How it works
A safety layer that lives where the risk actually happens
The dangerous moment isn't the model's answer — it's the second before you send. Halo sits exactly there.
You type
Halo watches the composer as you compose or paste.
Halo scores
The prompt is classified locally in milliseconds across the four risk categories.
You decide
If a real risk is found, the inline banner offers redaction, override, or cancel.
Inline in the chat window
Halo attaches to the composer of the assistants you already use — no separate app, no copy-paste gateway.
ChatGPT, Claude, Gemini, and Perplexity
Warning appears above the send button
Keyboard-first: redact, send anyway, or cancel
Artifact-grade detection
Structural checks — not keyword lists — decide whether something is a real financial artifact.
Account, routing, IBAN, SWIFT, and card validation
Value-like content required before a topic counts as data
Intent parsing separates “delete this file” from a policy list
On-device by default
Scoring happens locally. Your prompt is not uploaded to ContextECF to decide whether it is risky.
No prompt storage, no shadow transcript
Works offline once installed
Optional local-only event log you can clear anytime
Team defaults
Set which categories warn, which block, and who can override — then roll the same profile out to a team.
Per-category warn or block policy
Override reasons captured locally
Aggregate counts without prompt contents