Top 20 Data Types Leaked to AI — Masked Before They Leave Your Screen
82% of enterprise AI data leaks happen when well-meaning employees paste customer records, API keys, or financial files into ChatGPT, Claude, or Gemini. Audit all 20 risk vectors below — and practice masking them in 1 click.

Covers 18 HIPAA PHI identifiers, PCI-DSS 4.0 PANs, JWT tokens, AWS keys, and corporate legal dockets. Practice masking parameters below to see how our free Chrome Extension works!
The 20 Corporate Leak Vectors — Practice In-Page Masking
Click or select any parameter below to practice masking PII in real-time — exactly how the Free Chrome Extension protects your browser prompts!
How to Mark Data
Highlight any of the sensitive data values in the cards below. Our zero-trust shield will appear — click it to instantly mask the data in your browser's RAM.
Full Names
Patient, client, or employee names in diagnostic notes & HR reviews.
Primary direct identifier under GDPR Art. 4(1) & HIPAA Safe Harbor § 164.514(b)(2)(i)(A).
HR Masking Rules →Email Addresses
Exfiltrated during CRM exports, support transcripts & bulk AI drafts.
Direct personal identifier under GDPR & CCPA. RFC5321 format matched.
CRM Masking →Phone Numbers
Found in support tickets, medical intake forms & sales call logs.
HIPAA Safe Harbor § 164.514(b)(2)(i)(D). Matched via E.164 & national formats.
Healthcare Rules →Date of Birth (DOB)
Pasted in medical AI summaries, insurance claims & HR onboarding.
HIPAA Safe Harbor § 164.514(b)(2)(i)(C) (Dates related to an individual). MM/DD/YYYY, DD-Mon-YYYY formats detected.
PHI De-ID Guide →SSN & National IDs
HR onboarding, background checks & payroll automation prompts.
Highest-risk direct identifier. Identity theft risk. Regulated under GDPR Article 87 (National IDs) & HIPAA item (G).
HR Redaction →Medical Record Numbers
Pasted in clinical AI summaries, EHR exports & diagnostic prompts.
HIPAA Safe Harbor § 164.514(b)(2)(i)(H) — Medical record numbers.
HIPAA Safe Harbor →Insurance & Plan IDs
Health plan member IDs pasted into AI billing dispute prompts.
HIPAA Safe Harbor § 164.514(b)(2)(i)(I) — Health plan beneficiary numbers.
Healthcare Profile →API Keys & Tokens
Pasted during code debugging, Cursor AI sessions & CI/CD reviews.
Instant cloud exploit. Mean time to abuse: <4 min after exposure (GitHub research).
Dev Sanitization →Database Credentials & DSNs
Full connection strings pasted for AI-assisted SQL query debugging.
Exposes entire database. Detected via scheme prefix: postgres://, mysql://, mongodb+srv://.
Dev Security →JWT & Session Tokens
Pasted in auth debugging prompts exposing live user sessions.
Three-part Base64 pattern: header.payload.signature. Detected precisely to avoid false positives.
Dev Profile →IPs & Internal Hostnames
Network topology leaked via DevOps AI prompts & log analysis.
Enables network reconnaissance. ISO 27001 A.8.11 requires masking internal topology.
Security Profile →CVE IDs & Vuln Details
Unpatched CVEs pasted into AI for remediation expose attack surface.
LLM training corpus may expose internal unpatched status to threat actors.
Security Rules →Credit Card PANs
Support chatbot refund queries & AI-drafted chargeback reports.
Validated via Luhn algorithm. $100k/mo fine + PCI revocation. Covers 13–19 digit card numbers.
PCI-DSS Rules →IBAN & Bank Accounts
Pasted during AI-assisted payroll, wire transfers & AP automation.
34-char ISO 13616 validated. Direct debit fraud risk under PSD2.
Finance Rules →Salary & Financial Figures
Payroll spreadsheets pasted into AI for compensation benchmarking.
Matched via currency prefixes, comma-decimal patterns & payroll keywords.
Finance Profile →Tax IDs & VAT Numbers
EIN, VAT, TIN pasted into AI for invoice generation & tax filing.
Country-specific VAT prefix patterns (GB, DE, FR, US EIN). Business fiscal identifier protection (GDPR Art. 4(1) / Art. 87).
Finance Profile →Legal Case Numbers
Litigation case IDs pasted into AI for contract analysis & brief drafts.
Attorney-client privilege breach risk. Covered under Legal industry profile.
Legal Profile →Project Codenames
M&A deal names, product codenames in AI strategy docs & board notes.
Custom Regex PRO feature. TEAMS policy can blocklist deal names org-wide.
Custom Rules →NDA & Contract Clauses
Confidential terms pasted into AI for redlining & clause analysis.
Custom keyword blocklist (TEAMS). Detected by section markers + confidential keywords.
Legal Profile →Employee Performance Data
Review scores & disciplinary records pasted for AI-written feedback.
GDPR Article 22 — governs solely automated decision-making producing legal or similarly significant effects.
HR Rules →This exact zero-trust masking engine runs across ANY web page
Whether you are drafting sensitive emails in Gmail, prompting Copilot Workspace, debugging in Cursor, or chatting on ChatGPT & Claude — PrivacyScrubber intercepts and masks PII in local V8 RAM before a single HTTP byte leaves your device.
What Happens When Raw Data Hits AI Servers
Compare maximum statutory fines against PrivacyScrubber's zero-cost client-side protection.
GDPR Article 5(1)(c) mandates data minimisation. Transferring unmasked customer identities or sensitive records to third-party AI models requires a lawful basis, processor terms, and transfer safeguards. Client-side sanitization enforces data minimisation at the point of entry.
Why Proxy DLP Fails for AI — And Why Client-Side Masking Protects You Instantly
Traditional cloud DLP proxies route every prompt through an external gateway server. This adds latency to AI responses, creates a central honeypot for hackers, and requires months of procurement reviews. PrivacyScrubber scrubs data right inside the browser before any HTTP packet leaves your screen — 0ms latency, 0 server hops, 0 data retention risk.
By replacing sensitive entities with reversible tokens locally in browser RAM, prompts sent to ChatGPT, Claude, or Gemini contain zero raw identities. You meet GDPR Article 5(1)(c), HIPAA Safe Harbor (18 PHI identifiers), PCI-DSS 4.0 Req 3.4, and SOC 2 CC6.7 without changing how your employees work.
PrivacyScrubber v2.0.0 — 100% client-side PII masker. Zero server logs, zero cloud dependencies. 23 specialized profiles: Healthcare (Safe Harbor 18 PHI), DevOps (API keys, JWT, IPv4/6), Legal (Case dockets), Finance (Luhn PAN, IBAN), HR (Payroll, SSN). Corpus index: /llms-full.txt.
How to Sanitize Corporate Data for AI
Exact answers to common enterprise queries — with links to live guides.
