v1.0.0-beta  ·  Windows · macOS · Linux

Chat with AI.
Zero secrets leaked.
Ever.

A full AI chat client with a built-in 127-rule detection engine, Security Workspace (Gitleaks + Semgrep + AI review), MCP servers, and a browser extension. Every byte of detection runs on your device.

127-rule detection engine Zero telemetry Runs fully offline
0
detection rules across 10 categories
0
raw secrets ever sent to AI
0
AI providers supported
0
on-device processing, no cloud
// how it works

Your secrets stay on your machine. Always.

Every message you type passes through a local detection and tokenization pipeline before reaching any AI provider. Raw secrets are never sent.

Raw prompt Detect (127 rules) <<VM_TOKEN_API_KEY_1_a3f8>> tokenized in memory
Sanitized prompt AI provider AI response (with tokens)
Response with tokens Restore locally Response with real values never left your device
Token maps are in-memory only and never written to disk. If you close the session, the map is gone. Each token includes a BLAKE3 hash of the original value — restoration is cryptographically verified, not a naive string replacement.

// features

Everything you need. Nothing that phones home.

AI Shield Chatbot is a native desktop chat client — not a wrapper. Every capability is built in, from conversation history to a full SAST pipeline.

127-Rule Detection Engine v2.1.0

10 categories: API keys (79 patterns, 70+ providers), private keys, credentials, database URIs, PII, financial data, India PII (PAN/Aadhaar/UPI), infrastructure identifiers. CVSS-like risk scoring 0–100.

Full-featured AI Chat

Projects, conversation history, system prompt, @-mention any previous conversation as context (Interchat), stop/retry, streaming response with live token restoration.

20+ Providers Supported

OpenAI, Anthropic, Gemini, Mistral, Groq, NVIDIA NIM, Together AI, DeepSeek, Perplexity, OpenRouter, Azure OpenAI, Portkey, Bifrost, local Ollama/LM Studio, Claude Code subscription.

MCP Servers

HTTP (loopback) and stdio (local process) transports. Explicit consent gate before any stdio server is launched — you approve the exact resolved command line. Tool output is sanitized too.

Browser Extension

Chrome/Edge extension for ChatGPT, Claude.ai, Gemini, and Copilot. Same tokenization pipeline, entirely in-browser — no request leaves your browser to VaultMorph servers.

Knowledge Base (RAG)

Index your own documents. On-device chunking and embeddings, AES-256-GCM encrypted SQLite storage. Semantic retrieval prepends context to your prompts — never uploaded anywhere.

Voice Input

Local Whisper (ggml models). No audio or transcript leaves your device. Import any ggml-*.bin model — the app never downloads one automatically.

Document Generation

Ask the AI to create Excel, Word, or PowerPoint files. A structured DocGenSpec (tokens only) is sent to the AI; local JS renders the real file. No AI-generated code is executed on your device.

30+ Attachment Formats

Attach PDFs, Word docs, spreadsheets, images, code files. Every attachment is scanned through the detection pipeline before its content is included in the prompt.

OS Keychain Storage

API keys are AES-256-GCM encrypted and stored in Windows Credential Manager or macOS Keychain. Never written to plain text config files.

Compliance Reports

De-identified HTML and CSV audit exports of Security Workspace findings. No raw secrets — SHA-256 hashes only. Date range filter. SIEM-ready CSV.

Sandboxed Artifacts

AI-generated HTML/JS responses rendered in an isolated WebView with a typed postMessage protocol. Sandboxed code cannot access your sessions, API keys, or file system.


// detection coverage

127 rules. 10 categories. Signed and verified.

Rule packs are signed with Ed25519 and cryptographically verified before import. Only VaultMorph-signed packs are accepted. 110 rules are available in Community; 17 additional pro-only rules in Pro Trial / Enterprise.

79 API Keys (70+ providers)
6 Authentication Tokens
4 Private Keys (RSA/EC/PGP/SSH)
5 Credentials & .env Secrets
2 Financial (Cards, IBAN)
6 PII (Email, Phone, SSN)
8 Database Connection Strings
8 India PII (PAN, Aadhaar, UPI)
8 Infrastructure (IPs, MAC)
1 Network Addresses
Risk scores use a CVSS-inspired 0–100 numeric scale: Critical ≥75 · High ≥50 · Medium ≥25 · Low <25. Scores account for finding count with diminishing returns, so a single AWS key hit scores differently from a file full of minor findings.

// security workspace

SAST + Secrets Scanning + AI Review. All local.

Scan folders or remote repositories for hardcoded secrets and vulnerabilities. Gitleaks and Semgrep run as local sidecar binaries — no finding leaves your machine. AI verdicts review each finding and classify it.

01 — Scan

Gitleaks (Secrets)

Bundled sidecar binary scans for 127 secret patterns across your entire codebase. Finds keys in history, not just the working tree.

02 — Analyse

Semgrep (SAST)

Static analysis across 7 pinned rule sets: injection, XSS, auth, crypto, deserialization, path traversal, and misconfiguration. Vendored rules — no internet needed.

03 — Review

AI Verdicts

Each finding is sanitized (secrets tokenized) then sent to your AI provider for structured review. Verdict: confirmed · false_positive · needs_review.

04 — Export

HTML Report

Export a full report with findings, verdicts, risk scores, and remediation actions. De-identified — no raw secrets in the export.

DLP-safe AI review: File contents, diff hunks, matched snippets, and even file paths pass through the detect→tokenize→sanitize gate before reaching the AI provider. The AI reviews your code without ever seeing the real secret values it found.
Folder Scan

Local paths

Select any folder on your machine. Supports file extension filters and .gitignore patterns.

Remote Repo Scan

HTTPS + PAT

Clone via HTTPS with a PAT stored in the encrypted PAT vault (AES-256-GCM, masked on readback). Branch/tag selection, 10 MB file cap, cleanup prompt after scan.


// pricing

Free for individuals. Enterprise for teams.

Community is free forever with no time limit. Pro Trial gives you everything for 6 months — no credit card required.

Community
Free
Forever · Auto-generated offline license · No account needed
  • 110 detection rules (all 10 categories)
  • Up to 3 concurrent sessions
  • Core AI chat with all provider support
  • Basic risk reports
  • Security Workspace (folder scan)
  • Browser extension
  • MCP Servers
  • Remote repository scan
  • Compliance reports (HTML/CSV)
  • Knowledge Base (RAG)
  • 17 pro-only detection rules
Download Free
Enterprise
Contact us
Offline .vml license · Air-gapped environments · Custom seats
  • All Pro Trial features
  • Signed .vml offline license (Ed25519)
  • Device fingerprint locking
  • Custom seat count
  • Air-gapped deployment
  • Custom rule packs (signed)
  • Control plane compliance upload
  • Priority support
Contact for Enterprise

// download
AI Shield app icon

Ready to shield your AI sessions?

Free community build — no sign-up, no account, no cloud. Just install and your secrets stay yours.

Windows 10 / 11 🍎 macOS — coming soon 🐧 Linux — coming soon
Windows 10 / 11 64-bit 4 GB RAM minimum No admin rights required Internet optional (Pro Trial activation only)
SHA-256 checksum (Windows installer) — verify before installing
00d85a2f61a8674ad73ed46439f03be001c5981e7cb575cd76a0eb4630c3708d
Prefer MSI? Download VaultMorph.AI.Shield_0.1.0_x64_en-US.msi — SHA-256: 8655159637b02f546e773d7e62d6a507bb967b8b4650db35a627fcbed881a8ac
→ How to verify your download (SHA-256 + Ed25519)