There are two ways in. Pick the one that matches you:Documentation Index
Fetch the complete documentation index at: https://docs.promptguard.co/llms.txt
Use this file to discover all available pages before exploring further.
Protect my own device
For an individual trying it out. Open the app, sign in, turn it on — about
two minutes, no technical setup.
Roll it out to my company
For IT and security leaders. Push it to every employee’s device and watch
all AI activity in one dashboard.
Protect your device
Install the app
Download PromptGuard and open the installer.
In private preview we send you the app directly — request access.
Signed, one-click installers for macOS and Windows arrive at general availability.
Sign in
Click the PromptGuard shield in your menu bar, then Connect this
device. Your browser opens, you sign in with your work account, and you’re
returned automatically — no keys or codes to copy.
Turn on protection
Click Turn on protection. You’ll be asked once to approve the secure
inspection certificate. After that it runs quietly in the background.
See it work
In ChatGPT (or Claude), try these and watch what happens:| Type this | What happens |
|---|---|
| “What is the capital of France?” | Allowed — answers normally |
| “Add this contact: Bob Smith, phone 415-555-0142.” | Redacted — the phone number is masked before it’s sent |
| “Here is my AWS key AKIAIOSFODNN7EXAMPLE” | Blocked — it never leaves your machine |
Deploy to your company
You don’t install Shadow AI machine-by-machine. An admin rolls it out once and manages the whole fleet from the dashboard:Create an enrollment token
In the dashboard, go to Fleet → Enrollment Tokens. This one token enrolls
as many devices as you allow.
Push it to your devices
Deploy the app through your existing MDM (Jamf, Intune, Kandji, …) with the
token. Employees get protection with zero action on their part — no
sign-in prompt, no certificate click.
Full fleet rollout guide
Tokens, per-device credentials, attribution, and instant revocation.
Turn it off
Click the shield → Turn off protection (or, while paused, it resumes automatically). Uninstalling the app removes the certificate and all local data.Advanced: install from the command line
Advanced: install from the command line
For automated or headless rollouts, the agent ships a CLI. From the unpacked
bundle:Managed fleets enroll with a token instead of a key:See the Desktop Agent reference for every command,
coverage details, and deployment tiers.