For CISOs
Fewer secrets in prompts. Every control checkable from your terminal.
API keys, tokens, passwords, IPv4 addresses: DoNotLeak finds them and replaces them before a text leaves for an AI. That leaves the question you ask of every new tool — what it adds to your attack surface. Here are its ten controls, and for each one, how to check it yourself.
Your text is processed in memory and dropped with the request that carries it: never stored, never logged. The service calls no one, and runs from a minimal image signed with our own key.

Secrets in prompts
A bug report, and what the AI gets from it.
Pasted to ask for help, it carries a password, an IP address, an account. The output is recorded from the engine, not written by hand.
What you paste
Bug — the database login fails since the update Log: ERROR login refused for claire.fabre@example.org from 192.0.2.87 Database password: Vx7qP2mLr9 Reproduced by Julien Marchand on his workstation.
What the AI receives
Bug — the database login fails since the update Log: ERROR login refused for [[EMAIL-1]] from [[IP_ADDRESS-1]] Database password: [[CREDENTIAL-1]] Reproduced by [[PERSON-1]] on his workstation.
What DoNotLeak spots here, and what it does not recognise
Keys and tokens in common formats, private keys, connection strings, passwords written after a label, IPv4 addresses. A server’s name or an architecture note, it does not recognise.
In your frames
Your questions, and the controls that answer them.
Each answer, filed where you assess it: ANSSI’s EBIOS Risk Manager, ISO/IEC 27001, NIS2, OWASP.
What does it add to your attack surface?
An image with no shell and no package manager, run as an unprivileged user, with no Linux capability, read-only, behind a user-space kernel. In the browser, a strict content policy and an integrity hash on every script.
Controls
Minimal runtime · Isolated execution · Browser hardening
In your frames
ISO/IEC 27001, A.8.9 configuration management · OWASP Secure Headers Project
Who built it, from what, and how can that be proven?
Every image is signed with our own key, with its build provenance naming the commit, and its bill of materials, signed as well. The base is pinned by its digest.
Controls
Signed images, provenance · Software bill of materials (SBOM)
In your frames
NIS2, art. 21(2)(d) and 21(3), supply chain security · ISO/IEC 27001, A.5.21
What about vulnerabilities?
Two scanners at every build: a high or critical flaw stops the release, unless a written, reviewed exception explains why. The host scans again before deploying. To report a flaw, a published contact, in French or English.
Controls
Vulnerability scans · Vulnerability disclosure
In your frames
NIS2, art. 21(2)(e), vulnerability handling and disclosure · ISO/IEC 27001, A.8.8
One more supplier: what does it see, what does it reach?
The text lives in the memory of the request, never written, never logged — a marker text checks it in every pipeline. No outbound flow: no AI provider, no third-party service. The host and the publisher are named; and the headless image can run inside your own information system.
Controls
Nothing kept · No outbound flow · A French host
In your frames
EBIOS Risk Manager, workshop 3, a stakeholder of your ecosystem · ISO/IEC 27001, A.5.19 to A.5.23
Who may call it, with which rights?
The page, anyone, with no account, within per-client budgets. The API, nobody by default: a client certificate or a token from your identity provider, each action granted by name, no static key.
Controls
Access, below
In your frames
ISO/IEC 27001, A.5.15 and A.8.5 · NIS2, art. 21(2)(i)
And the leak itself?
It is what the tool is for: find and replace before sending, showing everything it found. What it does not cover is written below.
Controls
The limits, below
In your frames
ISO/IEC 27001, A.8.11 data masking and A.8.12 data leakage prevention · OWASP Top 10 for LLM Applications, LLM02:2025
These frames are yours
DoNotLeak claims no certification and no conformity with any of them. The references are our reading, for each organisation to review against its own framework: they say where to file each answer in your risk analysis or your security accreditation file.
The controls
Ten controls in place today.
Each one says what it means for you and where its proof is.
Signed images, provenance
What it means for you
Every published image is signed with DoNotLeak’s own key, with its build provenance (SLSA): the commit it was built from. The pipeline verifies the signature before announcing a release; the hosting platform checks it before deploying.
How to check
The public key is on this site; the command is further down.
Vulnerability scans
What it means for you
Two independent scanners examine every image before it is published: a high or critical flaw stops the pipeline, unless a written, reviewed exception explains why. Automated web security scans probe the running service, and the code’s dependencies are checked against the public advisory database. The hosting platform scans again and refuses an image whose serious flaw has a fix.
How to check
Your own scanner can judge the same image from its bill of materials.
HIGH · CRITICAL
Software bill of materials (SBOM)
What it means for you
Every release carries the list of every package in its image, with its version, in a standard format — signed with the same key.
How to check
Attached to the image in the registry, beside its signature.
SPDX
Minimal runtime
What it means for you
The image holds the service and the few system libraries it needs: no shell, no package manager. It runs as an unprivileged user, on a base pinned by its digest.
How to check
The image’s configuration names the user; its bill of materials lists no shell.
USER 65532:65532
Isolated execution
What it means for you
The service contract asks the hosting platform for a user-space kernel between the service and the host, no Linux capability, a read-only file system, and fixed limits: 1 GiB of memory, 2 CPUs, 128 processes.
How to check
Written in the service contract, which the hosting platform applies.
cap_drop: ALL · read_only
No outbound flow
What it means for you
The detection calls nobody: no AI provider, no third-party service. The service contract grants the service no outbound network. In your browser, the page may only talk to this site.
How to check
The content policy header; your browser’s network panel shows it.
connect-src 'self'
Nothing kept
What it means for you
Your text and your files live in the memory of the request that carries them, then are dropped: never written to disk, never logged. Every pipeline sends a marker text through the server and fails if its logs ever show it.
How to check
The legal notice, under “Personal data” — with what the host logs: address, date, page.
Browser hardening
What it means for you
HTTPS only. A strict content policy: scripts and styles from this site alone, a fresh nonce for every page, no framing. An integrity hash on every script and style sheet file. What the page sends must come from this site’s exact origin; per-client budgets answer 429 beyond them.
How to check
The response headers of any page, and the integrity attributes in its source.
content-security-policy · integrity="sha384-…"
A French host
What it means for you
The service is hosted by OVH SAS, a French company, and published by AQ INVESTISSEMENTS (Contee), in Paris.
How to check
The legal notice names both.
Vulnerability disclosure
What it means for you
Found a flaw? Write to our security contact. It is published in the standard file security teams look for, with the languages we read.
How to check
/.well-known/security.txt (RFC 9116).
Least privilege
An open page, an API closed by default.
The page asks for no account: anyone may paste a text, within per-client budgets that keep the service available to all.
The API, for a deployment on your own servers, does not start without an identity source and refuses every anonymous call: each caller shows a client certificate or a token from your identity provider, and your policy grants each action by name. What it does not grant is refused.
Client certificate (mutual TLS) or bearer token · deny by default

