Sensitive data stops
at the prompt box.
Your team already pastes contracts, customer records, and source code into ChatGPT. Requestador's browser extension intercepts every prompt, paste, and upload and validates it against your own model or DLP engine, configured, hosted, and controlled by you, before anything you don't approve ever reaches an AI vendor.
Works with most modern AI assistants, including ChatGPT, Claude, Gemini, Copilot and Perplexity
Requestador validates every prompt against your policy before it's sent.
Every prompt is a
potential leak.
Nobody means any harm. Someone just wants a contract summarized, a spreadsheet cleaned up, a bug explained, and the fastest way there is a chat box. Without a check in place, that's how customer records, credentials, and unreleased plans end up sitting on someone else's servers, one paste at a time.
Five steps,
fully under your control.
Requestador intercepts the prompt in the browser, then calls the validation endpoint you configure: your model, your infrastructure, your policy. Nothing reaches an AI vendor until that decision is made, and the response comes back through the same controlled channel.
Prompt
You type, paste, or drop a file into the composer of an AI site, just like normal.
Intercept
The extension hooks the composer on AI sites: typed prompts, pastes, screenshots, file uploads.
Classify
Your validation model or DLP engine scans for personal data, financial data, credentials, source code, and confidential info.
Score risk
Findings are checked against your policies and rated low, moderate, high, or critical.
Decide
Low risk passes, moderate warns and waits for confirmation, high and critical are blocked before reaching an AI vendor.
Log & audit
Every prompt and decision is recorded to your audit trail: Elasticsearch, OpenSearch, or your SIEM. Never to us.
Two layers.
Zero gaps.
Your infrastructure decides which AI services are reachable. Requestador decides what may be said to them, with full visibility either way.
Bring your own model.
We never see your data.
Requestador doesn't provide or host your validation model. You choose it: a locally hosted LLM, a private AI model, a dedicated classification service, or your existing DLP engine. You control where it runs, how it's trained, and how long results are kept.
You control the model
Local LLM, private AI model, classification service, or your existing DLP engine: you choose one or more. Requestador never ships or manages the detection model itself.
You control the data
Sensitive data categories, detection rules, data processing controls, and retention policy are all set by you.
Policy actions beyond allow/block
Depending on the result, Requestador can also warn, request removal of sensitive content, suggest anonymization, redact protected values, or route the prompt to an approved internal AI service.
Every decision,
logged in your own store.
Requestador can record every validation event and policy decision: who, when, where it was headed, what triggered it, and what happened, into your own Elasticsearch or OpenSearch environment. Requestador doesn't host it: you provide, secure, and retain it.
Elasticsearch or OpenSearch: yours
Requestador doesn't include it as a hosted service. You provide, license, secure, scale, and back it up; Requestador just integrates with it, powering dashboards, compliance review, incident investigation, and SIEM alerting.
What can be logged
User, timestamp, destination AI, validation endpoint, triggered policy, data category, risk level, and decision, from metadata only, up to full prompt content where your compliance requirements explicitly permit it.
Central management
Admins manage approved AI services, validation endpoints, policies, risk thresholds, user permissions, and the Elasticsearch/OpenSearch connection, all from one place.
Your people already use AI.
Decide what it gets to see.
Free for teams up to 25. No account needed to start.
Works with most modern AI assistants, including ChatGPT, Claude, Gemini, Copilot and Perplexity
Rolling out to a team? Talk to us · or email x@xiphias.hr