How it works
Employees want to paste work into AI tools. PromptHarbor checks each prompt before it leaves: it finds sensitive content, replaces what can be replaced, and applies a fixed policy that says whether it may go, needs a manager, or can't go at all. Nothing is sent until the person has seen exactly what the AI provider will receive.
Automation enforces the rules that are known. AI may only explain. People decide the exceptions.
All data here is mock-up data. The people, companies, keys and account numbers are fictional, and there is no real AI provider: the only destination is an in-process mock on this server.
What happens to a prompt
- You write a prompt…and say what it's for (the task), where it's going (the provider) and how sensitive it is.
- It's cleaned up in memoryHidden characters are removed, look-alike letters folded, and encoded text decoded once, so tricks like zero-width spaces or base64 don't hide anything.
- Seven detectors scan itCredentials and API keys, email addresses, phone numbers, account numbers, payment cards (with a checksum), classification markings like CONFIDENTIAL, and requests for decisions about people's jobs, credit, health or legal position.
- Sensitive values are replacedContact details and numbers become placeholders like [EMAIL_1] or [ACCOUNT_1]; secrets become [SECRET_REDACTED]. The mapping back to the originals is thrown away, and the raw prompt is never stored.
- A versioned policy decidesBuilt-in rules run first and can't be weakened, then the company's own rules. Every matching rule is recorded, and the strictest one wins.
- You confirm the exact previewYou see precisely what the provider will get and confirm it. Exceptions go to a manager, who can't be the person who wrote the prompt.
- It's sent, re-checked and recordedThe destination is checked again against the current policy at send time, the mock provider receives only the redacted text, and every step lands in a hash-chained audit trail that never contains the prompt itself.
The four decisions
Nothing sensitive found. You still confirm before it's sent.
Sensitive values are replaced; you confirm the redacted version.
A manager must approve first, for example for confidential material.
Not sent. Secrets, unapproved providers, data a provider isn't cleared for, and decisions about people can't be overridden by anyone.
Run it live
Each scenario runs the real engine on this server in your own throwaway sandbox (deleted after 2 hours). You'll see the original synthetic prompt, what the provider would receive, why, and the checks against the expected result.
What it does not do
- It can't see AI use outside this workspace: personal accounts, other browsers and phones are out of scope.
- Pattern matching misses things such as names and street addresses. It reduces risk; it isn't complete data-loss prevention. In testing it caught 98% of labelled samples with no false alarms, on a test set written by the same team.
- The optional AI explainer only sees finding types, never the prompt, and can't change a decision.
- The audit chain detects tampering but isn't anchored to an outside record.
To call it yourself, see the API docs. To use the full workspace, including approvals, policy and the audit trail as different people, open the workspace and switch persona in the left rail.