Requestador AI DLP: intercept. validate. enforce. audit.

Sensitive data stops
at the prompt box.

Your team already pastes contracts, customer records, and source code into ChatGPT. Requestador's browser extension intercepts every prompt, paste, and upload and validates it against your own model or DLP engine, configured, hosted, and controlled by you, before anything you don't approve ever reaches an AI vendor.

Works with most modern AI assistants, including ChatGPT, Claude, Gemini, Copilot and Perplexity

🛡 AI Assistant
‹ ›
🔒 chat.ai-assistant.example
⤴ ⟳
Today
Candidate file summary
Q3 board memo outline
Rewrite onboarding email
Yesterday
SQL join explanation
Travel policy questions
Acme AI · Fast model ▾ Requestador on
Can you help me with something?
AI
Of course, go ahead and paste what you'd like help with.
Requestador is validating this prompt…
+ 🌐

Requestador validates every prompt against your policy before it's sent.

🛡
Requestador DLP
A browser extension, built and offered by Requestador.
Add to browser Works with most modern AI assistants, including ChatGPT, Claude, Gemini, Copilot and Perplexity
The problem

Every prompt is a
potential leak.

Nobody means any harm. Someone just wants a contract summarized, a spreadsheet cleaned up, a bug explained, and the fastest way there is a chat box. Without a check in place, that's how customer records, credentials, and unreleased plans end up sitting on someone else's servers, one paste at a time.

Your browser Their servers
How It Works

Five steps,
fully under your control.

Requestador intercepts the prompt in the browser, then calls the validation endpoint you configure: your model, your infrastructure, your policy. Nothing reaches an AI vendor until that decision is made, and the response comes back through the same controlled channel.

Prompt

You type, paste, or drop a file into the composer of an AI site, just like normal.

Intercept

The extension hooks the composer on AI sites: typed prompts, pastes, screenshots, file uploads.

Classify

Your validation model or DLP engine scans for personal data, financial data, credentials, source code, and confidential info.

Score risk

Findings are checked against your policies and rated low, moderate, high, or critical.

Decide

Low risk passes, moderate warns and waits for confirmation, high and critical are blocked before reaching an AI vendor.

Log & audit

Every prompt and decision is recorded to your audit trail: Elasticsearch, OpenSearch, or your SIEM. Never to us.

Architecture

Two layers.
Zero gaps.

Your infrastructure decides which AI services are reachable. Requestador decides what may be said to them, with full visibility either way.

Safe usage
Data stays in the EU
GDPR · ISO · NIS2
Full audit trail
Any LLM you choose
Validation Model

Bring your own model.
We never see your data.

Requestador doesn't provide or host your validation model. You choose it: a locally hosted LLM, a private AI model, a dedicated classification service, or your existing DLP engine. You control where it runs, how it's trained, and how long results are kept.

You control the model

Local LLM, private AI model, classification service, or your existing DLP engine: you choose one or more. Requestador never ships or manages the detection model itself.

You control the data

Sensitive data categories, detection rules, data processing controls, and retention policy are all set by you.

Policy actions beyond allow/block

Depending on the result, Requestador can also warn, request removal of sensitive content, suggest anonymization, redact protected values, or route the prompt to an approved internal AI service.

Audit Trail

Every decision,
logged in your own store.

Requestador can record every validation event and policy decision: who, when, where it was headed, what triggered it, and what happened, into your own Elasticsearch or OpenSearch environment. Requestador doesn't host it: you provide, secure, and retain it.

Elasticsearch or OpenSearch: yours

Requestador doesn't include it as a hosted service. You provide, license, secure, scale, and back it up; Requestador just integrates with it, powering dashboards, compliance review, incident investigation, and SIEM alerting.

What can be logged

User, timestamp, destination AI, validation endpoint, triggered policy, data category, risk level, and decision, from metadata only, up to full prompt content where your compliance requirements explicitly permit it.

Central management

Admins manage approved AI services, validation endpoints, policies, risk thresholds, user permissions, and the Elasticsearch/OpenSearch connection, all from one place.

Your people already use AI.
Decide what it gets to see.

Free for teams up to 25. No account needed to start.

Works with most modern AI assistants, including ChatGPT, Claude, Gemini, Copilot and Perplexity

Rolling out to a team? Talk to us · or email x@xiphias.hr