Data loss prevention for AI

Your team pastes anything into AI.

Sorbe is the last check before your data reaches an AI tool. It inspects every prompt, paste, and file on the device — the instant before send — and stops what shouldn’t leave. Your team keeps moving. Your secrets stay put.

The Sorbe mark, floating behind a pane of glass.

Watching the tools your team already uses

ChatGPT
Claude
Gemini
Perplexity
Copilot
DeepSeek
Grok
Mistral
Cursor
VS Code
v0
Replit
Gmail
Notion
Claude Desktop
Slack
Outlook

How it works

Read. Decide. Deliver.

Every send runs the same three steps — on the endpoint, in milliseconds, before a byte gets out.

Step 01

Read

The prompt, the paste, the file, the request body — parsed and inspected on the device, in every language, the moment before send.

Step 02

Decide

Your policy runs the same way every time — allow, mask, or block. Same input, same decision, and a record of exactly why.

Step 03

Deliver

Clean content passes untouched. Sensitive content is stopped, or handed back masked — so the work still ships.

Try it — right here

Paste something you shouldn’t. Watch it get caught.

This is the real detection engine, running entirely in this browser tab. Type or paste anything — a card number, an API key, an email. Sorbe flags it the instant before it could be sent, and not one byte leaves this page.

Sorbe · inspecting in your browserNothing here is sent anywhere
Clear to send — nothing sensitive foundTry editing it · 0 bytes left this page

Live, on-device detection — no network, no logging. Clear it and paste your own.

Watch it work

A leak, caught in the composer.

Someone drops a customer export into ChatGPT and reaches for send. Before the request can fire, Sorbe opens the file on the device, finds the card numbers and the live key inside, and stops it — with the reason in plain language, and a safe version ready to go.

  • Inspected on the device — the bytes never leave to be scanned.
  • Every finding surfaced, masked, and logged.
  • The send is stopped — not just flagged after the fact.
ChatGPT5
Sorbe

Happy to help — attach the file and I’ll summarise it.

customers-export.csvSpreadsheet · 2,481 rowsInspecting · /2,481
Summarise churn risk from this export
Tools
Blocked by Sorbe3 findings
  • Credit cardPCI···· 4821
  • Israeli IDPII···· 5729
  • AWS secret keySecretAKIA····
Send masked versionKeep editing

The problem

Blocking alone does not work.

A block with no way out is a block people route around. The same prompt just goes to a phone, a personal login, or a browser with nothing watching — and now you’ve lost both the data and the record.

So when Sorbe stops something, it hands back the same message with the sensitive parts masked, shows exactly what changed, and lets you send that instead. The work continues. The data stays.

What you typedBlocked

Refund the customer, card 4532 5312 8841 4821

offered instead
Safe to sendMasked

Refund the customer, card •••• •••• •••• 4821

Coverage

Wherever data leaves, we’re already there.

Browser, desktop, network — three ways data gets out to AI, three places Sorbe inspects it in real time. And each one tells you honestly when it can’t.

The browser

An extension that inspects the composer before the send fires — ChatGPT, Claude, Gemini, Copilot, and every other site through a generic adapter.

Reports back whether the send was actually stopped.

The desktop

A local agent that inspects what native apps and IDEs send — Cursor, Claude Desktop, Copilot in your editor — before it reaches the provider.

Runs behind a certificate authority you install deliberately.

The network

A gateway your own apps call instead of the model provider. Same rules, same record, applied to everything you build.

Every decision is deterministic and reproducible.

What we claim

And what we refuse to.

Security products are graded on what they promise. These are ours — written the way they’re enforced in the code.

On-device inspection
Content is analysed on the endpoint. It never leaves to be scanned.
Deterministic decisions
The same content and policy always reach the same decision — reproducible long after the fact.
Proof, or it doesn’t count
A channel that can’t prove it prevented something says so, rather than claiming it did.
Masked in the record
The console keeps the incident and a masked preview — never the sensitive value itself.

Pricing

Priced per person, not per promise.

Start with one team for a week. Roll it out when the first report settles the argument.

Pilot

Freeone team, one week

Point it at a single team and let the first report make the case.

  • One channel
  • Up to 25 seats
  • Masked audit log
  • Community support
Start a pilot

Team

Most teams
$18per seat · month

Every exit enforced, with the record your auditors ask for.

  • Browser, desktop & network
  • Up to 500 seats
  • Full policy engine
  • Email support
Request access

Enterprise

Customannual

For fleets that need SSO, self-hosting, and a name to call.

  • Unlimited seats
  • SSO & SCIM
  • Self-hosted option
  • Dedicated support
Talk to us

Every plan inspects on-device and keeps a masked, auditable record. No card required to pilot.

About us

Built for the way data actually moves.

Your people work across browsers, editors, desktops, and the services you build — and sensitive data flows through all of them. Sorbe watches those exits from the endpoint, so the decision happens where the data is, not after it has already gone.

We’re a small team of security and infrastructure engineers. We’d rather ship a claim we can prove than a promise we can’t — which is why every channel reports whether it actually stopped something, and says so plainly when it couldn’t.

Israeli PIICredit cardsAPI keys & secretsSource codeHebrew + English