Stop sensitive data at the prompt, not after it leaves.
Deltawall inspects text inputs and pastes into AI tools on the device and masks or blocks sensitive values before the request is sent, while the rest of the work goes through.

Copy-and-paste is now the largest file-less exfiltration channel.
Sensitive data pasted into AI prompts.
The challenge
Employees paste code, contracts, customer records and payment details into AI prompts to get work done. The data may be logged, retained or used for training by the provider, and it has left your control.
Why existing controls miss it
File-centric DLP inspects attachments and endpoints. A paste into a web text box is file-less, encrypted in transit and sent to a permitted site, so it passes every layer unseen.
How Deltawall enforces it
The extension classifies the prompt on submit. Regulated identifiers are masked in the box, secrets are blocked with the reason shown, and a Warn can require a written justification before the user proceeds.
- Checksum-verified identifiers: almost no false alarms
- Secrets blocked at submit, everywhere
- One line in the evidence log, no content
Five actions, chosen per data class.
Record without friction
Low-risk classes are allowed and logged, so you learn where data flows before you enforce.
Coach, with managed bypass
The user sees why, and can proceed with a written business justification that is recorded.
Mask or stop
Identifiers are masked in the message box; secrets and prohibited classes are blocked at submit.
25 data classes. Four ways to be sure.
Twenty-one deterministic detectors, validated by checksum, structure or context, and an on-device model for the four classes no pattern can describe. Where a checksum matches, it overrides the model.
Financial data4
- IBANChecksum
- Payment card numberChecksum
- Dutch VAT number (BTW)Format
- KvK numberContext
National identifiers5
- BSN (Netherlands)Checksum
- German tax ID (Steuer-ID)Checksum
- EU national IDChecksum
- German tax number (Steuernummer)Format
- BIG number (Dutch healthcare register)Context
Personal data5
- Email addressFormat
- Phone numberFormat
- IP addressFormat
- Dutch postcodeFormat
- Date of birthContext
Secrets and credentials6
- API keyFormat
- AWS access keyFormat
- GCP keyFormat
- JSON Web TokenFormat
- Private keyFormat
- Generic secretFormat
Unstructured content5
- Person nameOn-device model
- Postal addressOn-device model
- Health dataOn-device model
- Organisation-confidentialOn-device model
- Source codeFormat
Four steps. Quoted in writing.
Every tier includes the whole platform. What changes with size is the price per user, the setup scope and the service level.
Paid proof of value
Thirty days in your own browser estate, up to 100 users, on your sector's template. Credited in full against year one.
Tier by headcount
Starter for 100 to 249 protected users, Growth for 250 to 999, Enterprise from 1,000.
One-time setup
Rollout through your MDM, policy tuning to your data, and the works-council documentation.
Annual contract
Per protected user, billed annually. Monthly billing is available with a surcharge.
What buyers ask.
Does it store what employees typed?
No. Only the data-class label, a salted hash of the match and metadata are recorded. The prompt and the file never leave the device.
Will it block legitimate work?
Start in Log or Warn, simulate your rules against live traffic, then promote to Redact or Block class by class. Masking lets the rest of the message go through.
Which AI tools are covered?
ChatGPT, Claude, Gemini, Microsoft Copilot, Perplexity and DeepSeek in Chrome, Edge and Firefox. The contract names them.
See it stop real-looking data in a real browser.
A 30-minute technical walkthrough: a prompt redacted, a file stopped, the dashboard, and an evidence pack verified offline in front of you.
No slide deck. Synthetic data only.
