ThreatVec Shadow AI

Discover shadow AI usage across 554 AI services, detect and block PII leakage, and enforce org policy on browser-based AI.

As of June 2026, ThreatVec Shadow AI has users in the Privacy & Security category.

Usersno change0%
Ratingno change0%
— reviews
Reviewsno change0%
Version
1.2.1
Manifest V3

History

1 snapshots

Tracking since May 24, 2026.

Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
DateUsersRatingReviewsVersion
May 24, 20261.2.1
Now1.2.1

Permissions & access

Permissions
storagetabsalarms
Host access
https://01.ai/*, https://*.01.ai/*, https://abnormalsecurity.com/*, https://*.abnormalsecurity.com/*, https://abridge.com/*, https://*.abridge.com/*, https://activepieces.com/*, https://*.activepieces.com/*, https://ada.cx/*, https://*.ada.cx/*, https://adept.ai/*, https://*.adept.ai/*, https://adobe.com/*, https://*.adobe.com/*, https://agenta.ai/*, https://*.agenta.ai/*, https://agentgpt.reworkd.ai/*, https://*.agentgpt.reworkd.ai/*, https://agpt.co/*, https://*.agpt.co/*, https://ai.360.cn/*, https://*.ai.360.cn/*, https://ai.google.co.jp/*, https://*.ai.google.co.jp/*, https://ai.google.com/*, https://*.ai.google.com/*, https://ai.naver.com/*, https://*.ai.naver.com/*, https://ai.tableau.com/*, https://*.ai.tableau.com/*, https://ai21.com/*, https://*.ai21.com/*, https://aide.dev/*, https://*.aide.dev/*, https://aider.chat/*, https://*.aider.chat/*, https://aidoc.com/*, https://*.aidoc.com/*, https://aikido.dev/*, https://*.aikido.dev/*, https://airbase.com/*, https://*.airbase.com/*, https://airgram.io/*, https://*.airgram.io/*, https://airtable.com/*, https://*.airtable.com/*, https://aistudio.baidu.com/*, https://*.aistudio.baidu.com/*, https://aistudio.google.com/*, https://*.aistudio.google.com/*, https://ajelix.com/*, https://*.ajelix.com/*, https://akkio.com/*, https://*.akkio.com/*, https://aleph-alpha.com/*, https://*.aleph-alpha.com/*, https://alphasense.com/*, https://*.alphasense.com/*, https://ambiencehealthcare.com/*, https://*.ambiencehealthcare.com/*, https://andi.co/*, https://*.andi.co/*, https://anthropic.com/*, https://*.anthropic.com/*, https://anyscale.com/*, https://*.anyscale.com/*, https://anyword.com/*, https://*.anyword.com/*, https://api.ai21.com/*, https://*.api.ai21.com/*, https://api.anthropic.com/*, https://*.api.anthropic.com/*, https://api.cohere.com/*, https://*.api.cohere.com/*, https://api.coze.com/*, https://*.api.coze.com/*, https://api.deepinfra.com/*, https://*.api.deepinfra.com/*, https://api.deepseek.com/*, https://*.api.deepseek.com/*, https://api.fireworks.ai/*, https://*.api.fireworks.ai/*, https://api.groq.com/*, https://*.api.groq.com/*, https://api.hyperbolic.xyz/*, https://*.api.hyperbolic.xyz/*, https://api.meta.ai/*, https://*.api.meta.ai/*, https://api.mistral.ai/*, https://*.api.mistral.ai/*, https://api.openai.com/*, https://*.api.openai.com/*, https://api.perplexity.ai/*, https://*.api.perplexity.ai/*, https://api.reka.ai/*, https://*.api.reka.ai/*, https://api.sambanova.ai/*, https://*.api.sambanova.ai/*, https://api.together.xyz/*, https://*.api.together.xyz/*, https://api.x.ai/*, https://*.api.x.ai/*, https://apollo.io/*, https://*.apollo.io/*, https://app.endpoints.huggingface.cloud/*, https://*.app.endpoints.huggingface.cloud/*, https://app.giskard.ai/*, https://*.app.giskard.ai/*, https://app.glean.com/*, https://*.app.glean.com/*, https://app.mlflow.org/*, https