Keep customer data out of AI tools.
A Chrome extension your admin force-installs. It inspects every prompt, file and reply before it leaves the browser.
Your team already pastes things into ChatGPT, Claude, Gemini and 130+ other AI tools. Thrace Security allows, warns, redacts or blocks per your policy, and keeps an audit trail of every decision without ever storing the prompt itself.
Decided in real time · before the prompt is sent
Protected by this afternoon.
No security team required. If you can install a Chrome extension from the Google Admin Console, you can run Thrace.
Install from Admin Console
Force-install the Chrome extension to your organisation from the Google Admin Console and paste one policy JSON. No agents, no proxies, no network changes.
The extension is an unlisted Chrome Web Store listing: your force-install policy adds it by ID, employees never install it themselves.
Set your policies
Choose what counts as sensitive (cards, IBANs, API keys, health identifiers…) and what happens per team and per AI tool: allow, warn, redact or block.
Watch it work
The portal shows every decision as it happens: who used which AI tool, what was caught and what the extension did about it. Slack alerts for the serious ones.
Inspected in memory. Never stored.
The prompt text exists only for the milliseconds it takes to decide. The database has no column for it.
Chrome extension
Intercepts the prompt, file or reply on 136 known AI sites and sends it for a decision.
Thrace API
28 detectors scan the text in memory and return one verdict: allow, warn, redact or block.
Admin portal
Stores metadata only: who, which tool, what category was found, what happened, when.
Self-hosted: the API and portal run on your infrastructure and nothing reaches Thrace. Hosted: a dedicated instance in Frankfurt (eu-central-1), no non-EEA subprocessors.
Enterprise DLP. SME price tag.
The controls big companies pay six figures for, packaged for teams of 10 to 500 on Google Workspace.
Stops leaks in real time
Prompts, file uploads and AI responses are inspected before they leave the browser, then allowed, warned, redacted or blocked per your policy.
28 detector types
Cards (Luhn-checked), IBANs, NHS and National Insurance numbers, passports, API keys, cloud credentials, private keys, connection strings and more.
Covers 136 AI tools
ChatGPT, Claude, Gemini, Copilot, Perplexity and 130+ chat, coding, image, voice and meeting tools. Optional discovery (admin-enabled) flags unlisted AI-looking sites for review.
One simple portal
Live events, user risk overview, per-team policies and Slack alerts. Built for the IT admin who also does everything else.
Prompts never stored
Only metadata is kept: what category of data was caught and what happened. The raw text your team writes is never persisted.
Native to Google Workspace
Deployed via Admin Console and tied to Workspace identity. Employees cannot uninstall it or opt out, and there is nothing for them to configure.
Twelve of the twenty-eight.
Each detector validates, not just pattern-matches: checksums, context words and known test values keep false positives down. You decide the action per team.
| Data | Detector | Severity | Example shape | Default policy |
|---|---|---|---|---|
| AWS secret key | aws_secret_key | critical | AKIA… + 40-char secret | Warn |
| Password or API key in config | password / api_key | critical | DB_PASSWORD=…, sk-live-… | Warn |
| Private key | private_key | critical | -----BEGIN PRIVATE KEY----- | Warn |
| Database connection string | connection_string | critical | postgres://user:pass@host | Warn |
| Credit card number | credit_card | high | Luhn-validated 13–19 digits | Warn |
| IBAN | iban | high | mod-97 validated | Warn |
| UK NHS number | nhs_number | high | checksum + context | Warn |
| UK National Insurance | national_insurance | high | QQ 12 34 56 C | Warn |
| US Social Security number | ssn | high | area/group validated | Warn |
| Date of birth | dob | medium | “date of birth 14/03/1988” | Log |
| Email address | low | jane.doe@acme.co.uk | Log | |
| Phone number | phone | low | +44 7700 900461 | Log |
Full list and the evaluation harness that measures precision and recall are in the open-source repository. Custom keywords (project names, client lists) can be added per policy.
See every AI decision. Store no secrets.
Live events, weekly trends, per-user risk and per-team policies in one place. Raw prompts are never stored: your employees’ words stay theirs.
Illustration. Figures are examples.
Latest events
Built to pass your security review.
Open source, forkable
The whole platform is Apache-2.0. Read the detector code before you trust it.
Prompts never stored
The events table has no column for prompt text. This is enforced by schema, not by promise.
EU hosting
Hosted instances run in Frankfurt (eu-central-1) with no non-EEA subprocessors.
Minimal permissions
identity, storage, tabs, alarms and a fixed list of AI hosts. No access to every website.
Runs inside your Workspace policy
Configured from the Google Admin Console. The extension key is scoped: it cannot read or change policies.
Security disclosures welcome
security@getthrace.com, acknowledged within two business days.
Same product. Two ways to run it.
Run the open-source platform yourself for free, or let us run a dedicated instance for you in the EU.
Self-hosted
For teams with an engineer to spare
Free forever · Apache-2.0
- Full platform, no locked features
- Docker Compose or AWS Terraform
- Your data never leaves your systems
- Community support
Hosted
For teams who want it handled
early-access rate · billed monthly
- Dedicated instance in Frankfurt
- Your own subdomain: yourcompany.getthrace.com
- We run upgrades, backups and monitoring
- Google Workspace force-install in about 20 minutes
- Email support, 1-business-day response
- Limited to five design partners in 2026
Enterprise
For 500+ seats or special requirements
custom agreement
- Dedicated instance and region of your choice
- Data processing agreement and DPIA support pack
- Google Workspace SSO today; SAML on request
- Priority support
Prices in EUR, excl. VAT. Hosted pricing is being finalised; early-access partners keep their rate.
| Self-hosted | Hosted | Enterprise | |
|---|---|---|---|
| Where it runs | Your servers (Docker or AWS) | Dedicated instance, Frankfurt | Dedicated instance, your region |
| Portal address | Your own hostname | yourcompany.getthrace.com | Your own domain |
| Upgrades | You pull and redeploy | Done for you | Scheduled with you |
| Backups | Your responsibility | Daily, 7-day retention | Per agreement |
| Data location | Wherever you run it | EU only | Your choice |
| Support | Community (issue tracker) | Email, 1 business day | Priority |
| Price | €0 | from €4 / user / month | Custom |
Same detectors, same portal, same extension in every option. Move between them any time: the database exports and imports cleanly.
Fair questions.
Do you store what my employees type?
What does the extension see?
How long does deployment actually take?
Where does the extension come from, and do employees have to install it?
Which AI tools are covered?
Where is data hosted?
Can we self-host now and move to hosted later, or the other way round?
Does it work outside Chrome?
Your data is in ChatGPT already.
The question is whether anything is watching. Put Thrace between your team and 136 AI tools. Self-host it today for free, or ask for a hosted instance in the EU.