Protect my own device
For an individual trying it out. Open the app, sign in, turn it on — about
two minutes, no technical setup.
Roll it out to my company
For IT and security leaders. Push it to every employee’s device and watch
all AI activity in one dashboard.
Protect your device
1
Download the app
Grab the installer for your platform from
promptguard.co/download — no waitlist,
no sign-up required to download.
- macOS — a universal
.dmg(one installer for Apple Silicon and Intel), signed and notarized by Apple. - Windows — an
.exeinstaller (an.msiis also available for admins). Early access: the Windows installer is not yet code-signed, so SmartScreen will warn on first run. - Linux — an
.AppImageor a.debpackage (x64).
2
Install it
- macOS
- Windows
- Linux
Double-click the
.dmg and drag PromptGuard Shadow into
Applications. When you turn protection on you’ll be asked once to
approve the secure HTTPS-inspection certificate with your Mac password.3
Sign in
Click the PromptGuard shield in your menu bar, then Connect this
device. Your browser opens, you sign in with your work account, and you’re
returned automatically — no keys or codes to copy.
4
Turn on protection
Click Turn on protection. You’ll be asked once to approve the secure
inspection certificate. After that it runs quietly in the background.
5
You're protected
The shield reads “You’re protected.” That’s it — keep working in ChatGPT,
Claude, and the rest, exactly as you do today.
See it work
In ChatGPT (or Claude), try these and watch what happens:
Click the shield → Activity to see every decision, why it was made, and a
one-click way to copy a safe version of anything that was blocked.
Deploy to your company
You don’t install Shadow AI machine-by-machine. An admin rolls it out once and manages the whole fleet from the dashboard:1
Create an enrollment token
In the dashboard, go to Fleet → Enrollment Tokens. This one token enrolls
as many devices as you allow.
2
Push it to your devices
Deploy the app through your existing MDM (Jamf, Intune, Kandji, …) with the
token. Employees get protection with zero action on their part — no
sign-in prompt, no certificate click.
3
Watch everything in one place
Every block, redaction, and allowed prompt — across browser and desktop —
rolls up to your dashboard, attributable per employee, revocable per device.
Full fleet rollout guide
Tokens, per-device credentials, attribution, and instant revocation.
Turn it off
Click the shield → Turn off protection (or, while paused, it resumes automatically). Uninstalling the app removes the certificate and all local data.Advanced: install from the command line
Advanced: install from the command line
For automated or headless rollouts, the agent ships a CLI. From the unpacked
bundle:Managed fleets enroll with a token instead of a key:See the Desktop Agent reference for every command,
coverage details, and deployment tiers.