent. Employees keep using sanctioned AI because it's governed, not forbidden.

Request an enterprise pilot

Force-installed via Chrome/Edge enterprise policy, per-device managed config. Leave your work email and we'll set up a scoped pilot.

Thanks — we'll be in touch. Meanwhile, grab the package above and run the four moves.

You cannot govern the AI you cannot see — and you cannot see it at the firewall; you govern it in the browser, reading what actually leaves, at the moment of send.