A full AI chat client with a built-in 127-rule detection engine, Security Workspace (Gitleaks + Semgrep + AI review), MCP servers, and a browser extension. Every byte of detection runs on your device.
Every message you type passes through a local detection and tokenization pipeline before reaching any AI provider. Raw secrets are never sent.
AI Shield Chatbot is a native desktop chat client — not a wrapper. Every capability is built in, from conversation history to a full SAST pipeline.
10 categories: API keys (79 patterns, 70+ providers), private keys, credentials, database URIs, PII, financial data, India PII (PAN/Aadhaar/UPI), infrastructure identifiers. CVSS-like risk scoring 0–100.
Projects, conversation history, system prompt, @-mention any previous conversation as context (Interchat), stop/retry, streaming response with live token restoration.
OpenAI, Anthropic, Gemini, Mistral, Groq, NVIDIA NIM, Together AI, DeepSeek, Perplexity, OpenRouter, Azure OpenAI, Portkey, Bifrost, local Ollama/LM Studio, Claude Code subscription.
HTTP (loopback) and stdio (local process) transports. Explicit consent gate before any stdio server is launched — you approve the exact resolved command line. Tool output is sanitized too.
Chrome/Edge extension for ChatGPT, Claude.ai, Gemini, and Copilot. Same tokenization pipeline, entirely in-browser — no request leaves your browser to VaultMorph servers.
Index your own documents. On-device chunking and embeddings, AES-256-GCM encrypted SQLite storage. Semantic retrieval prepends context to your prompts — never uploaded anywhere.
Local Whisper (ggml models). No audio or transcript leaves your device. Import any ggml-*.bin model — the app never downloads one automatically.
Ask the AI to create Excel, Word, or PowerPoint files. A structured DocGenSpec (tokens only) is sent to the AI; local JS renders the real file. No AI-generated code is executed on your device.
Attach PDFs, Word docs, spreadsheets, images, code files. Every attachment is scanned through the detection pipeline before its content is included in the prompt.
API keys are AES-256-GCM encrypted and stored in Windows Credential Manager or macOS Keychain. Never written to plain text config files.
De-identified HTML and CSV audit exports of Security Workspace findings. No raw secrets — SHA-256 hashes only. Date range filter. SIEM-ready CSV.
AI-generated HTML/JS responses rendered in an isolated WebView with a typed postMessage protocol. Sandboxed code cannot access your sessions, API keys, or file system.
Rule packs are signed with Ed25519 and cryptographically verified before import. Only VaultMorph-signed packs are accepted. 110 rules are available in Community; 17 additional pro-only rules in Pro Trial / Enterprise.
Scan folders or remote repositories for hardcoded secrets and vulnerabilities. Gitleaks and Semgrep run as local sidecar binaries — no finding leaves your machine. AI verdicts review each finding and classify it.
Bundled sidecar binary scans for 127 secret patterns across your entire codebase. Finds keys in history, not just the working tree.
Static analysis across 7 pinned rule sets: injection, XSS, auth, crypto, deserialization, path traversal, and misconfiguration. Vendored rules — no internet needed.
Each finding is sanitized (secrets tokenized) then sent to your AI provider for structured review. Verdict: confirmed · false_positive · needs_review.
Export a full report with findings, verdicts, risk scores, and remediation actions. De-identified — no raw secrets in the export.
Select any folder on your machine. Supports file extension filters and .gitignore patterns.
Clone via HTTPS with a PAT stored in the encrypted PAT vault (AES-256-GCM, masked on readback). Branch/tag selection, 10 MB file cap, cleanup prompt after scan.
Community is free forever with no time limit. Pro Trial gives you everything for 6 months — no credit card required.
Free community build — no sign-up, no account, no cloud. Just install and your secrets stay yours.
8655159637b02f546e773d7e62d6a507bb967b8b4650db35a627fcbed881a8ac