ContextECF Halo warns you before you hand an LLM something you can’t take back.
Inside the ChatGPT, Claude, Gemini, or Perplexity chat window, Halo shows an inline alert the moment your prompt contains sensitive financial artifacts or a destructive action request — before you press enter.
Halo · active in ChatGPT
Your message
Please pay this vendor today from account •••• 4417 routing 021000021 and publish the confirmation to the status page now.
2 risks found before send
- Financial artifact — account and routing number detected
- Destructive action intent — “publish … now”
Prompts never leave your device to be scored
Classification in milliseconds, inline with typing
Mentions alone never trigger a false alarm
How Halo works
One job: catch the risky prompt at the last safe moment.
Halo watches the chat box, not your data
Classification runs locally as you type in ChatGPT, Claude, Gemini, or Perplexity. Nothing is sent anywhere to decide whether something is risky.
It separates real artifacts from mere topics
A forecast conversation is not a leak. A routing number is. Halo scores value-like content, not keywords, so the alerts stay rare and credible.
You get the warning before you hit enter
An inline banner names what was detected, why it matters, and gives you one click to redact, continue anyway, or cancel the send.
Classification
Four categories decide whether you see a warning.
Precision is the product. Halo separates real artifacts and real intent from ordinary business talk that only mentions risky words.
Financial artifact
Actual sensitive values or artifacts: bank account, routing number, IBAN, card number.
IBAN DE89 3704 0044 0532 0130 00
Business / financial topic
Words like invoice, forecast, or payment only count as financial data when paired with value-like content.
“Draft an invoice reminder email template”
Destructive action intent
Direct requests to act on the real world: “please publish this now” or “delete this file”.
“Delete the production bucket”
High-risk action mention
Architecture, policy, examples, screenshots, route design, or taxonomy lists that merely mention send, pay, publish, or delete.
“Our policy doc lists publish and delete scopes”
What we promise
Identity protection instincts, applied to the prompt box.
You already have a reflex about giving out a card number over the phone. Halo gives you that same reflex when the recipient is a model.
Runs in the chat window you already use — no new app to learn.
Detection happens on-device; prompts are never uploaded for scoring.
Keyword-only mentions never trigger alerts, so warnings stay meaningful.
Every warning explains what was found and what to do next.
Redaction replaces the artifact and leaves the rest of your prompt intact.
Works for individuals and for teams with shared policy defaults.
Put Halo around your chat window.
Early access is open for individuals and teams who paste real work into AI chat every day.