For CISOs

Fewer secrets in prompts. Every control checkable from your terminal.

API keys, tokens, passwords, IPv4 addresses: DoNotLeak finds them and replaces them before a text leaves for an AI. That leaves the question you ask of every new tool — what it adds to your attack surface. Here are its ten controls, and for each one, how to check it yourself.

Your text is processed in memory and dropped with the request that carries it: never stored, never logged. The service calls no one, and runs from a minimal image signed with our own key.

Line drawing, no people: a document marked with a padlock goes through a scanning machine and comes out plain; a dotted side path leads only to a clock and three status lights, never to the document.
What the service records about a request never includes its text.

Secrets in prompts

A bug report, and what the AI gets from it.

Pasted to ask for help, it carries a password, an IP address, an account. The output is recorded from the engine, not written by hand.

What you paste

Bug — the database login fails since the update Log: ERROR login refused for claire.fabre@example.org from 192.0.2.87 Database password: Vx7qP2mLr9 Reproduced by Julien Marchand on his workstation.

What the AI receives

Bug — the database login fails since the update Log: ERROR login refused for [[EMAIL-1]] from [[IP_ADDRESS-1]] Database password: [[CREDENTIAL-1]] Reproduced by [[PERSON-1]] on his workstation.

What DoNotLeak spots here, and what it does not recognise

Keys and tokens in common formats, private keys, connection strings, passwords written after a label, IPv4 addresses. A server’s name or an architecture note, it does not recognise.

In your frames

Your questions, and the controls that answer them.

Each answer, filed where you assess it: ANSSI’s EBIOS Risk Manager, ISO/IEC 27001, NIS2, OWASP.

What does it add to your attack surface?

An image with no shell and no package manager, run as an unprivileged user, with no Linux capability, read-only, behind a user-space kernel. In the browser, a strict content policy and an integrity hash on every script.

Controls

Minimal runtime · Isolated execution · Browser hardening

In your frames

ISO/IEC 27001, A.8.9 configuration management · OWASP Secure Headers Project

Who built it, from what, and how can that be proven?

Every image is signed with our own key, with its build provenance naming the commit, and its bill of materials, signed as well. The base is pinned by its digest.

Controls

Signed images, provenance · Software bill of materials (SBOM)

In your frames

NIS2, art. 21(2)(d) and 21(3), supply chain security · ISO/IEC 27001, A.5.21

What about vulnerabilities?

Two scanners at every build: a high or critical flaw stops the release, unless a written, reviewed exception explains why. The host scans again before deploying. To report a flaw, a published contact, in French or English.

Controls

Vulnerability scans · Vulnerability disclosure

In your frames

NIS2, art. 21(2)(e), vulnerability handling and disclosure · ISO/IEC 27001, A.8.8

One more supplier: what does it see, what does it reach?

The text lives in the memory of the request, never written, never logged — a marker text checks it in every pipeline. No outbound flow: no AI provider, no third-party service. The host and the publisher are named; and the headless image can run inside your own information system.

Controls

Nothing kept · No outbound flow · A French host

In your frames

EBIOS Risk Manager, workshop 3, a stakeholder of your ecosystem · ISO/IEC 27001, A.5.19 to A.5.23

Who may call it, with which rights?

The page, anyone, with no account, within per-client budgets. The API, nobody by default: a client certificate or a token from your identity provider, each action granted by name, no static key.

Controls

Access, below

In your frames

ISO/IEC 27001, A.5.15 and A.8.5 · NIS2, art. 21(2)(i)

And the leak itself?

It is what the tool is for: find and replace before sending, showing everything it found. What it does not cover is written below.

Controls

The limits, below

In your frames

ISO/IEC 27001, A.8.11 data masking and A.8.12 data leakage prevention · OWASP Top 10 for LLM Applications, LLM02:2025

These frames are yours

DoNotLeak claims no certification and no conformity with any of them. The references are our reading, for each organisation to review against its own framework: they say where to file each answer in your risk analysis or your security accreditation file.

The controls

Ten controls in place today.

Each one says what it means for you and where its proof is.

Signed images, provenance

What it means for you

Every published image is signed with DoNotLeak’s own key, with its build provenance (SLSA): the commit it was built from. The pipeline verifies the signature before announcing a release; the hosting platform checks it before deploying.

How to check

The public key is on this site; the command is further down.

/cosign.pub

Vulnerability scans

What it means for you

Two independent scanners examine every image before it is published: a high or critical flaw stops the pipeline, unless a written, reviewed exception explains why. Automated web security scans probe the running service, and the code’s dependencies are checked against the public advisory database. The hosting platform scans again and refuses an image whose serious flaw has a fix.

How to check

Your own scanner can judge the same image from its bill of materials.

