Security architecture

Designed to reduce exposure without creating a second copy of the risk.

NIMVEIL's default path keeps supported prompt analysis in the browser and sends only the metadata required to manage protection.

1Prompt or plain-text fileUntrusted content in a supported AI composer
2Local detection + policyDeterministic checks inside the browser
3Safe event metadataNo matched secret or full prompt

Local-first detection

Supported text is analyzed inside the extension by default. Raw prompts are not sent to the analytics backend.

Minimal event data

The dashboard receives categorical metadata such as service, risk type, severity, policy, and action.

Organization isolation

Every production read and write must derive tenant scope from the verified server session—not a browser-supplied ID.

Environment-only secrets

Provider credentials stay in server environment variables and never enter the web or extension bundles.

Deterministic policy

Policy configuration is versioned and validated. Employee content and website text cannot change policy behavior.

Narrow extension access

V1 requests access only to supported AI hostnames plus extension storage. It does not inject into every website.

Sent to your dashboard
  • AI service
  • Detection category and confidence class
  • Policy action and timestamp
  • Device and member deployment identity
Not sent by default
  • Full prompts or pasted text
  • Detected passwords, tokens, SSNs, or card values
  • Full browsing history
  • Unsupported binary file contents
Responsible disclosure

Found a security issue?

Email [email protected] with a concise description and reproduction steps. Do not include real customer data or publicly disclose an unpatched issue.

Production trust requires more

This repository is a serious first version, not a completed assurance program. External penetration testing, legal/privacy review, incident response operations, monitoring, backup/deletion drills, and browser-store review remain required before protecting real client data.

Privacy-first by design

See the protection flow for yourself.

Run NIMVEIL in monitor mode for seven days. Nothing is blocked during the test.

Start free exposure test Explore the demo