LOCKE FOR CHATGPT
Use ChatGPT without handing OpenAI your confidential data.
ChatGPT became the everyday scratchpad faster than any policy could keep up. People paste contracts to summarise, customer emails to rewrite, error logs to debug, and spreadsheets to analyse — usually into the consumer web app or the desktop client, often on a personal account that no admin can see. The convenience is the whole point, and it's also the whole risk: the box that makes ChatGPT useful is the same box that ships your data to a third party.
Even with a no-training setting or an enterprise agreement, the prompt still leaves your device, is decryptable by the provider, and can sit in retention logs. For regulated data — client PII, PHI, financials, privileged material — "the vendor promised not to train on it" is not the same as "it never left the machine." The gap between those two statements is where AI data incidents happen.
Locke closes that gap at the only place it can be closed for certain: on your device, before the network call. You keep using ChatGPT the way you already do; the sensitive fields just never make the trip.
The risk with ChatGPT
ChatGPT is most often used through a consumer account that corporate controls never touch. Pasted contracts, customer records, and source code leave the device the instant you hit send — and once a prompt is transmitted, it can't be unsent.
How Locke helps
Locke detects sensitive values as you compose a prompt and masks them locally before anything reaches OpenAI. Locke — the Sonomos desktop app, coming soon — extends that same protection to the ChatGPT desktop client and every other AI tool on your machine, not just the browser tab.
Keep using ChatGPT — without the exposure
Locke runs entirely on your device. Sensitive data is detected and masked before any prompt is sent, so nothing confidential ever leaves your machine. Pricing for Locke, the desktop app, is coming soon; Canary is free and open source.