Straight answers, including where something isn't built yet.
What is SafePrompt?
SafePrompt is an AI data loss prevention (DLP) agent that runs on an employee's device and inspects prompts before they reach ChatGPT, Claude, Gemini, or Copilot. If a prompt contains a password, API key, or personal data, SafePrompt can warn, redact, or block it — before it ever leaves the device.
Does SafePrompt work as a browser extension?
No, not anymore. SafePrompt is a native endpoint agent, not a browser extension. It intercepts traffic to known AI services locally on the device and inspects it there, which means it isn't limited to a single browser and can't be disabled by uninstalling an extension.
Does SafePrompt inspect prompts locally, or send them to your servers?
Detection itself runs locally, on the device — that's where the scanning happens, not in our cloud. For audit purposes, a redacted snippet of the prompt is stored in your dashboard's activity log (with the actual secret or PII value stripped out and replaced with a placeholder like [REDACTED_API_KEY]) — the surrounding text is kept so admins can see what was caught. We never store or train on the sensitive values themselves.
Which AI tools does SafePrompt support?
ChatGPT, Claude, Gemini, and Microsoft Copilot today. We only list a tool here once it's actually supported.
Which operating systems does SafePrompt run on?
Windows and Linux are fully supported and tested today. A macOS build exists but hasn't been validated on real hardware yet — it's in beta.
Does SafePrompt work offline?
Prompt detection runs locally and doesn't require a live connection to inspect a prompt. A network connection is needed to issue or renew a license and to sync activity logs to your dashboard.
How many devices can I protect?
The free trial covers 5 devices. Professional covers up to 50. Enterprise supports 200+ devices with a custom device count set per contract.
How does licensing work?
Each device runs against a license file that's cryptographically signed by SafePrompt. The license specifies the edition, device limit, and expiry. The agent verifies it locally before enforcing anything, so it can't be edited by hand.
Can I try SafePrompt for free?
Yes — a 14-day trial covering up to 5 Windows devices, no credit card required. See /trial.
Can SafePrompt be deployed with Microsoft Intune?
We have a written Intune deployment guide (.intunewin packaging, detection script), but it hasn't yet been field-validated against a real Intune tenant. Enterprise customers get a guided rollout with our team rather than a fully self-serve Intune package today.
Does SafePrompt support Group Policy (GPO) deployment?
Yes — a GPO startup-script deployment method is built and tested. A native "Group Policy Software Installation" path is documented but not yet verified against a real domain controller.
Does SafePrompt support SCCM?
A SCCM application deployment guide exists with correct packaging instructions, but like Intune, it hasn't been field-tested against a real SCCM site yet. Enterprise customers get hands-on help from our team for this.
Does SafePrompt support SSO, SAML, or SCIM?
Not today, and it isn't something we sell or promise a date for — we'd rather say that plainly than have you find out after signing a contract.
What kind of sensitive data does SafePrompt detect?
Credentials (API keys, passwords, database URLs, SSH keys), personally identifiable information (names, emails, phone numbers, SSNs, credit cards), and file uploads (PDF, DOCX, XLSX) containing any of the above.
Can I write my own detection rules?
Yes, on Professional and above — you can define custom keyword lists and choose the action (block, warn, or redact) for each.
What happens when SafePrompt blocks a prompt?
The prompt never reaches the AI tool. Depending on policy, the user sees a warning (and can proceed with a justification), a hard block, or the sensitive parts get redacted and the rest of the prompt goes through.
Is there an API for programmatic detection, not just the desktop agent?
Professional and above include API-based detection for local integrations — applications on the same device can submit content to the local detection engine, rather than only intercepting browser/OS traffic.
How is my data stored, and where?
Activity logs (redacted prompt snippets and detection metadata) are stored in SafePrompt's own hosted database today for Community and Professional plans — encrypted at rest and in transit. On-prem / self-hosted deployment is available as an Enterprise contract option; it's not yet a fully self-serve product feature. See /security for the full breakdown.
Is SafePrompt SOC 2 or ISO 27001 certified?
Not yet — both are in progress, targeted for 2026. We'll update this page the day either one is actually certified, not before.
How do I cancel or get a refund?
Professional is billed monthly with no long-term contract — cancel anytime. There's a 14-day money-back guarantee on your first payment. See /legal/refund for the full policy.