Nesgate: let staff use AI without handing over your data

In most organizations, staff now paste text into AI tools such as ChatGPT to draft letters, summarize reports or check figures. Some of that text contains customer records, ID numbers, passwords or confidential plans. Once it is sent, the organization loses control of it. Under Indonesia’s Personal Data Protection Law (UU PDP), it is still responsible for the personal data involved.

Nesgate is a browser extension that deals with the problem where it starts. It spots sensitive data on the employee’s own device and masks it before the prompt reaches the AI tool.

NESGATE · AI DATA-LEAK PREVENTION VISIT NESGATE.COM → ON-DEVICE MASKING BROWSER EXTENSION · NO PROXY · NO AGENT

What it looks like in practice

The employee writes a normal request. Nesgate swaps the sensitive values for placeholders before anything is sent, and the AI tool still has enough context to help.

TYPED BY THE EMPLOYEE
Refund 4111 1111 1111 1111 for jane@example.com
SENT TO THE AI APP
Refund [CARD_1] for [EMAIL_1]

The card number and the email address stay in the browser. The request still makes sense to the AI tool, and the employee gets on with the job.

Why not simply block AI?

Blocking looks safe on paper. In practice, people move to personal phones and accounts, and the security team can no longer see what is being shared. Nesgate keeps AI available and removes only what should never leave the organization.

It also shows which AI apps people use without IT approval, often called “shadow AI”, so you can decide which ones to allow.

On-device
Detection and masking
3
Responses: Mask, Warn or Block
Self-host
Option with Docker and PostgreSQL

How it differs from other approaches

Data loss prevention (DLP) tools watch for sensitive information leaving the organization. Many of the AI-focused ones inspect prompts in the vendor’s cloud or through a proxy (a server that sits between your staff and the internet). Nesgate does the check on the device instead.

  Block AI apps Cloud or proxy AI DLP Nesgate
Productivity Lost; people move to personal accounts Kept Kept; only the sensitive part is masked
Where prompts are checked Not applicable Usually in the vendor’s cloud or a proxy On the device, before sending
How it is deployed Network or firewall rules Proxy or endpoint agent A browser extension

What it checks

Typed text is only part of the risk. Nesgate also checks PDFs, Word and Excel files, and even photos of ID cards before they are uploaded, reading the text in images on the device itself. It recognizes Indonesian and international identity numbers out of the box and validates them with checksums, which keeps false alarms low.

You can also teach it what is confidential to you: project code names, customer lists, or fingerprints of sensitive documents. These lists are scrambled (hashed) in the browser before they are uploaded, so Nesgate never holds them in readable form.

What administrators control

  • How Nesgate responds when sensitive data appears in a prompt: mask it, warn the person, or block the prompt. Finance, Legal or a single person can have their own rules, and changes reach every browser within a minute.
  • Which AI apps are in use across the organization, and what to do about the unapproved ones.
  • A tamper-evident audit trail of incidents and admin actions, where any later change to the record would show. Nesgate’s own support actions appear in it too.
  • An investigation view: pick a person, a browser or an AI app and see everything connected to it, to tell a one-off mistake from a pattern. Content stays masked throughout.
  • Alerts sent to Slack, Microsoft Teams, Splunk or another SIEM (the system your security team uses to collect alerts), a webhook or email.
  • Sign-in through single sign-on (SSO), with users added and removed automatically through SCIM (the standard that keeps accounts in step with your identity system).

Where your data stays

Masking happens on the device, so sensitive values are removed before a prompt reaches any AI tool. The Nesgate console only ever receives the type of data found, the action taken and a masked preview, never the original value. If the console cannot be reached, protection on the device keeps running. Backups are encrypted, retention is configurable, and each customer’s data is kept separate.

Some organizations also want the management side in-house. For them, Nesgate can be self-hosted on their own servers with Docker and PostgreSQL. Banks and public bodies whose policies require security records to stay inside their network usually prefer this route.

Getting started

Nesgate is in early access. It runs on Chrome and Edge today, with Firefox in testing. There is no proxy to install and no agent on each laptop. IT installs the extension and connects every browser with one deployment key or an invite link, so staff never type a code. Once the browser store listings go live, it can also be pushed out through Intune, Google Admin or Jamf.

Teams can start with a 14-day trial for up to 25 browsers, with no credit card. Larger organizations can run a guided 30-day pilot for 100 seats or more. Individuals get one browser free, and a 14-day Pro trial when they sign up.

It is a good fit for security, IT and compliance teams in finance, healthcare, legal and technology who want to allow AI at work while keeping personal data under control. Nesgate stops new leaks through AI tools. To find data that has already leaked elsewhere, pair it with Snipeyes DBM. If you build AI applications of your own, our AI security testing checks them for weaknesses.

Allow AI at work, safely

Start a trial at nesgate.com, or book a walkthrough with our team to plan a pilot for your organization.

Early access • Chrome and Edge • Self-host option