Pilot programme open to Nordic firms

Let your team use AI without leaking sensitive data

Vaktor masks sensitive data in the browser before it reaches ChatGPT or Claude, and gives you the audit trail to prove it. Built for Nordic teams that handle things they can't afford to leak.

What your analyst types

Draft the redemption memo for Erik Lindqvist, personnummer 811218-9876, on his Nordkap Fond holding.

What ChatGPT receives

Draft the redemption memo for [KLIENT_1], personnummer [PERSONNUMMER_1], on his [KLIENT_2] holding.

3 values masked on device 0 bytes to Vaktor
Covers
ChatGPT
Claude
Gemini
Perplexity

European Union Data residency in Stockholm Detection runs on the device Evidence exports for DORA and NIS2

Every way of controlling this leaks somewhere.

Your best people are faster with these tools, so the volume only goes one way. Three responses are available to you, and each one has a hole in a different place.

Ban it

They route around you

Cyberhaven's 2026 endpoint telemetry already puts 32.3% of workplace ChatGPT use on personal accounts. Outside SSO, outside retention, outside your logs.

Standardise on one vendor

They open the other one anyway

People reach for whichever model is better at the task in front of them. The enterprise seat you paid for covers the traffic you can see.

Allow it, write a policy

The policy is not in the loop

39.7% of what employees move into these tools is sensitive. A policy does not sit between the clipboard and the send button.

Then someone asks you to prove it.

A client's vendor questionnaire. An auditor working through DORA. Finansinspektionen. They ask what happened, on which day, to which data.

A policy document holds no record of a single prompt. Neither does an acceptable-use training module, and neither does the browser history on a laptop you do not administer.

GDPRDORANIS2EU AI Act

Figures from Cyberhaven Labs, 2026 AI Adoption & Risk Report, measured across corporate endpoint telemetry rather than self-reported survey.

A browser extension, between the keyboard and the network.

Nothing to route traffic through, nothing for your team to remember, and no new place for sensitive text to sit.

Your analyst

Opens chatgpt.com and starts typing

Their own account, the workflow they already have. No proxy, no gateway, no second login.

chatgpt.com · claude.ai · gemini.google.com
Vaktor, on the device

Rewrites the prompt before it is sent

Personnummer and organisationsnummer are confirmed by Luhn checksum, IBANs by mod-97, client names against your own list. Each match becomes a numbered placeholder, and repeat mentions reuse the same number so the model can still tell two people apart.

runs in the extension, on the laptop
The model

Answers the placeholder version

[KLIENT_1] sits in the same grammatical slot the real name did. Vaktor restores the real values in the browser as the answer renders.

the reader sees the original names
Compliance

Reads a separate ledger: which categories were masked, how many of each, on which date, by which user. Never the text of the prompt, which is not transmitted and therefore cannot be produced. Export it when an auditor asks how the firm uses AI.

Put your own text through it.

Masking runs in this page, on your machine, using the same checksum code that ships in the extension. Open the network tab if you would like to watch nothing happen.

What the model receives

This demo recognises Swedish personnummer and organisationsnummer, IBANs, email addresses, and a three-name sample client list (Erik Lindqvist, Nordkap Fond, Åsa Sjöberg). In a deployment the client list is yours. Every identifier shown here is an official Swedish test number.

You should not have to take our word for any of this.

Vaktor is not in the prompt path. The extension rewrites text inside the page, the browser sends it to OpenAI or Anthropic the way it always did, and our endpoint receives a category, a count and a timestamp.

Your security team can settle the whole question in an afternoon with a proxy and a packet capture. No source access, no NDA first. We will help set it up if that is useful.

If a capture ever showed prompt text leaving for a Vaktor endpoint, the product would be broken and you would be holding the evidence.

api.openai.com Masked prompt
api.anthropic.com Masked prompt
api.vaktor.ai Category, count, time

Prompt text appears in none of these

Questions we get

Mostly from the person who has to sign off.

If yours is not here, ask it on the call. We would rather answer it before you buy.

What do you store?
Categories, counts, timestamps and the user. Never prompt text, which stays on the device. A full breach of our backend would expose nothing a client told you in confidence.
What happens when detection misses something?
Checksums make false positives rare and misses possible, so treat this as one layer rather than the whole control. Unusual names are the usual gap, which is why the client list is configurable and why the ledger records what was caught rather than claiming nothing got through.
Which tools does it cover?
ChatGPT, Claude, Gemini and Perplexity in the browser, each on the user's own account. Copilot is next. New surfaces arrive as updates to the same extension.
What about the desktop apps?
Not covered yet. Browser first, because that is where the work is happening. A desktop agent is on the roadmap and the ledger format already has room for it.
Does it slow anyone down?
Masking happens as they type, on their own machine, in single-digit milliseconds. Nobody changes how they work, which is the only reason a control like this survives contact with a trading desk.
Does the answer get worse?
A placeholder such as [KLIENT_1] occupies the same grammatical slot as the name it replaced, and the model works on the structure rather than the identity. Real values are restored in the browser, so the reader sees the original names.
How do we know nothing leaves the laptop?
Standard network monitoring. Vaktor is never in the prompt path, so a packet capture settles it. See verification.
GDPR, DORA, NIS2?
Masking supports data minimisation before anything reaches a third-country model, and the ledger drops into DORA and NIS2 evidence requests. The legal judgment stays with your DPO. We supply the record, not the opinion.

Bring a prompt you would rather not have sent.

Thirty minutes. We run your own text through it and you see exactly what would have stayed on the laptop.

Or write first: [email protected]