LifeLock for the AI and LLM era

ContextECF Halo warns you before you hand an LLM something you can’t take back.

Inside the ChatGPT, Claude, Gemini, or Perplexity chat window, Halo shows an inline alert the moment your prompt contains sensitive financial artifacts or a destructive action request — before you press enter.

On-device detectionWorks in 4 chat appsWarn, redact, or continue

Halo · active in ChatGPT

Send paused

Your message

Please pay this vendor today from account •••• 4417 routing 021000021 and publish the confirmation to the status page now.

2 risks found before send

  • Financial artifact — account and routing number detected
  • Destructive action intent — “publish … now”
Redact and sendSend anywayCancel
Scored on-device18 ms

Prompts never leave your device to be scored

Classification in milliseconds, inline with typing

Mentions alone never trigger a false alarm

How Halo works

One job: catch the risky prompt at the last safe moment.

Halo watches the chat box, not your data

Classification runs locally as you type in ChatGPT, Claude, Gemini, or Perplexity. Nothing is sent anywhere to decide whether something is risky.

It separates real artifacts from mere topics

A forecast conversation is not a leak. A routing number is. Halo scores value-like content, not keywords, so the alerts stay rare and credible.

You get the warning before you hit enter

An inline banner names what was detected, why it matters, and gives you one click to redact, continue anyway, or cancel the send.

Classification

Four categories decide whether you see a warning.

Precision is the product. Halo separates real artifacts and real intent from ordinary business talk that only mentions risky words.

Blocked before send

Financial artifact

Actual sensitive values or artifacts: bank account, routing number, IBAN, card number.

IBAN DE89 3704 0044 0532 0130 00

No warning — topic only

Business / financial topic

Words like invoice, forecast, or payment only count as financial data when paired with value-like content.

“Draft an invoice reminder email template”

Confirm before send

Destructive action intent

Direct requests to act on the real world: “please publish this now” or “delete this file”.

“Delete the production bucket”

No warning — mention only

High-risk action mention

Architecture, policy, examples, screenshots, route design, or taxonomy lists that merely mention send, pay, publish, or delete.

“Our policy doc lists publish and delete scopes”

What we promise

Identity protection instincts, applied to the prompt box.

You already have a reflex about giving out a card number over the phone. Halo gives you that same reflex when the recipient is a model.

Runs in the chat window you already use — no new app to learn.

Detection happens on-device; prompts are never uploaded for scoring.

Keyword-only mentions never trigger alerts, so warnings stay meaningful.

Every warning explains what was found and what to do next.

Redaction replaces the artifact and leaves the rest of your prompt intact.

Works for individuals and for teams with shared policy defaults.

Put Halo around your chat window.

Early access is open for individuals and teams who paste real work into AI chat every day.