Vaktor
Pilot programme open to Nordic firms

Let your team use AI without leaking sensitive data

Vaktor masks sensitive data in the browser before it reaches ChatGPT or Claude, and gives you the audit trail to prove it.

Draft the redemption memo for Erik Lindqvist, personnummer 811218-9876, on his Nordkap Fond holding, and confirm to [email protected].

4 values masked on device 0 bytes to Vaktor
Covers
ChatGPT
Claude
Gemini
Perplexity

European Union Data residency in Stockholm Detection on the device Evidence exports for DORA and NIS2

The problem

Your team already uses AI. You just can't prove what they sent.

32.3%

of workplace ChatGPT use already runs on personal accounts.

39.7%

of what employees move into AI tools is sensitive data.

Ban it

They route around you, on accounts you cannot see.

Buy one enterprise seat

They open the other model for the task it happens to be better at.

Allow it, write a policy

A policy does not sit between the clipboard and the send button.

Then the auditor asks

What happened, on which day, to which data. A policy document holds no record of a single prompt.

Figures from Cyberhaven Labs, 2026 AI Adoption & Risk Report, measured across corporate endpoint telemetry rather than self-reported survey.

How it works

One extension, between the keyboard and the network.

Your analyst

Types as usual

Their own account, their own workflow. No proxy, no gateway, no second login.

chatgpt.com · claude.ai · gemini.google.com
Vaktor, on the device

Swaps the sensitive parts

Personnummer by Luhn checksum, IBANs by mod-97, client names against your list. Each match becomes a numbered placeholder.

runs on the laptop
The model

Answers the placeholder version

[KLIENT_1] holds the slot the real name did. Vaktor puts the values back as the answer renders.

the reader sees the real names
Compliance

Reads a separate ledger: categories, counts, dates, users. Never the prompt text, which is not transmitted and therefore cannot be produced.

Demo

Put your own text through it.

Runs in this page, on your machine, on the same code that ships in the extension. Open the network tab if you would like to watch nothing happen.

What the model receives

Recognises Swedish personnummer and organisationsnummer, IBANs, emails, and a sample client list (Erik Lindqvist, Nordkap Fond, Åsa Sjöberg). In a deployment the list is yours. Every identifier here is an official Swedish test number.

Verification

Don't take our word for it.

Vaktor is never in the prompt path. The browser sends to OpenAI or Anthropic exactly as it did before, and our endpoint receives a category, a count and a timestamp.

Your security team can settle it in an afternoon with a proxy and a packet capture. No source access, no NDA first.

api.openai.com Masked prompt
api.anthropic.com Masked prompt
api.vaktor.ai Category, count, time

Prompt text appears in none of these

Questions

Mostly from whoever signs off.

If yours is not here, ask it on the call. We would rather answer it before you buy.

What do you store?
Categories, counts, timestamps and the user. Never prompt text, which stays on the device. A full breach of our backend would expose nothing a client told you in confidence.
What happens when detection misses something?
Checksums make false positives rare and misses possible, so treat this as one layer rather than the whole control. Unusual names are the usual gap, which is why the client list is configurable and why the ledger records what was caught rather than claiming nothing got through.
Which tools does it cover?
ChatGPT, Claude, Gemini and Perplexity in the browser, each on the user's own account. Copilot is next. New surfaces arrive as updates to the same extension.
What about the desktop apps?
Not covered yet. Browser first, because that is where the work is happening. A desktop agent is on the roadmap and the ledger format already has room for it.
Does it slow anyone down?
Masking happens as they type, on their own machine, in single-digit milliseconds. Nobody changes how they work, which is the only reason a control like this survives contact with a trading desk.
Does the answer get worse?
A placeholder such as [KLIENT_1] occupies the same grammatical slot as the name it replaced, and repeat mentions reuse the same number, so the model can still tell two people apart. Real values are restored in the browser, so the reader sees the original names.
How do we know nothing leaves the laptop?
Standard network monitoring. Vaktor is never in the prompt path, so a packet capture settles it. See verification.
GDPR, DORA, NIS2?
Masking supports data minimisation before anything reaches a third-country model, and the ledger drops into DORA and NIS2 evidence requests. The legal judgment stays with your DPO. We supply the record, not the opinion.

Bring a prompt you would rather not have sent.

Thirty minutes. We run your own text through it and you see what would have stayed on the laptop.

Or write first: [email protected]