Control over AI
Product & engineering

API keys do not belong in an AI prompt

Engineers use AI coding tools all day. BeeSensible highlights API keys, tokens, and customer data in the text you write, before a prompt or message leaves the company.

  • On-device or EU processing
  • No content stored
  • Helps with GDPR

Who this is for

  • Engineers using AI coding tools against production systems
  • Product managers writing specs and tickets that carry customer data
  • Data teams using AI to analyse or describe sensitive datasets
  • Engineering leads, security, and CISOs overseeing AI use
Developer or product manager working at a laptop

18

apps with a highlight while you type: AI tools, email, chat, and social

0 sec.

The text you type is processed and discarded at once

Local or EU

Detection runs on-device or on EU infrastructure

A stack trace, a log line, a snippet from production: exactly the text you paste into an AI tool to fix a bug faster. And exactly the text with an access token, a connection string, or a customer email in it. BeeSensible highlights that data while you type, so you can remove it before you send.

From the field

Three moments your policy never reaches.

In a bug report

Pasting a snippet to ask for help

An engineer is stuck on an error and pastes the whole code fragment into ChatGPT. That fragment holds a connection string with a password and an API key from the staging config. The answer is ready at once, but the key has now been processed by an outside tool and really needs to be rotated.

In a log or trace

A stack trace that carries too much

A developer asks AI to read a trace that breaks on an edge case. Between the lines sit an access token, a customer's email address, and an account number from the payload. The explanation is correct, but a real user's data has now left the company.

At the lead's standup

The question you cannot answer

After a report of a leaked key, the engineering lead wants to know which secrets and customer data ended up in which AI tools. A guideline on responsible AI use exists. Proof that developers got a warning at the moment itself does not.

01 See and decide

See which AI coding tools are already used, and decide per tool what is allowed.

The catalog already covers more than 55 AI tools built for engineering, from AI code editors to autonomous coding agents, each scored on data governance, jurisdiction, and vendor trust. When a developer opens one, you see it appear. Then the organisation decides: allow it, allow it with a condition of your own, or not allow it. Anyone opening the tool afterwards sees that decision in the browser, with the approved alternative leading.

55+ engineering AI tools already risk-scored in our catalog
Search tool, vendor or categoryโ€ฆ
700+ tools
ChatGPT๐Ÿ‡บ๐Ÿ‡ธ
HighAllowed
Claude๐Ÿ‡บ๐Ÿ‡ธ
MediumAllowed
DeepSeek๐Ÿ‡จ๐Ÿ‡ณnew
CriticalNot allowed
Perplexity๐Ÿ‡บ๐Ÿ‡ธnew
MediumNo decision yet
Mistral๐Ÿ‡ซ๐Ÿ‡ท
LowNo decision yet
Midjourney๐Ÿ‡บ๐Ÿ‡ธ
MediumNo decision yet
02 Guidance while people write

API keys, passwords, and tokens are marked before the prompt is sent.

Engineers can remove credentials before asking an AI tool or teammate for help.

ChatGPT5
Summarise the last 3 support emails from this customer.
Start with the 500 in the logs. Remove the API key, the password, and the token before you share this or paste it into a ticket.
This deploy keeps throwing a 500. The logs show API key sk-live-9f2a7c1b4d, the database password Pr0d!2024#core, and token ghp_8Xk2pQ7vR1m. What is going wrong?
ChatGPT can make mistakes. Check important info.
03 Clean

Clean a debug export before it goes into an AI tool.

A stack trace, an incident report, a sample data export: open it in the Mac or Windows desktop app, and API keys, tokens, customer emails, and account numbers are marked for you to remove before you share the document or paste it into AI.

Incident report.pdf
API key
Token
Customer email
Account number

Why this is hard

The risk sits in the moment someone types.

01

AI coding tools are always open

Engineers use Copilot, ChatGPT, and Claude to fix bugs, explain code, and write queries. Often with a snippet from production right next to them. Policy lags behind what happens every day.

02

A pasted key is an incident

An access token or connection string in a consumer AI tool means you have to rotate it and report it. Even when the developer acts in good faith, it is a breach.

