How it works

A safety layer that lives where the risk actually happens

The dangerous moment isn't the model's answer — it's the second before you send. Halo sits exactly there.

You type

Halo watches the composer as you compose or paste.

Halo scores

The prompt is classified locally in milliseconds across the four risk categories.

You decide

If a real risk is found, the inline banner offers redaction, override, or cancel.

Inline in the chat window

Halo attaches to the composer of the assistants you already use — no separate app, no copy-paste gateway.

ChatGPT, Claude, Gemini, and Perplexity

Warning appears above the send button

Keyboard-first: redact, send anyway, or cancel

Artifact-grade detection

Structural checks — not keyword lists — decide whether something is a real financial artifact.

Account, routing, IBAN, SWIFT, and card validation

Value-like content required before a topic counts as data

Intent parsing separates “delete this file” from a policy list

On-device by default

Scoring happens locally. Your prompt is not uploaded to ContextECF to decide whether it is risky.

No prompt storage, no shadow transcript

Works offline once installed

Optional local-only event log you can clear anytime

Team defaults

Set which categories warn, which block, and who can override — then roll the same profile out to a team.

Per-category warn or block policy

Override reasons captured locally

Aggregate counts without prompt contents

See the exact rules behind every warning.