Shield sits in front of every AI tool your team uses and replaces the secrets and PII its filter packs match with placeholders, outbound, before they leave your company, then rehydrated inbound so your developers never notice. Shield runs on your machine, not ours. The gateway, the CLI, the dashboard, the audit log: all one binary. No hosted service. No data pipeline.
What did your developers send to an LLM this week? Not just what they spent—what actually left the machine.
A live credential in a debugging prompt. An .env file swept into an agent context window. A customer record pasted into ChatGPT at 11pm. For many teams, there’s no practical record of that boundary crossing—just an invoice and a growing compliance question.
That’s the blind spot Shield is built for.
Shield is a local-first LLM security gateway deployed on your infrastructure. It sits between developer AI tools and compatible LLM endpoints, detects secrets and sensitive data before a request leaves, replaces those values with consistent placeholders, and restores them only in the response the developer sees. The model gets the sanitized context. Your developer keeps their workflow. Your security and compliance teams get an auditable record of what was detected and redacted—without routing prompts, secrets, or logs through Purfect Labs.
We built Shield because “please remember to sanitize every prompt” is not a security program.
We’d love feedback from teams using Cursor, Claude, Copilot, Codex, ChatGPT, or similar tools: where are you most worried sensitive context is escaping today?