Security and compliance

Built for environments where data governance is non-negotiable.

GhostPrompt's local architecture makes it suitable for regulated industries, government environments, and any organization with strict data residency or DLP requirements.

Architecture
Where GhostPrompt sits.

GhostPrompt operates entirely at the pre-prompt construction stage, on the user's device, before any content reaches an AI provider. It is not middleware, not a proxy, not an agent runtime, not a browser extension, and not a request interceptor. There is no network path between GhostPrompt and any AI model.

User device
  Document or prompt    GhostPrompt detection    Entity replacement    Sanitized copy
                                                                                              ↓ user pastes manually
AI provider
  ChatGPT / Gemini / Copilot / any tool    receives sanitized version only

No network connection exists between GhostPrompt and any AI provider.

Scope
What GhostPrompt solves. And what it does not.
In scope

LLM02: Sensitive Information Disclosure

Specifically, accidental PII, financial data, and confidential entity disclosure when employees paste documents into third-party AI tools. GhostPrompt addresses this one failure mode precisely, by replacing sensitive entities before any content reaches a model provider.

Explicitly out of scope
XPrompt injection (direct or indirect)
XJailbreak detection or prevention
XSystem prompt extraction
XTool misuse or agent runtime security
XMulti-turn conversation monitoring
XModel provider data retention enforcement
XHiding prompts from the AI model itself

We address LLM02 only. These are real and important problems, but they require different architectural approaches. GhostPrompt does not attempt to solve them.

Our threat model

The attacker in GhostPrompt's threat model is not an external adversary. It is the well-intentioned employee who pastes a client contract, financial model, or HR document into ChatGPT without recognizing the exposure. The threat is accidental disclosure to a third-party AI provider at scale, repeated across an organization, without any malicious intent. GhostPrompt assumes manual review will always miss something. That is why detection runs automatically.

Compliance positioning

The items below describe GhostPrompt's architectural alignment with each framework. These are self-assessed positions based on the product's local-only, zero-telemetry design. Formal third-party certifications (SOC 2, ISO 27001, IRAP) are not in place today and will be pursued post-beta based on customer demand.

PIPEDA aligned
Canadian privacy law. No cross-border data transfer. No third-party processing. Self-assessed alignment.
GDPR aligned
EU data residency requirements met by design. No processing occurs outside your device. Self-assessed alignment.
Zero telemetry
No usage data, no analytics, no document telemetry collected from within the application. Verifiable via network capture.
DLP complementary
Endpoint-local detection complements and extends existing organizational DLP policy without conflict.
Protected A suitable
Architecturally suitable for Canadian government Protected A contexts: no cloud processing, no data residency concerns. Formal ITSG-33 control mapping and Security Assessment & Authorization have not been pursued and are not required for individual-use licensing.
Air-gap capable
Sanitization requires no internet connection. Fully functional in air-gapped or restricted network environments.
Note on naming

GhostPrompt the privacy tool is unrelated to academic research on prompt injection attacks published under similar names, including the 2025 arXiv paper describing a jailbreak technique. We are a document sanitization product. We have no connection to jailbreak research, prompt injection exploits, or AI security vulnerability disclosure of any kind. If you encountered GhostPrompt in a security context, it was not us.

Security FAQ
Does GhostPrompt send any document content to your servers?
No. GhostPrompt processes all content locally. We have no server infrastructure that receives document content. Monitor your network traffic during use and you will observe zero document-related outbound requests during sanitization.
Can GhostPrompt operate in an air-gapped or restricted network environment?
Yes. The sanitization engine requires no internet connection. All entity detection and replacement runs entirely on-device. License validation requires a one-time internet connection at activation but not during ongoing use. GhostPrompt is suitable for deployment in air-gapped, restricted-network, and classified computing environments.
What data does GhostPrompt log by default?
Nothing is logged to us. The only local storage GhostPrompt creates is the session replacement manifest, a record of what was detected and replaced in that session. This manifest is stored on your device, under your control, and is never transmitted. Retention is entirely at the user's discretion. We collect no usage analytics, no error telemetry, and no document content.
How does license validation work without sending data?
License validation sends only an anonymous device fingerprint and your license key ID. No document content, entity data, or replacement manifests are included. The validation payload is under 200 bytes.
Does GhostPrompt guarantee 100% detection of all sensitive data?
No, and we will not claim that it does. GhostPrompt significantly reduces exposure by catching the entities your manual review misses. It is a risk-reduction tool, not an absolute guarantee. You remain responsible for reviewing content before sharing with any AI platform. We will publish detection accuracy data from our beta program when available.
What data residency guarantees does GhostPrompt provide?
Because all processing is endpoint-local, your documents never leave your jurisdiction. There is no cloud processing to route through foreign data centers. This makes GhostPrompt suitable for environments with strict data residency requirements including Canadian government Protected A classification contexts.
Is GhostPrompt auditable?
The replacement manifest generated for each session is stored locally and available for audit review. Each session produces a full log of what was detected, replaced, and retained. No external audit trail is created. Everything stays on your device.
What are GhostPrompt's detection accuracy rates?
We are currently in pre-launch and do not have live deployment metrics to publish. We will publish entity detection accuracy data within 90 days of beta launch, based on controlled internal benchmark testing. The tool collects no usage data from user sessions. Benchmark results come from our own test document sets, not from monitoring what you process. We believe in being honest about limits. That is the only basis on which a security-adjacent product can build trust.
Can GhostPrompt be deployed organization-wide without IT involvement?
Yes. GhostPrompt requires no server configuration, no cloud provisioning, and no network policy changes. Each installation is self-contained. Organizations can distribute licenses and let individuals install independently without IT configuration.
Whitepapers and standards
Authoritative guidance from government and industry bodies.

The frameworks and standards that define responsible AI security practice. Each links directly to the original document.

LLM
Top 10
OWASP Top 10 for LLM Applications 2025
The definitive open-source reference for LLM application security risks. GhostPrompt addresses LLM02: Sensitive Information Disclosure, the specific risk of user-supplied sensitive data reaching model providers.
View online → Download PDF →
NIST
AI
NIST AI Risk Management Framework (AI RMF 1.0)
The US government's voluntary framework for incorporating trustworthiness into AI systems. Covers data privacy, confidentiality, and information security throughout the AI lifecycle. Widely adopted by enterprise procurement as a baseline governance requirement.
NIST AI RMF at nist.gov →
NIST
GenAI
NIST AI RMF: Generative AI Profile (NIST AI 600-1)
Extends the AI RMF specifically to generative AI risks, including data privacy violations, information security failures, and sensitive data disclosure through user-provided prompts and documents.
NIST AI 600-1 at nist.gov →
CCCS
CA
Canadian Centre for Cyber Security: Generative AI Guidance (ITSAP.00.041)
The Canadian government's official cybersecurity guidance on generative AI risks, including data leakage through LLMs and the risks of employees submitting sensitive information to public AI platforms. Directly relevant to PIPEDA compliance contexts.
CCCS ITSAP.00.041 at cyber.gc.ca →
ABA
512
ABA Formal Opinion 512: Generative AI Tools in Legal Practice
The American Bar Association's first formal ethics guidance on AI use. Requires informed client consent before entering client information into self-learning AI tools. Directly applicable to any legal professional using AI for document work.
ABA Formal Opinion 512 at americanbar.org →
Questions about enterprise deployment?

Email us at hello@ghostprompt.io. We respond within one business day.

Contact us