Local-first detection
Supported text is analyzed inside the extension by default. Raw prompts are not sent to the analytics backend.
NIMVEIL's default path keeps supported prompt analysis in the browser and sends only the metadata required to manage protection.
Supported text is analyzed inside the extension by default. Raw prompts are not sent to the analytics backend.
The dashboard receives categorical metadata such as service, risk type, severity, policy, and action.
Every production read and write must derive tenant scope from the verified server session—not a browser-supplied ID.
Provider credentials stay in server environment variables and never enter the web or extension bundles.
Policy configuration is versioned and validated. Employee content and website text cannot change policy behavior.
V1 requests access only to supported AI hostnames plus extension storage. It does not inject into every website.
Email [email protected] with a concise description and reproduction steps. Do not include real customer data or publicly disclose an unpatched issue.
This repository is a serious first version, not a completed assurance program. External penetration testing, legal/privacy review, incident response operations, monitoring, backup/deletion drills, and browser-store review remain required before protecting real client data.
Run NIMVEIL in monitor mode for seven days. Nothing is blocked during the test.