Free Tools / AI Security
Shadow AI Data Leak Scanner
Check any text for API keys, passwords, personal data, and proprietary code — before it goes into ChatGPT, Claude, or Copilot.
Runs on Framz-owned hardware — your text never touches a third-party AI
Runs on Framz hardware. Your text is never stored or sent to a third-party AI.
Your results will appear here. Nothing is sent until you press Scan for leaks.
How it works
1. Paste
Drop in the prompt, code, email, or document you were about to share with an AI tool.
2. Scan
19 credential and PII pattern rules run instantly. The optional AI deep check reviews context on our own hardware.
3. Decide
Get a clear verdict — safe, review, or do not paste — with every finding listed and masked.
What it detects
The same categories a corporate data-loss-prevention system watches for — free and in seconds.
Credentials & secrets
AWS, OpenAI, Anthropic, Stripe, GitHub, Google and Slack keys, private key blocks, JWTs, bearer tokens, connection strings, hard-coded passwords.
Personal data (PII)
Emails, phone numbers, US SSNs, UK National Insurance numbers, IBANs — plus names, addresses, and health or financial details via the AI deep check.
Payment data
Card numbers validated with the Luhn algorithm to avoid false alarms on random digit strings.
Proprietary content
The AI deep check judges whether text reads like confidential source code, internal documents, or client material.
AI Data Governance Policy Template
A ready-to-adapt policy for controlling what your team shares with public AI tools.
Sent to the work email you verified for tool access. No newsletter, no spam — ever.
Frequently asked questions
Is my text stored or sent to OpenAI, Google, or another AI company?+
No. Pattern matching runs on our servers and the optional AI deep check runs on AI hardware Framz owns and operates. Your text is processed in memory, never stored, and never sent to any third-party AI provider.
What exactly does the scanner detect?+
Cloud and API credentials (AWS, OpenAI, Anthropic, Stripe, GitHub, Google, Slack, SendGrid), private keys, JWTs, database connection strings, hard-coded passwords, payment card numbers (Luhn-validated), US SSNs, UK National Insurance numbers, IBANs, email addresses, phone numbers, and internal IP addresses. The AI deep check additionally flags proprietary-looking code and confidential business content that patterns alone cannot catch.
Why is pasting company data into public AI tools risky?+
Public AI chatbots may retain prompts for abuse monitoring or model improvement depending on plan and settings, and pasted secrets live on in chat history, logs, and browser extensions. Once a credential or client record leaves your perimeter, you cannot revoke the copy — only the credential. Most companies now treat unreviewed AI pasting ("shadow AI") as a data-loss vector.
Is a "safe" result a guarantee?+
No automated scan is perfect. A clean result means no known credential formats or common PII patterns were found — it does not replace your judgment about business context, contracts, or regulated data.
Can my whole team use this?+
Yes, it is free without signup. If you want this behaviour enforced automatically — a policy, gateway, or private AI setup so staff can use AI safely — that is exactly what we build. Get in touch.
Worried about shadow AI across your whole team?
We build private AI setups, gateways, and governance so your staff get the benefits of AI without leaking client data.