Pastebreak

Stop customer data and API keys from going into personal ChatGPT.

Your team already uses ChatGPT and Claude, often on personal accounts your Microsoft or Google licence can't see. Pastebreak is a browser extension that blocks the paste before it is sent: client lists, SSNs, card numbers, passwords, AWS and API keys, private key files. Your admin pushes it to every laptop from the console you already use.

 Card required, cancel any time. $149/month flat for up to 50 people after the trial.
Placeholder for a short screen recording: a fake customer file is pasted into ChatGPT and Pastebreak blocks it.

What it does, in plain English

Blocks the dangerous stuff

Hard blocks for things with no innocent reason to paste: API keys and tokens, private keys, .env/.pem files, card numbers that pass the bank checksum, valid-format SSNs, and customer or project names you add to a list.

Warns on the grey areas

An email address, phone number or login token gets a "Check before sending" prompt. If someone sends anyway, it is logged. You can turn warnings into blocks, or into monitor-only.

Starts in monitor mode

Run it for a week with nobody blocked. See what would have been caught, add allow-list entries for anything noisy, then turn blocking on.

Runs in the browser

Detection happens on the laptop. Your prompt text is never sent to us. We receive only the event: which AI site, what kind of data, blocked or allowed, and when.

Works today on ChatGPT and Claude. Gemini, Copilot and Perplexity support is built but still in testing, so we don't promise it yet. Chrome and Edge, on managed work laptops.

Who it's for

Founders, ops leads and IT people at 20–150 person companies on Microsoft 365 Business Premium or Google Workspace without the premium security add-ons, where staff open a personal ChatGPT or Claude tab next to the company tools. If you have a CISO, a SOC 2 requirement this quarter, or more than a couple of hundred people, a larger platform is probably the right call.

Honest comparison

Prices are public list prices as we understand them; check each vendor's current page before you decide. We tried to be fair, including where we lose.

PastebreakPush SecurityMicrosoft Purview (Endpoint DLP / browser DLP)Chrome Enterprise Premium
Price$149/mo flat, up to 50 peopleabout $5 per user per monthabout $10 per user per month (add-on licensing)about $6 per user per month
At 20 people$149about $100about $200about $120
At 30 people$149about $150about $300about $180
At 50 people$149about $250about $500about $300
ScopeOne job: block secrets and customer data going into AI chat sitesBroader: identity, phishing, shadow SaaS, with AI-paste controlsBroad enterprise DLP across Microsoft 365 and endpointsBroad Chrome data-loss controls, threat protection, reporting
SetupForce-install from Google Admin or Intune, about 20 minutesAgent/extension plus a platform to configureLicensing, policies, device onboardingLicensing and policy configuration in the admin console
Personal AI accountsYes: works on the page, whichever account is logged inVaries by control; checkDepends on policy and browser; checkDepends on policy; check

Where Pastebreak loses: below about 30 people Push is cheaper on paper, and any of the three covers far more than AI pasting. If you already own Purview or Chrome Enterprise Premium and have configured it to stop this, keep it. Pastebreak is for the company that wants this one problem solved at one flat price, without buying and configuring a platform.

Pricing

$149 / month, flat, up to 50 people

14-day free trial with a card on file. Cancel in one click from the billing portal. No per-user math. Need more than 50 people? Email us.

FAQ

Do you see what my team types?

No. The extension reads the text in the browser to check it, and prompt text is never sent to our servers. We receive: event type, AI site, time, the action taken, a user label and a random install ID. See the privacy page.

Will it annoy my team with false positives?

Hard blocks are kept for things with no innocent reason to paste. Softer matches (an email address) only warn. Start in monitor mode for a week, and add anything noisy to the allow-list from the dashboard.

Can employees turn it off?

A force-installed extension can't be removed by the user. Incognito windows and other browsers are an admin setting in Google Admin and Intune; our install guide shows the two settings.

What does it not cover?

Personal phones and personal laptops. Desktop AI apps and coding agents (Claude desktop, Cursor, Copilot in an IDE). Anything typed by hand character-by-character that doesn't match a rule. Images and PDFs are not scanned, only text files (first 64 KB). It is a seatbelt for accidents, not protection against a determined insider.

What happens when ChatGPT or Claude changes its page?

If Pastebreak can't find the message box it shows "unprotected" instead of pretending. Selector updates are delivered as a signed config file, so a fix doesn't wait on a browser-store review. Honestly: this is a new product and a site change can still leave a gap for a few hours.

Which browsers?

Chrome and Microsoft Edge (Edge installs Chrome Web Store extensions).

How are seats counted?

By browser installs that check in during the last 30 days. The limit is 50; going slightly over triggers a notice, not a shutoff.

Do you have a SOC 2 report?

Not yet. We're a new company. The design keeps risk small: detection runs on your laptops, we never receive prompt text, and we store only event metadata for 90 days. Subprocessors: Cloudflare, Stripe, Resend (email), and Slack if you connect it. We'll answer a security questionnaire of up to about 30 questions within 48 hours. If your customers or auditors require a SOC 2 Type II report from every vendor this year, we're probably not the right choice yet.

How do I cancel?

From the billing portal in the dashboard, any time. Protection stops at the end of the paid period.