🇨🇭 Swiss made · Local-first AI DLP

Your prompts never leave your browser.

AlpineGate detects sensitive data in AI prompts and replaces it with reversible tokens — entirely on your device. No cloud analysis, no account, no telemetry. The answer still makes sense, because the real values are restored in the page.

Free extension · Chrome & Edge · No account required

chatgpt.com

What you type

Draft a reminder for Marc Baumann about invoice CH93 0076 2011 6238 5295 7.

What the AI receives

Draft a reminder for [PERSON_1] about invoice [IBAN_1].

What you see back

Dear Marc Baumann, our records show invoice CH93 0076 … is still open…
Token vault stored locally · nothing transmitted for analysis
Zero prompt egress
No account, no telemetry
17 AI platforms covered
Works offline
The trust boundary

Most AI DLP tools are themselves an egress channel

To classify your prompt, they send it to their cloud. You solve one data-leak problem by creating another — and adding a vendor to your processing register. AlpineGate draws the line at your device.

Capability AlpineGate Cloud AI DLP
Prompt text analysed on-device, zero egress
Reversible tokens with in-page response restorerare
No account, works offline
Self-hostable admin consoleplannedSaaS only
Very large entity catalogues, ML classification

Where we are honest: cloud engines using machine-learning classification report higher recall than an on-device rule engine — published third-party figures sit around 95%. We are not selling better detection. We are selling a boundary no cloud tool can offer: your prompts are never transmitted for analysis, by anyone, including us.

Four steps, all inside your browser

No proxy, no network changes, no agent to deploy.

1

Detect

A local rule engine scans the prompt as you type — names, IBANs, health data, credentials, your own keywords.

2

Pseudonymize

Each finding is replaced by a stable token. The mapping goes into a vault that never leaves the device.

3

Send safely

The AI receives a prompt it can still reason about — without a single real identifier in it.

4

Restore

Tokens in the answer are swapped back to the real values directly in the page. The output stays usable.

AlpineGate v3.0

What ships today

A working extension for Chrome and Edge — not a waiting list for a future product.

Local rule engine

Configurable detection rules for personal data, financial identifiers, credentials and your own keyword lists — evaluated entirely on-device.

Reversible pseudonymization

Stable tokens keep the prompt coherent, and the response restore puts the real values back in the page. Masking without losing the answer.

17 AI platforms

ChatGPT, Claude, Gemini, Copilot, Perplexity, Mistral and more — with a network-layer backstop for anything the page-level rules miss.

Managed policy config

Rules, keyword lists and switches can be pushed through Chrome and Edge enterprise policy — no per-machine setup.

No account, no waiting

Install and you are protected. Nothing to sign up for, nothing to provision, nothing that stops working when the network does.

Zero friction

No blocked sites, no approval queues. People keep the AI tools they already use — the sensitive parts simply never make it out.

Where AlpineGate is going

We would rather show you the plan than imply everything already exists.

Shipping now

Available in the current build.

  • Local detection, pseudonymization and response restore
  • 17 AI platforms with network-layer backstop
  • Managed policy configuration for fleets
  • Chrome and Edge store listing in review

Next

In development, in this order.

  • Vertical entity packs: Swiss/DACH, legal, healthcare, finance
  • Paste and text-file scanning
  • Local audit buffer, then the policy & audit console
  • Self-hosted console image, Firefox and Safari builds
Pricing

The engine is free. You pay for evidence.

Local protection costs us nothing per user, so we do not charge for it. What organisations buy is central policy and the audit trail that proves enforcement.

Team In development

Small teams that need proof of enforcement

CHF 5 / user / month
  • Everything in Free
  • Hosted console and central policy push
  • Audit log and compliance export
  • Annual billing, 10 seats minimum
Join the waitlist

Business In development

Regulated teams with an auditor to satisfy

CHF 9 / user / month
  • Everything in Team
  • SSO/SAML and SIEM connector
  • Vertical entity packs and custom rules
  • Priority support, 50 seats minimum
Join the waitlist

Self-hosted

Banks, insurers, public sector, legal

From CHF 12'000 / year
  • Console in your own infrastructure
  • No metadata ever leaves your network
  • Custom packaging, branding and entity packs
  • Deployment support and SLA, from 250 seats
Talk to us

Prices excl. VAT. Paid tiers ship with the console — design partners get them at launch pricing, for good.

Frequently asked questions

Does AlpineData ever see the content of our prompts?

No — and not as a policy, as an architecture. Detection, tokenization and the token vault all run inside the extension on your device. The free extension makes no network calls of its own, requires no account and collects no telemetry. There is no server for your prompts to reach.

How is this different from other AI DLP tools?

Every serious competitor sends prompt text to their own cloud to classify it. That makes the DLP tool an egress channel in its own right, and a new processor in your compliance register. AlpineGate keeps the analysis on the device, so the trust boundary stops at your browser.

What exactly is reversible pseudonymization?

Sensitive values are swapped for stable tokens such as [PERSON_1] before the prompt is sent, so the model still understands the structure of your request. The mapping lives in a local vault, and when the answer comes back the real values are restored directly in the page — you get a usable reply without ever exposing the data.

How accurate is on-device detection, honestly?

Less exhaustive than a cloud engine, and we would rather say so. Machine-learning classification services report recall around 95% in published third-party tests; a configurable rule engine will trail that on unusual or multilingual data. What we offer in exchange is absolute: nothing is transmitted for analysis. You can also add your own keywords and entities, which usually matter more than catalogue size.

Can we run the admin console ourselves?

Yes — that is the Enterprise tier, and it is the reason the console exists as a docker-compose image, not only as SaaS. You run it in your own infrastructure, so even policy and audit metadata stay inside your network. The console is in development; design partners shape what it does.

What happens if we install more seats than we pay for?

Protection never switches off. Unlicensed devices keep protecting their users and simply appear in the console as outside the licence, which turns into a true-up at renewal. A security control should not stop working over a billing dispute.

How long does deployment take?

A single user is protected in under five minutes. A fleet rollout uses Chrome or Edge enterprise policy — no proxy, no network changes, no agent to install.

Be an early user — or a design partner.

The extension is working today and the console is being built now. Early users get the build; design partners get to decide what the console reports.

contact@alpinedata.ch