Check it yourself
Three checks, from your own terminal.
The response headers
curl -sI https://donotleak.contee.eu/What you should see
content-security-policy with default-src 'self' and a new nonce on every call, strict-transport-security, and x-frame-options: DENY.
The signature and the provenance
curl -sO https://donotleak.contee.eu/cosign.pubcosign verify --key cosign.pub forge.contee.eu/contee/donotleak-app@sha256:<digest>cosign verify-attestation --key cosign.pub --type slsaprovenance forge.contee.eu/contee/donotleak-app@sha256:<digest>What you should see
With access to the image, and a release’s digest: the signature verifies against our public key, and the provenance names the commit it was built from. Use cosign 3 or later.
The security contact
curl -s https://donotleak.contee.eu/.well-known/security.txtWhat you should see
The address for a vulnerability report, and the languages we read: French and English.
What DoNotLeak does not protect against
A protection that knows its limits.
Every detection misses something.
The page shows everything it found, so that you read before you send.
It protects what goes through it.
A text sent from another tab, by e-mail or in a shared file never meets it.
It cannot recall what has already been sent.
Nor can it revoke a leaked password or key for you.
Your own device comes first.
Malware or a browser extension that reads your screen reads the text before we do.
A trade secret in plain words can slip past it.
It finds personal data and identifiers; a trade secret written in plain words can read like any other sentence.
Today, the text travels to our server for the scan — encrypted in transit, held in memory only. A mode where the scan runs entirely in your browser: Soon
This page describes technical controls. It is neither a certification nor legal advice.

Check, then decide.
Approve, restrict or refuse: the three commands above are enough to start, and the page can be tried with a fake secret. To host it inside your information system, with your machines’ identity, see the IT page. A vendor security questionnaire, a question: message Contee.