Skip to main content
The desktop agent is the part your team installs. Once it’s on, it watches the AI tools they already use and enforces your policy on the device, before a prompt or file reaches the AI tool — no browser extension required, because one agent covers both the AI apps in the browser (ChatGPT, Claude) and the AI APIs behind coding tools (Cursor, IDE assistants, SDKs). It ships today on macOS (signed and notarized), Windows (early access — the installer is not code-signed, so SmartScreen warns on first run; the two-click path is in the quickstart), and Linux. All three are downloadable from promptguard.co/download.

Install

Getting a single machine running takes about five minutes — install the bundle, then one guided command:

Full quickstart

Step-by-step: prerequisites, the menu-bar option, verifying, your first block, and uninstall.
The rest of this page is the reference — what’s covered, how it enforces, the deployment tiers, and the honest limits.

What it protects

The agent works from a host allowlist of known AI vendors — it inspects traffic to those hosts and leaves everything else untouched. The current list covers: This covers both the AI web apps in the browser and the AI APIs behind coding tools and SDKs. Adding a new vendor to the allowlist is a small config change on our side — see Known Limitations for how to request one. For scripted or MDM deployments, stable download URLs redirect (302) to the latest artifact:

What happens at send-time

Every paste, prompt, or upload gets one verdict in milliseconds:
  • Block — secrets, API keys, and prompt-injection attempts are stopped; the employee gets a clear notification with a short reference and a one-click copy-safe-version option.
  • Redact — PII is masked on the device, so the AI tool never receives the raw value and the employee still gets useful help.
  • Allow — everything else passes through untouched.
To reach that verdict the agent masks on the device first, then asks. The prompt it sends — with text extracted from attachments, and any images or audio — already has every masker finding replaced by its placeholder, and it travels with a {category, count} summary of what was taken out so the engine isn’t blinded by the masking. Raw prompt text is not something the agent sends anywhere. Devices pointed at an engine we don’t run go further and default to sending no prompt content at all — see What the engine is shown. If the engine is ever unreachable, the agent fails open by default — traffic is allowed through rather than blocking the employee’s work. A refused connection fails open immediately; an engine that accepts the connection but stalls gets a 30-second timeout. Organizations that need the opposite trade can set on_engine_unreachable to hold, and a prompt the engine couldn’t be asked about is then not sent at all — see If the engine cannot be reached. See Troubleshooting for what an outage looks like and Privacy & Data Handling for what is logged.

Two ways to deploy

Self-serve (today)

A user installs it and approves the certificate once. Perfect for pilots and smaller teams. A local admin can turn it off unless you push it via MDM.

Managed for enterprise

Pushed by your MDM, with a managed certificate and a tamper-resistant capture layer (macOS System Extension / Windows filtering driver). Same detection — just locked down and zero-touch for employees.

Honest limits

A few things are out of scope by design or still in progress. The short version:
Inspecting HTTPS means terminating TLS, which requires a trusted certificate on the device — in both deployment tiers. The enterprise tier doesn’t remove the certificate; it makes it MDM-managed and harder to tamper with. The agent reads content on the device and sends it to the engine for a verdict; the engine logs the verdict with a masked preview.
Some native apps pin their own certificate and bypass any inspection proxy, and QUIC/HTTP-3 can route around the HTTP proxy entirely. Image OCR isn’t supported yet either.
For the full, honest list — and how to mitigate each one — see Known Limitations.

Updates

The agent keeps itself current — you shouldn’t have to think about versions:
  • Automatic by default. Updates download and install in the background. In the app’s Settings you can switch the update mode to Notify me (you approve each update) or Off.
  • Every update is signed. Update packages are cryptographically signed and verified against a public key embedded in the app before anything is installed — an unsigned or tampered package is rejected.
  • Staged rollout. New versions roll out to a growing percentage of devices, with a kill-switch on our side that can halt a rollout if a problem is found.
  • Minimum-version floor. We can mark versions below a floor as dangerously outdated, which forces an update. Until it updates, a stale agent keeps protecting with its current policy — it never disarms — but coverage-reducing controls (like turning protection off) are locked.
  • Beta channel. Opt in from Settings to receive pre-release builds early.
Update checks go to the engine the agent is signed in to, and fall back to PromptGuard’s GitHub releases if that engine doesn’t answer. Two managed-configuration keys take that traffic off PromptGuard entirely, and both are locked against local change:
  • updater_enabled off stops every update check. No release feed, no version-policy call. The device still polls its own engine for your organization’s update settings, which is also how it heartbeats.
  • update_url, pointing at the latest.json of your mirror of our signed releases, becomes the only update source — no dynamic endpoint on the engine host, and no GitHub fallback. Mirroring doesn’t mean re-signing: every artifact is still verified against the public key compiled into the app, wherever it came from, so a mirror cannot substitute a build of its own.
A freshly imaged machine with neither a device credential nor any managed configuration makes none of those calls — not the release feed, not the version policy. With a managed enrollment token it makes exactly one, the enrollment, and starts the rest on the cycle after it has a credential. See Managed configuration for where to write those keys. On managed fleets, org admins can also force the update mode, pin the release channel, and set a minimum version for every device — see Fleet Enrollment. The agent lives in your menu bar (macOS) or system tray (Windows / Linux):
  • The shield icon shows protection state at a glance — a filled shield means protected; an outline means protection is off. Hover for a tooltip with the current status.
  • Right-click for a quick menu: protection status, Open, and Quit.
  • Click to open the popover — home, Activity (every verdict, with detail per event), tools, settings, and help. Press Esc to go back a screen or dismiss the popover.

Next steps

Roll it out to your team

Enroll many devices with scoped, revocable credentials.

Choose where your data runs

Cloud, hybrid, or fully air-gapped.