How Aegis treats prompt data
Browser-side enforcement, hash-only logging by default, and honest boundaries — built for trust reviews without overpromising.
Prevent first · Store only what you need
Works where AI is already used
- ChatGPT
- Claude
- Gemini
- Microsoft Copilot
Where enforcement happens
Prompts are evaluated before they leave the browser, so Aegis can warn or block risky submissions before they reach the AI provider — prevent, don't just detect.
Event data is encrypted in transit and at rest. Session credentials in the extension are stored encrypted on the device.
Employee
Writes a prompt
Aegis in browser
Risk engine → decision
If allowed
Continues to ChatGPT, Claude, Gemini, or Copilot
Evidence sync
Client-reported event data → cloud dashboard
Stored by default
Security evidence fields
Hashes let administrators prove the same prompt was submitted again — and correlate events — without storing the original text.
Security evidence without collecting the conversation
Honest boundaries matter more than absolute claims. We do not pretend nothing is ever stored.
- Full prompt plaintext
- AI model responses as a product log
- Card numbers or payment credentials
- Unfiltered page content in error reports
What happens on each prompt
Protection starts at the point of use. Cloud analysis is optional and consented; synced event findings are client-reported rather than server-verified.
Step 1
Capture in the browser
Aegis intercepts a prompt on ChatGPT, Claude, Gemini, or Copilot before it is sent to the AI service.
Step 2
Analyze and decide
Local rules produce a decision in the browser. Cloud analysis contributes only when organization policy enables it and the user has consented.
Step 3
Sync evidence, not the story
The backend receives client-reported hashes, metadata, and findings. Consented cloud plaintext is processed transiently and event sync does not persist it.
Defaults that favor least privilege
Prompt events are retained for 90 days by default, while audit logs are retained for one year. Administrators can configure retention and preview cleanup before data is removed.
Browser-side enforcement first
Warn or block risky submissions before they reach the AI provider.
Hash-only logging by default
Store proof of risk and enforcement — not the full prompt text.
Plaintext is opt-in
Full prompt storage stays off unless an admin enables that policy.
Retention you can enforce
90 days for prompt events by default; one year for audit logs.
Common trust questions
Does Aegis send every prompt to your servers?
No. Prompts are evaluated in the browser first. With an active plan, cloud analysis may run for policy decisions, but by default Aegis stores hash and metadata — not the full prompt text.
Can administrators enable full prompt storage?
Yes. Plaintext retention is an explicit organization policy setting. It is off by default so privacy remains the safer baseline.
Can users see when prompts are blocked?
Yes. The extension shows a clear decision panel when a prompt is warned or blocked, including the policy reason when available.
How long is data retained?
Prompt events and security alerts default to 90 days. Audit logs default to one year. Admins can preview and apply retention cleanup from the dashboard.
Is prompt storage configurable per organization?
Yes. Hash logging, plaintext retention, and related policy controls are tenant-scoped so each organization sets its own posture.
What happens if cloud analysis is unavailable?
Local rules can still evaluate prompts in the browser. Organizations can also choose fail-closed behavior so high-risk submissions do not proceed when analysis cannot complete.
Need the contractual language?
Privacy notice and deployment review
Framework explains the product. Privacy covers legal detail.