03

Customer data leaks via debugging prompts

Logs, traces, and query results are full of names, email addresses, and account numbers of real users. In the rush of debugging, those go straight into a prompt.

04

Security cannot see it

AI tools in the browser leave no network trail that existing DLP tools can read. What developers paste into a prompt stays invisible until it causes a problem.

Across engineering

Recognisable wherever you work.

The same risk shows up in different workflows, from debugging to data migrations.

Debugging

Snippets and error messages you paste into an AI tool, often with a key or password mixed in.

Code review

Diffs and pull requests you ask AI to summarise, config and credentials included.

Logs and traces

Stack traces and log lines full of access tokens and real users' data.

Incidents

Postmortems and reports where payloads with customer data get pasted in.

Data migrations

Sample rows and queries with names, email addresses, and account numbers.

How BeeSensible helps

A warning in the text field, before anything is sent.

Sensitive details get a highlight while staff write. They decide what to remove, replace, or mask.

Recognises secrets and customer data

Highlights API keys, passwords, tokens and other credentials, and personal data such as names and email addresses while you type.

Works in the tools you already use

Runs in the browser, in AI tools, email, and chat, plus a desktop app for macOS and Windows for on-device detection. No IDE plugin, no proxy, no training up front.

You stay in control

You choose: remove, replace with a realistic alternative, or mask. The extension never changes your text on its own and never blocks sending.

Counts, not content

Security sees patterns by tool and category. What an individual developer writes is never stored and cannot be read.

For engineering leads, security, and CISOs

Show the control works, without looking over anyone's shoulder

BeeSensible gives you the figures security and audit ask for: how many markings developers adjusted before sending and how many went out anyway, what happened after a tool notice, and what share of AI use runs through approved tools. All at organisation level, never per developer.

Total detections

12,438

Top apps

  • ChatGPT
  • Gmail
  • Gemini
  • Slack

Example dashboard. Counts and types only, never content.

Security officer

A control you can demonstrate

Show auditors and the organisation that a control sits at the moment of input, with figures per period: markings adjusted or sent anyway, a recorded decision per AI tool, and what people did with the notice.

Engineering lead

No view into individuals

The dashboard shows no text and no single people: only aggregate counts, with no per-employee drill-down anywhere. Insight into patterns, not surveillance of people.

CISO and IT

Nothing changes in your stack

No proxy and no new application. The extension runs in Chrome and Edge. Detection runs on-device or on EU infrastructure, all traffic encrypted in transit.

Honest answers

The questions we hear first.

Straight answers to the questions people actually ask before rolling this out.

Does BeeSensible watch everything developers type?

No. The extension analyses text in the input fields of supported tools to highlight sensitive data. In on-device mode, that text never leaves the machine. Otherwise it travels to a BeeSensible server inside the EU, is processed in working memory, and is discarded at once. The content is never stored and cannot be read by anyone, not even an administrator.

Does it block AI tools or block sending?

No, BeeSensible blocks nothing. You see a highlight in the text and choose what to do: remove, replace, or mask. The developer stays in control, and security gets insight into patterns.

Does this make us GDPR compliant?

No tool makes you compliant on its own. BeeSensible helps with GDPR by covering the moment of input and supporting your accountability. Your organisation stays the controller, BeeSensible is the processor, and a processing agreement is signed.

Does detection work on Dutch data too?

Yes. The detection engine handles Dutch and English reliably and recognises both technical secrets and personal data, such as names, email addresses, and account numbers.

How much work is the rollout?

Limited. There is no proxy to configure and nothing changes in your network. The desktop app for on-device detection and document redaction is optional. The extension runs in the browser your team already uses and can be rolled out centrally through your management console.

Compliance

Built to support the checks you already have to show.

GDPR

Supports your accountability and covers the moment personal data is entered.

Secrets and credentials

Helps recognise API keys, tokens, and connection strings before they reach an AI tool or log.

Processing agreement

A processing agreement is signed with every customer. A product DPIA is available on request.

EU processing

Detection runs on the user's own machine, or on ISO 27001 certified EU infrastructure (API in the Netherlands, detection in Germany).

Give developers a signal at the moment that counts

BeeSensible works in the tools your team already uses. No rollout project, and you see your first detections in minutes.