Now onboarding pilot firms in the Nordics  ·  Book 30 minutes →

Let your team use AI without leaking sensitive data

Vaktor masks sensitive data in the browser before it reaches ChatGPT or Claude, and gives you the audit trail to prove it. Built for Nordic teams that handle things they can't afford to leak.

Works with ChatGPT Claude Gemini Perplexity
EU EU data residency · Stockholm GDPR-first architecture DORA & NIS2 evidence exports 100% on-device detection

You can't ban AI
You can't lock it down either

Your best people work faster with AI, so demand only grows. Every way of controlling it has the same hole.

Ban it
They route around youA third of workplace ChatGPT already runs on personal accounts, outside SSO and retention.
Lock it
They use the others anywayCommit to one enterprise model and people still reach for Claude or GPT. The lead keeps moving.
Allow it
Every shortcut is a leak40% of prompts carry sensitive data, and the fastest path is the least careful one.
Cyberhaven Labs, 2026 AI Adoption & Risk Report  ·  Gartner, Market Guide for AI TRiSM

And you still have to prove it

Forget leaks for a moment. A client, an auditor or Finansinspektionen asks a simpler question: how does your firm use AI? A policy document describes the rules. It holds no record of a single prompt. Intent is not evidence.

EU GDPR DORA NIS2 EU AI Act

How Vaktor works

Your team

Opens claude.ai or chatgpt.com

no new login

The tools they know, the way they already work.

Vaktor, on the device

Strips the sensitive parts

runs locally on the laptop

Names, personnummer, IBANs and org numbers are replaced before the prompt leaves the machine.

The AI

Sees a clean prompt

answer still works

The model never needed the sensitive parts to give a great answer. It works on the placeholders and returns the same quality.

A clean, high-quality answer comes back to your team ←
Compliance, in parallel

Reads the metadata trail

categories · counts · timestamps

Never the prompt content. An exportable record of how AI is used, ready for an auditor or the regulator.

See it strip a prompt live

What you type
What the AI receives

The field above is editable. Masking runs in your browser, which you can confirm in the network tab (F12). The demo recognizes Swedish personnummer, org numbers, IBANs, emails and a sample client list. Demo data uses official Swedish test numbers.

Verify that your data stays local

Vaktor sits outside the prompt path by design. Detection runs on the device, and our backend receives metadata only. Your security consultant can confirm it with standard network monitoring. The claim is easily checkable.

Ask your preferred AI about this

One click opens a fresh chat with the question already written. The models know this problem well.

Questions buyers ask us

What does it store?+
Categories, counts and timestamps. Never prompt content, which stays on the device. Even a breach of our own backend would expose nothing a client told you in confidence.
Which AI tools does it cover?+
ChatGPT, Claude, Gemini and Perplexity in the browser, each on the user's own account. Copilot next. New surfaces ship as updates to the same extension.
What about the desktop apps?+
Browser first, since that's where the work is. A lightweight desktop agent is on the roadmap, and the audit trail already accounts for it.
Does it slow people down?+
No. Masking happens inline as they type, on their own machine, in milliseconds. Nobody changes how they work.
How do we know nothing leaves the laptop?+
Your security team can confirm it with standard network monitoring. Vaktor is never in the prompt path.
GDPR, DORA, NIS2?+
Masking supports data minimization before anything reaches a third-country model, and the audit trail slots into DORA and NIS2 evidence. Your DPO keeps the judgment.

Give your team AI,
and the proof you stay in control

A 30-minute call. We show you exactly what would stay on the laptop, on your own prompts.