Panoptes Privacy Policy

Last updated: 2026-07-16

Panoptes is a data-loss-prevention tool for AI assistants. It inspects what you send to AI chat services and warns you when it detects sensitive data (PHI, PII, credentials, financial data) before you send it. Because Panoptes exists to protect sensitive data, it is built to hold as little of it as possible and to send none of it anywhere you did not explicitly configure.

This policy is the privacy policy for the Panoptes browser extension (Chrome / Chromium), published by Ironwright. Panoptes is also available as a separate VS Code extension with additional enterprise DLP, SIEM, and email alert integrations; those integrations do not exist in the browser extension and are called out below wherever they would otherwise be confused with it.

The short version

What Panoptes processes

Two capabilities in the browser extension are off by default and process more than text once you turn them on:

What Panoptes sends, and where

This browser extension only sends data to destinations you configure. Out of the box, all three of these are off:

ChannelDefaultWhat is sent
Webhook (Slack/Teams/custom endpoint)OffRedacted finding metadata
Central reporting serverOffRedacted finding metadata
Policy server (organization deployments)OffNothing about you or your text. Panoptes only fetches your organization's detection policy, sending the access token you configured and, if set, your team name

This browser extension has no SIEM, DLP, or email (SMTP) alert channel. Those integrations (Splunk, Elastic, QRadar, Sentinel, Chronicle for SIEM; Purview, Symantec, Forcepoint, Digital Guardian for DLP; and SMTP email) exist only in the separate Panoptes VS Code extension, not in this browser extension.

Before any alert is sent, Panoptes strips the raw prompt/response snippet and masks matched values, so the sensitive data that triggered the alert is not reproduced in the alert. Every destination above must use https, whether or not it carries a credential; Panoptes refuses to send to a plain http endpoint.

What Panoptes stores

A local detection-metadata log file is a feature of the separate Panoptes VS Code extension, not this browser extension; the browser extension writes no log file to disk.

Third parties

Panoptes has no advertising, no third-party analytics, and no data brokers. The only third parties that ever receive data are the alert destinations you point this browser extension at (your own webhook or your own central monitoring server).

Your control

Contact

Questions or privacy concerns: hello@ironwright.dev.