Security & Trust

What we touch, what we store, and what we honestly don't do.

We build privacy-first tools, which means we owe you a straight answer about how each product handles your data. No marketing layer, no certification badges we don't hold - just the truth, organized by product.

Core principles

How we think about your data.

Minimum necessary access

Each product asks for the least access it needs to do its job. Read-only where read-only is enough. No requests for power we'd never use.

Purpose-limited use

Data we receive is processed for the stated purpose only - fraud detection, masking, audit logging. We don't sell it, share it with advertisers, or use it for unrelated features.

Honest about limits

We don't claim certifications we don't hold. We don't say "bank-grade" or "military-grade." If we run on certified infrastructure, we say so. If we don't, we say that too.

The extension

How AI Leak Guard handles your data: it doesn't.

AI Leak Guard runs entirely in your browser. A technical safeguard that supports your HIPAA program. The extension does not transmit the content it scans to Zabcore - you can verify that in the open-source code on GitHub. There is nothing on Zabcore's side that holds patient content, because the extension never sends it. (The zabcore.com website itself does have contact and signup forms; if you use them, only the info you type into that form is captured. See /privacy for the full split.)

What AI Leak Guard does
  • Runs detection regex locally in your browser when you paste content into a supported AI tool.
  • Reads PDF, Word, Excel, PowerPoint or text files you attach to a supported AI tool on your device, and warns you before the file uploads.
  • Reads the message you are about to send at the moment you send it on ChatGPT, Claude, Gemini, and Microsoft Copilot (Copilot uses a two-press review to fit its send flow). Your draft is always kept, and the message still sends if the check ever fails.
  • Replaces detected sensitive data with placeholders before the AI tool receives the text.
  • Keeps a local activity view (counts, categories, site, time) and lets you export it to CSV or JSON. Everything stays on your device.
What AI Leak Guard doesn't do
  • No server-side path for what the extension scans. Patient text, file contents, and filenames stay on your device.
  • No outbound network requests. The extension does not contact any server or fetch anything at runtime. Detection patterns are bundled inside the extension and change only when the extension itself updates through the Chrome Web Store.
  • No analytics, no telemetry, no error tracking, no usage logs.
  • No account, no email, no registration. We don't know who installed it.
  • No reading of pages other than the AI tools you've explicitly enabled (send-time protection: ChatGPT, Claude, Gemini, Microsoft Copilot; paste checking: also covers Perplexity; document scanning: ChatGPT, Claude, Gemini, Perplexity).
  • No scanning of document uploads on Microsoft 365 Copilot (the work or school version) - those are handled inside your Microsoft 365 environment.
  • No recording of the text you pasted, the message you sent, the contents of files you attached, or the filenames - the local activity view only ever holds counts, categories, site, and time.
  • No access to browsing history, cookies, saved passwords, or autofill data.
Your data

Where your data goes: your device.

The extension runs entirely in your browser. Patient information you paste is scanned locally and either masked or passed through, whichever you choose. Files you attach are read on your device before upload and you decide whether they go. As of v1.3, on ChatGPT, Claude, and Gemini, the message you are about to send is read on your device at the moment you send it, checked locally, and either warned on or allowed through, whichever you choose. Your draft is always kept. If the check ever fails, the message still sends: fail-open, never blocks. The local activity view holds only counts, categories, site, and time - never the text, the sent message, the file contents, or the filename. None of it is sent to Zabcore, stored on our systems, or shared with anyone else. There is no server-side database of your content to breach, subpoena, or leak.

Responsible disclosure

Found a security issue? Tell us first.

If you've found a vulnerability in AI Leak Guard, the zabcore.com website, or our extension update pipeline, we want to hear about it before anyone else does. We don't have a formal bug bounty program yet, but we take every report seriously and will credit researchers publicly (with permission) on resolution.

Please don't share findings publicly until we've had a reasonable window to fix the issue - typically 30 days for critical issues, 60 days for everything else.

support@zabcore.com