We will be undergoing planned maintenance on Oct 7th 6:00AM UTC / Oct 7th 2:00AM ET

Inspiration

As artificial intelligence adoption explodes across the modern workforce, a silent crisis is unfolding behind closed doors: "ShadowGuard." Employees daily copy-paste proprietary source code, confidential legal contracts, API keys, and sensitive customer PII into consumer chatbots like ChatGPT or Claude without realizing the severe regulatory and data leakage consequences. Inspired by rising corporate data breaches and impending AI governance mandates (such as the EU AI Act), we set out to build a proactive defense layer that bridges developer workflow flexibility with enterprise compliance and digital rights protection.

What it does

ShadowGuard acts as an intelligent real-time browser extension and compliance proxy. As users interact with consumer AI tools, the extension silently monitors input text fields, instantly evaluates prompts for high-risk corporate data leaks (such as hardcoded API secrets, source code syntax, or financial PII), and flags violations. It blocks critical leaks, provides instant visual warnings to the user, and automatically populates a centralized compliance dashboard where security and legal officers can review infraction logs and generate audit reports.

How we built it

We engineered a modular architecture split between a lightweight client extension and a robust backend engine: The Client Interceptor: Built using Chrome Extension Manifest V3 and content scripts (content.js), it hooks into major consumer LLM interfaces to capture prompt submissions in real time. The Compliance Engine: Powered by a high-performance Python FastAPI backend (main.py), incoming prompt snippets are processed through advanced regex pattern matching and heuristic safety rules to calculate risk levels (Low, Medium, High, Critical). The Reporting Dashboard: An interactive web dashboard built with HTML and Tailwind CSS that queries backend endpoints to display live metrics, violation breakdowns, and recent incident logs.

Challenges we ran into

Latency vs. Security: Ensuring our browser content script could inspect text payloads instantly upon submission without causing noticeable lag or breaking the host website's user interface required careful event optimization. Heuristic Precision: Tuning our detection filters to accurately catch actual code blocks and secret tokens while minimizing false positives on normal, everyday language required iterative fine-tuning.

Accomplishments that we're proud of

Successfully building a fully functioning, end-to-end prototype—from a working browser extension interceptor to a live backend inspection server and reporting dashboard—during the hackathon timeline. Creating a solution that tackles a major, bleeding-edge corporate governance challenge right at the intersection of AI safety and regulatory compliance.

What we learned

Gained deep practical experience with Chrome extension development policies, DOM event listeners, and asynchronous API communication. Better understood the technical and legal complexities companies face regarding AI data governance, shadow IT, and compliance automation.

What's next for ShadowGuard: AI Governance & Data Shield

Advanced Compliance Frameworks: Expanding our rule engine to map directly to specific legal frameworks like the EU AI Act, GDPR, and HIPAA. Enterprise Integrations: Adding instant team-wide alert webhooks for Slack and Microsoft Teams so security leads are notified of critical data leaks immediately. Cloud Pilot Deployment: Containerizing the backend and launching a pilot program with partner organizations to test ShadowGuard in live enterprise environments.

Built With

Share this project:

Updates

Submission history