How Aegis treats prompt data

Browser-side enforcement, hash-only logging by default, and honest boundaries — built for trust reviews without overpromising.

Prevent first · Store only what you need

Works where your team already uses AI

Where enforcement happens

Prompts are evaluated before they leave the browser, so Aegis can warn or block risky submissions before they reach the AI provider — prevent, don't just detect.

Event data is encrypted in transit and at rest. Session credentials in the extension are stored encrypted on the device.

Stored by default

Security evidence fields

SHA-256 prompt hash and prompt length
Risk score, severity, and matched categories
Platform and analysis mode
Enforcement action history
Timestamps and limited browser metadata

Hashes let administrators prove the same prompt was submitted again — and correlate events — without storing the original text.

Not the default

Security evidence without collecting the conversation

Honest boundaries matter more than absolute claims. We do not pretend nothing is ever stored.

  • Full prompt plaintext
  • AI model responses as a product log
  • Card numbers or payment credentials
  • Unfiltered page content in error reports

What happens on each prompt

Protection runs at the point of use. Cloud sync is for policy and evidence — not a copy of every conversation by default.

Step 1

Capture in the browser

Aegis intercepts a prompt on ChatGPT, Claude, Gemini, or Copilot before it is sent to the AI service.

Step 2

Analyze and decide

Local rules and, with an active plan, cloud policy analysis produce a risk score and enforcement decision in real time.

Step 3

Sync evidence, not the story

The backend receives hash, metadata, and findings. Prompt plaintext is not stored unless policy allows it.

Defaults that favor least privilege

Prompt events are retained for 90 days by default, while audit logs are retained for one year. Administrators can configure retention and preview cleanup before data is removed.

Browser-side enforcement first

Warn or block risky submissions before they reach the AI provider.

Hash-only logging by default

Store proof of risk and enforcement — not the full prompt text.

Plaintext is opt-in

Full prompt storage stays off unless an admin enables that policy.

Retention you can enforce

90 days for prompt events by default; one year for audit logs.

Common trust questions

Does Aegis send every prompt to your servers?

No. Prompts are evaluated in the browser first. With an active plan, cloud analysis may run for policy decisions, but by default Aegis stores hash and metadata — not the full prompt text.

Can administrators enable full prompt storage?

Yes. Plaintext retention is an explicit organization policy setting. It is off by default so privacy remains the safer baseline.

Can users see when prompts are blocked?

Yes. The extension shows a clear decision panel when a prompt is warned or blocked, including the policy reason when available.

How long is data retained?

Prompt events and security alerts default to 90 days. Audit logs default to one year. Admins can preview and apply retention cleanup from the dashboard.

Is prompt storage configurable per organization?

Yes. Hash logging, plaintext retention, and related policy controls are tenant-scoped so each organization sets its own posture.

What happens if cloud analysis is unavailable?

Local rules can still evaluate prompts in the browser. Organizations can also choose fail-closed behavior so high-risk submissions do not proceed when analysis cannot complete.

Need the contractual language?

Privacy notice and deployment review

Framework explains the product. Privacy covers legal detail.