AlpineGate detects sensitive data in AI prompts and replaces it with reversible tokens — entirely on your device. No cloud analysis, no account, no telemetry. The answer still makes sense, because the real values are restored in the page.
Free extension · Chrome & Edge · No account required
What you type
What the AI receives
What you see back
To classify your prompt, they send it to their cloud. You solve one data-leak problem by creating another — and adding a vendor to your processing register. AlpineGate draws the line at your device.
| Capability | AlpineGate | Cloud AI DLP |
|---|---|---|
| Prompt text analysed on-device, zero egress | ✓ | ✗ |
| Reversible tokens with in-page response restore | ✓ | rare |
| No account, works offline | ✓ | ✗ |
| Self-hostable admin console | planned | SaaS only |
| Very large entity catalogues, ML classification | ✗ | ✓ |
Where we are honest: cloud engines using machine-learning classification report higher recall than an on-device rule engine — published third-party figures sit around 95%. We are not selling better detection. We are selling a boundary no cloud tool can offer: your prompts are never transmitted for analysis, by anyone, including us.
No proxy, no network changes, no agent to deploy.
A local rule engine scans the prompt as you type — names, IBANs, health data, credentials, your own keywords.
Each finding is replaced by a stable token. The mapping goes into a vault that never leaves the device.
The AI receives a prompt it can still reason about — without a single real identifier in it.
Tokens in the answer are swapped back to the real values directly in the page. The output stays usable.
A working extension for Chrome and Edge — not a waiting list for a future product.
Configurable detection rules for personal data, financial identifiers, credentials and your own keyword lists — evaluated entirely on-device.
Stable tokens keep the prompt coherent, and the response restore puts the real values back in the page. Masking without losing the answer.
ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral and more — with a network-layer backstop for anything the page-level rules miss.
Rules, keyword lists and switches can be pushed through Chrome and Edge enterprise policy — no per-machine setup.
Install and you are protected. Nothing to sign up for, nothing to provision, nothing that stops working when the network does.
No blocked sites, no approval queues. People keep the AI tools they already use — the sensitive parts simply never make it out.
We would rather show you the plan than imply everything already exists.
Available in the current build.
In development, in this order.
Local protection costs us nothing per user, so we do not charge for it. What organisations buy is central policy and the audit trail that proves enforcement.
Individuals and evaluation
Small teams that need proof of enforcement
Regulated teams with an auditor to satisfy
Banks, insurers, public sector, legal
Prices excl. VAT. Paid tiers ship with the console — design partners get them at launch pricing, for good.
No — and not as a policy, as an architecture. Detection, tokenization and the token vault all run inside the extension on your device. The free extension makes no network calls of its own, requires no account and collects no telemetry. There is no server for your prompts to reach.
Every serious competitor sends prompt text to their own cloud to classify it. That makes the DLP tool an egress channel in its own right, and a new processor in your compliance register. AlpineGate keeps the analysis on the device, so the trust boundary stops at your browser.
Sensitive values are swapped for stable tokens such as [PERSON_1] before the prompt is sent, so the model still understands the structure of your request. The mapping lives in a local vault, and when the answer comes back the real values are restored directly in the page — you get a usable reply without ever exposing the data.
Less exhaustive than a cloud engine, and we would rather say so. Machine-learning classification services report recall around 95% in published third-party tests; a configurable rule engine will trail that on unusual or multilingual data. What we offer in exchange is absolute: nothing is transmitted for analysis. You can also add your own keywords and entities, which usually matter more than catalogue size.
Yes — that is the Enterprise tier, and it is the reason the console exists as a docker-compose image, not only as SaaS. You run it in your own infrastructure, so even policy and audit metadata stay inside your network. The console is in development; design partners shape what it does.
Protection never switches off. Unlicensed devices keep protecting their users and simply appear in the console as outside the licence, which turns into a true-up at renewal. A security control should not stop working over a billing dispute.
A single user is protected in under five minutes. A fleet rollout uses Chrome or Edge enterprise policy — no proxy, no network changes, no agent to install.
The extension is working today and the console is being built now. Early users get the build; design partners get to decide what the console reports.
contact@alpinedata.ch