HIGH · CRITICAL

Software bill of materials (SBOM)

What it means for you

Every release carries the list of every package in its image, with its version, in a standard format — signed with the same key.

How to check

Attached to the image in the registry, beside its signature.

SPDX

Minimal runtime

What it means for you

The image holds the service and the few system libraries it needs: no shell, no package manager. It runs as an unprivileged user, on a base pinned by its digest.

How to check

The image’s configuration names the user; its bill of materials lists no shell.

USER 65532:65532

Isolated execution

What it means for you

The service contract asks the hosting platform for a user-space kernel between the service and the host, no Linux capability, a read-only file system, and fixed limits: 1 GiB of memory, 2 CPUs, 128 processes.

How to check

Written in the service contract, which the hosting platform applies.

cap_drop: ALL · read_only

No outbound flow

What it means for you

The detection calls nobody: no AI provider, no third-party service. The service contract grants the service no outbound network. In your browser, the page may only talk to this site.

How to check

The content policy header; your browser’s network panel shows it.

connect-src 'self'

Nothing kept

What it means for you

Your text and your files live in the memory of the request that carries them, then are dropped: never written to disk, never logged. Every pipeline sends a marker text through the server and fails if its logs ever show it.

How to check

The legal notice, under “Personal data” — with what the host logs: address, date, page.

/legal

Browser hardening

What it means for you

HTTPS only. A strict content policy: scripts and styles from this site alone, a fresh nonce for every page, no framing. An integrity hash on every script and style sheet file. What the page sends must come from this site’s exact origin; per-client budgets answer 429 beyond them.

How to check

The response headers of any page, and the integrity attributes in its source.

content-security-policy · integrity="sha384-…"

A French host

What it means for you

The service is hosted by OVH SAS, a French company, and published by AQ INVESTISSEMENTS (Contee), in Paris.

How to check

The legal notice names both.

/legal

Vulnerability disclosure

What it means for you

Found a flaw? Write to our security contact. It is published in the standard file security teams look for, with the languages we read.

How to check

/.well-known/security.txt (RFC 9116).

security@contee.eu

Least privilege

An open page, an API closed by default.

The page asks for no account: anyone may paste a text, within per-client budgets that keep the service available to all.

The API, for a deployment on your own servers, does not start without an identity source and refuses every anonymous call: each caller shows a client certificate or a token from your identity provider, and your policy grants each action by name. What it does not grant is refused.

Client certificate (mutual TLS) or bearer token · deny by default

Line drawing: a woman holds out her badge and her request reaches the scanning service; from the other side, a laptop’s certificate is stopped. Beside them, a man studies the board of rights.
Each caller, person or program, has only the rights it was given.

Check it yourself

Three checks, from your own terminal.

  1. The response headers

    curl -sI https://donotleak.contee.eu/
    What you should see

    content-security-policy with default-src 'self' and a new nonce on every call, strict-transport-security, and x-frame-options: DENY.

  2. The signature and the provenance

    curl -sO https://donotleak.contee.eu/cosign.pubcosign verify --key cosign.pub forge.contee.eu/contee/donotleak-app@sha256:<digest>cosign verify-attestation --key cosign.pub --type slsaprovenance forge.contee.eu/contee/donotleak-app@sha256:<digest>
    What you should see

    With access to the image, and a release’s digest: the signature verifies against our public key, and the provenance names the commit it was built from. Use cosign 3 or later.

  3. The security contact

    curl -s https://donotleak.contee.eu/.well-known/security.txt
    What you should see

    The address for a vulnerability report, and the languages we read: French and English.

What DoNotLeak does not protect against

A protection that knows its limits.

Every detection misses something.

The page shows everything it found, so that you read before you send.

It protects what goes through it.

A text sent from another tab, by e-mail or in a shared file never meets it.

It cannot recall what has already been sent.

Nor can it revoke a leaked password or key for you.

Your own device comes first.

Malware or a browser extension that reads your screen reads the text before we do.

A trade secret in plain words can slip past it.

It finds personal data and identifiers; a trade secret written in plain words can read like any other sentence.

Today, the text travels to our server for the scan — encrypted in transit, held in memory only. A mode where the scan runs entirely in your browser: Soon

This page describes technical controls. It is neither a certification nor legal advice.

Line drawing: a woman and a man study three parts on a technical drawing; two carry measurement marks, and the man points at the third, which nothing has marked. A laptop and a caliper lie on the table.
The tool gives markers; the context remains yours to judge.

Check, then decide.

Approve, restrict or refuse: the three commands above are enough to start, and the page can be tried with a fake secret. To host it inside your information system, with your machines’ identity, see the IT page. A vendor security questionnaire, a question: message Contee.