Protect your sensitive data from AI.
Whatever sensitive data your people type or upload, we find it and stop it before it reaches ChatGPT, Claude, Gemini or Copilot. In the browser. Nothing leaves. Nobody is scored.
A prompt, then a file. All data synthetic.




Twenty-one kinds of sensitive data. Typed or uploaded. Found on your device.
One place. Everything it decided.
Aggregated by department. That is what makes it lawful to show.

Secure by default.
Labels and hashes. Never the content your people typed.
More AI than ever.Fewer leaks than ever.
Machine-speed prompts. Device-speed walls.
Your people paste customer records, contracts, source code and personal details into AI every day. Some of it goes in as a file.
Your DLP was built for email attachments. It has never seen a prompt box.
Most AI-security tools send the prompt to a cloud outside Europe to check it.
We read the page and the file in your browser. We decide before send.
Detect. Decide. Prove.
Every time someone presses send or attaches a file.
Detect
We read prompts and uploads on your device, before anything is encrypted.
- Checksums catch IBANs, ID numbers, cards and keys
- 13 MB model: names, addresses, health terms
- PDF, Word, Excel, PowerPoint, CSV, text, Markdown and JSON
Decide
Your policy picks one of five actions. Four EU templates work from the first hour.
- Allow, log, warn, redact or block
- Rules from department, data type, destination and channel
- New rules simulate first, enforcing nothing
Prove
Every decision goes into a signed, tamper-evident log. Labels and hashes, never content.
- Each record carries the previous fingerprint
- Batches are sealed and the seal is signed
- An auditor verifies the export offline, without us
ner-onnx · int8 · 13 MB · p95 2.2 ms
parse: pdf docx xlsx pptx csv txt md json
A checksum match always beats the model.
AND data ∈ [IBAN]
AND destination = external-AI
→ REDACT + LOG
Chain: OK (201 events)
Pack signature: OK
Batch c83ec1d9: merkle OK, signature OK
VERIFIED — record is intact.
What changes on the first day.
The left column is what happens today, before anything is installed.
| Without Deltawall | With Deltawall | |
|---|---|---|
| Sensitive data typed into AI | Leaves the device | Masked in the box before send |
| Sensitive data uploaded | Leaves the device | Scanned on the device first |
| Certificates on every machine | ✓ | None |
| Traffic routed through a proxy | ✓ | Network path unchanged |
| Record of what left | None | Chained, sealed and signed |
| What an auditor gets | A screenshot | A pack they verify offline |
| Individual employee scoring | Department level only | |
| Looking at what one person typed | Second approver, and logged | |
| Time to first enforcement | Weeks | The first hour, on a template |
| If the scanner fails | Fails open, the site keeps working | |
| Erasing one person from the record | Delete the salt, chain intact | |
| Where the data sits | Wherever the tool sits | EU |
Six leaks. Stopped.
No named customers yet. We show the product instead. Financial template, Accounting seat, external AI. All data synthetic.
01A payment reminder with an IBANREDACT
Masked in the box before send. The rest goes through.
02A debugging question with an API keyBLOCK
Send stopped. Reason shown.
03A clean question about the Cyber Resilience ActALLOW
Passes untouched. We only act when your policy says so.
04payment-instructions.docx attachedBLOCK
Two IBANs, a card, an ID number, one API key. Upload blocked.
05employee-data.csv attachedREDACT
ID numbers, emails, phones. Redact path.
06scanned-contract.pdf attachedBLOCK
No text layer. We say so. Your policy blocks it.
node demo/verify.mjsThe regulations that decide the architecture.
Not badges we were awarded. Rules the product was designed against.
What we see. What we don't.
We say it in the product and in the contract.
| Surface | Sees content | Redacts | Blocks | How |
|---|---|---|---|---|
| Browser AI toolsChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek | Full | Yes | Yes | The extension reads the page before encryption |
| Developer APIs, agentsSanctioned tools and automation | Full | Yes | Yes | Opt-in gateway, keys you issueNo interception |
| Native desktop appsClaude Desktop, Slack and similar | Metadata only | No | Destination | A device blocklist steers use into the browserDiscovery only |
| Scanned documentsPDF or image without a text layer | Flag | No | Yes | Flagged. Your policy decides.No text recognition yet |
No proxy. No root certificate. No kernel driver. No app hooking.
Read it before the first call.
Works-council pack
Written for BetrVG §87, WOR Art. 27 and the CSE. Suggested clauses for the works agreement.
Download PDF For the DPODPIA template
For you as controller. Purpose, means, risks, data-subject rights and sign-off.
Download PDF For the auditorThe evidence verifier
A command-line tool that checks an exported pack. No network. No access to us.
How it worksSay yes to AI. Keep the data in. Prove it to the regulator.
The same engine already governs APIs, agents and automated tools through the gateway.
What comes next, we decide with you.
Let's talk.
Thirty minutes. You watch the product stop realistic data in a real browser.
- Six leaks: three prompts, three files, live
- The dashboard a security lead sees on Monday
- An evidence pack exported and verified while you watch
- Whether a proof of value in your estate makes sense