://*.app.mlflow.org/*, https://app.moveworks.com/*, https://*.app.moveworks.com/*, https://app.runwayml.com/*, https://*.app.runwayml.com/*, https://app.slack.com/*, https://*.app.slack.com/*, https://app.snowflake.com/*, https://*.app.snowflake.com/*, https://appzen.com/*, https://*.appzen.com/*, https://arize.com/*, https://*.arize.com/*, https://armorcode.com/*, https://*.armorcode.com/*, https://artbreeder.com/*, https://*.artbreeder.com/*, https://asana.com/*, https://*.asana.com/*, https://ashbyhq.com/*, https://*.ashbyhq.com/*, https://ask.tableau.com/*, https://*.ask.tableau.com/*, https://askyourpdf.com/*, https://*.askyourpdf.com/*, https://assemblyai.com/*, https://*.assemblyai.com/*, https://atlassian.com/*, https://*.atlassian.com/*, https://audo.ai/*, https://*.audo.ai/*, https://auth.openai.com/*, https://*.auth.openai.com/*, https://autodraw.com/*, https://*.autodraw.com/*, https://autogpt.net/*, https://*.autogpt.net/*, https://autotrain.huggingface.co/*, https://*.autotrain.huggingface.co/*, https://avoma.com/*, https://*.avoma.com/*, https://aws.amazon.com/*, https://*.aws.amazon.com/*, https://baichuan-ai.com/*, https://*.baichuan-ai.com/*, https://bardeen.ai/*, https://*.bardeen.ai/*, https://baseten.co/*, https://*.baseten.co/*, https://beamery.com/*, https://*.beamery.com/*, https://bearly.ai/*, https://*.bearly.ai/*, https://beautiful.ai/*, https://*.beautiful.ai/*, https://bedrock.aws.amazon.com/*, https://*.bedrock.aws.amazon.com/*, https://bentoml.com/*, https://*.bentoml.com/*, https://beta.character.ai/*, https://*.beta.character.ai/*, https://bigmodel.cn/*, https://*.bigmodel.cn/*, https://bing.com/*, https://*.bing.com/*, https://bitbucket.org/*, https://*.bitbucket.org/*, https://blackboxai.com/*, https://*.blackboxai.com/*, https://bluewillow.ai/*, https://*.bluewillow.ai/*, https://bolt.new/*, https://*.bolt.new/*, https://boomy.com/*, https://*.boomy.com/*, https://botkeeper.com/*, https://*.botkeeper.com/*, https://botpress.com/*, https://*.botpress.com/*, https://box.com/*, https://*.box.com/*, https://braintrustdata.com/*, https://*.braintrustdata.com/*, https://brandmark.io/*, https://*.brandmark.io/*, https://brex.com/*, https://*.brex.com/*, https://build.nvidia.com/*, https://*.build.nvidia.com/*, https://canva.com/*, https://*.canva.com/*, https://casetext.com/*, https://*.casetext.com/*, https://cdn.oaistatic.com/*, https://*.cdn.oaistatic.com/*, https://cerebras.ai/*, https://*.cerebras.ai/*, https://character.ai/*, https://*.character.ai/*, https://chartgpt.dev/*, https://*.chartgpt.dev/*, https://chat.deepseek.com/*, https://*.chat.deepseek.com/*, https://chat.forefront.ai/*, https://*.chat.forefront.ai/*, https://chat.lmsys.org/*, https://*.chat.lmsys.org/*, https://chat.mistral.ai/*, https://*.chat.mistral.ai/*, https://chat.openai.com/*, https://*.chat.openai.com/*, https://chat.together.ai/*, https://*.chat.together.ai/*, https://chatbot.theb.ai/*, https://*.chatbot.theb.ai/*, https://chatglm.cn/*, https://*.chatglm.cn/*, https://chatgpt.com/*, https://*.chatgpt.com/*, https://chathub.gg/*, https://*.chathub.gg/*, https://chatpdf.com/*, https://*.chatpdf.com/*, https://chatsonic.writesonic.com/*, https://*.chatsonic.writesonic.com/*, https://chorus.ai/*, https://*.chorus.ai/*, https://civitai.com/*, https://*.civitai.com/*, https://claude-ai.net/*, https://*.claude-ai.net/*, https://claude.ai/*, https://*.claude