Skip to content
AI-Guardian
Technology

How AI-Guardian Works

Four layers of protection — all running locally on your device. Here's the full technical picture.

Architecture Overview

Browser Extension

Chrome / Firefox / Edge content script + service worker

Desktop Agent

Electron-based OS-level input hook (macOS, Windows)

Detection Engine

Compiled regex + entropy analysis + lightweight on-device ML

Audit Pipeline

Anonymised event metadata → Supabase (no raw text ever transmitted)

Step-by-Step Breakdown

AI-Guardian's browser extension injects a lightweight content script into every AI web interface (ChatGPT, Claude, Gemini, Perplexity, Cursor, etc.). The script hooks into the browser's native input events — beforeinput, paste, and submit — to capture the full text of any prompt before the browser constructs the outbound HTTP request.

For native desktop AI applications (Claude Desktop, Cursor, VS Code extensions), the companion desktop agent operates at the OS input layer using platform-specific accessibility APIs (macOS Accessibility API, Windows UI Automation). This ensures coverage extends beyond the browser to every application on the device.

Why local interception matters

Network-level DLP tools inspect traffic after it has left the endpoint — often encrypted and already en route. By intercepting at the input layer, AI-Guardian catches sensitive data before any TLS handshake occurs, making it effective even when employees use personal hotspots, VPNs, or connections that bypass corporate proxies.

Built for Regulated Industries

AI-Guardian's privacy-first architecture satisfies the data minimisation and purpose limitation requirements of GDPR, the system governance mandates of the EU AI Act, and the access control requirements of SOC 2. Detailed compliance documentation is available for enterprise customers.

GDPR Art. 25
EU AI Act
SOC 2 Type II
HIPAA Ready
ISO 27001
How It Works — On-Device AI DLP | AI-Guardian · AI-Guardian