Aegis OmniGuard scans your input locally for credit cards, API keys & crypto mnemonics before sending to AI chatbots. 100% offline. Zero cloud. Open source.
Install Aegis OmniGuard in one click. Free, lightweight (215 KB), and ready to protect you in seconds.
Install from Chrome Web Store →Every day, millions of users paste sensitive data into AI chatbots without realizing the risk.
Two shields. One extension. Zero data leaves your browser.
Real-time scanning of everything you type or paste into AI chatbots. Detects credit cards, API keys, mnemonics, private keys, PII, and .env secrets before they leave your browser.
Phase 1 — LiveIntercepts MetaMask eth_sendTransaction, eth_signTypedData, and personal_sign calls. Analyzes contracts for unlimited approvals, permit exploits, and phishing signatures.
Phase 2 — LiveBitcoin WIF keys (Base58Check + SHA-256), Solana keypairs, Tron private keys, and Ethereum hex keys. Plus BIP-39 mnemonic detection in English and Chinese.
BTC · ETH · SOL · TRONBring Your Own Key for deep Web3 contract analysis. Supports OpenAI (gpt-4o-mini), Anthropic (claude-haiku-4), and DeepSeek. Keys encrypted with AES-256-GCM.
Optional · Off by DefaultFull English and Chinese (Simplified) support with 93 translation keys across all pages. One-click language toggle. Preference persisted automatically.
EN · 中文All in-page UI (toast notifications, alert panels) injected via Shadow DOM with mode:closed. Complete style isolation from any website's CSS. Works everywhere.
Shadow DOM IsolationInstall once. Aegis works silently in the background, protecting every keystroke.
Text enters an input field or contenteditable element on any webpage
Regex pre-filter + Luhn + BIP-39 + Shannon entropy analysis runs locally
Sensitive data identified with confidence scoring and type classification
Content replaced with **** before sending. Shield notification confirms the block.
Fast regex pre-filter, then algorithmic confirmation. Minimal false positives.
13-19 digit validation. Random numbers pass through.
12/24 word sequences. English + Chinese supported.
ETH (0x+64 hex), BTC WIF, SOL, TRON chains.
Pattern match with near-zero false positives.
Claude API key detection.
20-character key ID format match.
All GitHub token formats detected.
Google API key pattern recognition.
DATABASE_URL, API_KEY, SECRET, TOKEN patterns.
Mathematical verification, not just pattern.
Chinese mobile number format.
Common email format detection.
Generic API keys and secrets > 20 chars.
Built on Chrome Manifest V3 with strict privilege separation.
Content Scripts (Isolated World) + Main World ES6 Proxy for window.ethereum hijacking
DLP scanning, Web3 contract analysis, AES-256-GCM encrypted key vault, LLM API proxy
React 19 Popup + Shadow DOM toast notifications & alert panels (zero CSS conflicts)



Credit card, API key, mnemonic, PII detection. React/Vue state sync. Shadow DOM UI. Whitelist & logging.
MetaMask transaction interception. Multi-chain key detection (BTC/ETH/SOL/TRON). BYOK LLM analysis. Chinese language support.
Phishing URL database. Cross-chain bridge monitoring. Enhanced false positive tuning. Community-contributed rules.
Admin dashboard. Centralized policy management. Team deployment. Advanced rule packages.
Firefox extension. VS Code / Cursor integration. Edge Add-ons. System-level clipboard guardian.
Click "Add to Chrome" from the Chrome Web Store. The extension icon appears in your toolbar.
Click the shield icon. Ensure the Protection toggle is ON (green). Choose your protection level.
Open ChatGPT or Claude. Paste 4111 1111 1111 1111 and hit Enter. Watch it get blocked!
Add trusted domains to Whitelist. Adjust protection level. Check Logs for interception history.
Protection Levels
All scanning runs entirely in your browser. Zero network requests for detection.
No analytics, no tracking, no data collection of any kind. Ever.
API keys encrypted with per-installation secrets + random salts via WebCrypto.
Every line of code is public under MIT License. Inspect, fork, contribute.