A Governance Tool Has to Earn Trust
We ask you to put ShadowWatch between your team and the AI they use. Here's exactly what that means for your data, and what it doesn't.
Risk scoring runs locally
Sensitive-data risk scoring happens in the browser extension. We capture prompts at submit time. There is no keystroke logging and no passive surveillance of what your team types.
Sensitive patterns auto-redacted
PII, secrets, and API keys are detected and redacted in the audit trail before storage, so your evidence of AI use doesn't itself become a data leak.
Encrypted in transit
Data moving between the extension and your ShadowWatch backend is encrypted in transit. Retention is configurable: 7 days on Starter, 90 on Pro, 365 on Enterprise.
You stay in control of retention
Export and delete audit data on your schedule. Retention follows your plan limits; nothing is kept longer than you configure.
Role-based access to audit data
Only the admins you designate can query the audit trail, with access scoped by role and team. Sensitive evidence is visible to the people who need it for governance, not exposed across the whole organization.
No training on your data
Your prompt data is never used to train AI models and never shared with third parties. It exists to serve your governance and audit. Your prompts stay yours: not trained on, not handed off.
Passwordless, magic-link sign-in
Admins sign in with a passwordless magic link, not a shared password. There is no password to phish, reuse, or leak, and access is scoped to the admin roles you designate.
DPoP-bound access tokens
Session and API tokens are cryptographically bound to the originating device using DPoP (RFC 9449), so a token intercepted in transit or stolen from a log cannot be replayed from another machine.
Where we draw the line
- Prompt text travels to your ShadowWatch backend so policy can be applied and alerts fired. Sensitive patterns are redacted before anything is stored, and you control how long data is retained.
- Non-sensitive prompt text is stored to give you a usable audit record. Sensitive patterns are redacted before that storage happens.
Want the full security review, or an NDA in place before you share anything with us? Contact us →
How this data handling turns into audit evidence: see the compliance mappings →
For the full policy, read our privacy policy →
Put it in place before you need the evidence.
Start free on up to 10 devices, or book a 15-min demo and we'll walk you through the data flow.
Start free