Start here
The free tool below runs entirely in this browser — no account, nothing stored or transmitted. Redact anything you would not want kept before you type it.
Open the companion tool →How public prompt inputs can leak into model training
Unless your organization uses an enterprise plan with strict zero-data-retention (ZDR) guarantees, data submitted to free or standard consumer AI tools may be logged for retraining.
Credentials, private keys, database connection strings, and internal URLs included in prompts remain in training sets or log files permanently once ingested.
The protocol
- Never paste `.env` files, production database connection strings, or secret tokens into any browser prompt.
- Replace internal server names, proprietary customer names, and employee emails with generic placeholders.
- Verify your AI vendor's privacy settings to turn off data sharing for model training where available.
- Use local or self-hosted models for highly confidential source code and sensitive customer datasets.
What the tool does
Scan code snippets and prompt text locally to flag API keys, tokens, and internal credentials before submission.
Limit first: Scans for known credential formats locally. Always double-check code manually before pasting into external tools.
Open the companion tool →One human next step
If secrets or private keys were accidentally submitted to a public model, rotate those credentials immediately and inform your security or legal department.
Research log and safety checks
AI-assist path: client-side regex token scanning. §6.10: not a frontier policy topic.
§0.5 protection result: category is data-privacy-exposure; crisis-adjacent: no; fear/urgency/scarcity toolkit used: no. The protective function is free and the paid feature is convenience only.