pgshadow status,
then work down this list.
Traffic isn’t being intercepted
If prompts pass through with no verdicts showing up, the agent isn’t seeing the traffic. Check, in order:Confirm the agent is running and healthy
pgshadow doctor runs the same checks with more detail.Confirm the proxy is applied
The PAC proxy must be set where your traffic actually flows. Turning
protection off and back on in the app re-applies both the proxy and the
certificate trust — that’s the quickest fix on every platform. To check by
hand:
- macOS
- Windows
- Linux
The proxy is set per network service (Wi-Fi vs. Ethernet vs. VPN), and
switching networks can leave a service uncovered. Check System
Settings → Network → your service → Details… → Proxies for the
automatic proxy configuration.
Gemini / Chrome traffic slips past
Chrome and some Google properties (including Gemini) prefer QUIC / HTTP-3, which runs over UDP and can route around the HTTP proxy entirely — so that traffic is never inspected. Fix: disable QUIC via browser policy. In a managed fleet, push a policy that turns off the experimental QUIC protocol (for Chrome, theQuicAllowed=false
enterprise policy). With QUIC off, the browser falls back to HTTPS over the
proxy and inspection resumes.
A specific app is never inspected
Some native desktop apps pin their own certificate and reject the agent’s CA outright. These bypass any inspection proxy and are out of scope by design — this is not a misconfiguration. See Known Limitations for the full list and the coverage policy.The engine is unreachable
The agent calls a remote/guard engine for each verdict. If it can’t reach the
engine, it waits up to 8 seconds, then fails open — the request is allowed
through rather than blocking the employee’s work.
- A short spike of allowed-without-verdict events during a network blip is expected, not a bug.
- If it’s persistent, check connectivity to the engine (
pgshadow status/pgshadow doctor) and, for self-hosted deployments, that the engine instance is healthy. See Deployment Modes.
Fail-open is the shipping behavior: availability of AI tools is preserved during
an outage. If your environment requires fail-closed, contact
support@promptguard.co to discuss options.
SmartScreen blocks the Windows installer
The Windows build is early access and the installer is not yet code-signed, so on first run SmartScreen shows “Windows protected your PC.” This is expected: click More info → Run anyway. Before you do, verify the installer’s SHA-256 checksum against the value published with the release:Where logs and config live
The agent keeps its state in one directory on every platform:| Platform | Location |
|---|---|
| macOS / Linux | ~/.promptguard/ |
| Windows | %USERPROFILE%\.promptguard\ |
config.json (credentials — never share this file),
pgshadow-proxy.log (the proxy log, useful for support), and events.db (the
local, PII-redacted event log).
Collecting logs for support
When you open a ticket, include the output of:pgshadow-proxy.log from
the directory above if asked (never config.json — it holds your device
credential). Send it all to
support@promptguard.co.
Next steps
Known limitations
What’s out of scope and why.
Privacy & data handling
What the agent logs and what reaches the cloud.