.ai/*, https://clay.com/*, https://*.clay.com/*, https://cleanlab.ai/*, https://*.cleanlab.ai/*, https://cleanup.pictures/*, https://*.cleanup.pictures/*, https://cleanvoice.ai/*, https://*.cleanvoice.ai/*, https://clickup.com/*, https://*.clickup.com/*, https://clipdrop.co/*, https://*.clipdrop.co/*, https://close.com/*, https://*.close.com/*, https://cloud.lambdalabs.com/*, https://*.cloud.lambdalabs.com/*, https://cloud.sambanova.ai/*, https://*.cloud.sambanova.ai/*, https://clova.ai/*, https://*.clova.ai/*, https://coda.io/*, https://*.coda.io/*, https://codegen.com/*, https://*.codegen.com/*, https://codeium.com/*, https://*.codeium.com/*, https://coderabbit.ai/*, https://*.coderabbit.ai/*, https://codestral.mistral.ai/*, https://*.codestral.mistral.ai/*, https://cody.sourcegraph.com/*, https://*.cody.sourcegraph.com/*, https://cogniflow.ai/*, https://*.cogniflow.ai/*, https://cognition.ai/*, https://*.cognition.ai/*, https://cognosys.ai/*, https://*.cognosys.ai/*, https://cohere.com/*, https://*.cohere.com/*, https://colibri.ai/*, https://*.colibri.ai/*, https://comet.com/*, https://*.comet.com/*, https://confluence.atlassian.com/*, https://*.confluence.atlassian.com/*, https://consensus.app/*, https://*.consensus.app/*, https://console.anthropic.com/*, https://*.console.anthropic.com/*, https://console.cloud.google.com/*, https://*.console.cloud.google.com/*, https://contentbot.ai/*, https://*.contentbot.ai/*, https://continue.dev/*, https://*.continue.dev/*, https://contractpodai.com/*, https://*.contractpodai.com/*, https://copilot.cloud.microsoft/*, https://*.copilot.cloud.microsoft/*, https://copilot.github.com/*, https://*.copilot.github.com/*, https://copilot.microsoft.com/*, https://*.copilot.microsoft.com/*, https://copy.ai/*, https://*.copy.ai/*, https://coral.cohere.com/*, https://*.coral.cohere.com/*, https://corover.ai/*, https://*.corover.ai/*, https://corti.ai/*, https://*.corti.ai/*, https://cotomi.ntt.com/*, https://*.cotomi.ntt.com/*, https://count.co/*, https://*.count.co/*, https://coupa.com/*, https://*.coupa.com/*, https://coze.com/*, https://*.coze.com/*, https://craft.do/*, https://*.craft.do/*, https://crew.ai/*, https://*.crew.ai/*, https://crewai.com/*, https://*.crewai.com/*, https://crowdstrike.com/*, https://*.crowdstrike.com/*, https://cursor.com/*, https://*.cursor.com/*, https://cursor.sh/*, https://*.cursor.sh/*, https://cybozuai.com/*, https://*.cybozuai.com/*, https://d-id.com/*, https://*.d-id.com/*, https://darktrace.com/*, https://*.darktrace.com/*, https://dashboard.cohere.com/*, https://*.dashboard.cohere.com/*, https://dashscope.aliyuncs.com/*, https://*.dashscope.aliyuncs.com/*, https://databricks.com/*, https://*.databricks.com/*, https://dataplatform.cloud.ibm.com/*, https://*.dataplatform.cloud.ibm.com/*, https://datarobot.com/*, https://*.datarobot.com/*, https://decktopus.com/*, https://*.decktopus.com/*, https://deepbrain.io/*, https://*.deepbrain.io/*, https://deepgram.com/*, https://*.deepgram.com/*, https://deepinfra.com/*, https://*.deepinfra.com/*, https://deepseek.com/*, https://*.deepseek.com/*, https://descript.com/*, https://*.descript.com/*, https://designs.ai/*, https://*.designs.ai/*, https://determined.ai/*, https://*.determined.ai/*, https://devin.ai/*, https://*.devin.ai/*, https://devv.ai/*, https://*.devv.ai/*, https://diagram.com/*, https://*.diagram.com/*, https://dify.ai/*, https://*.dify.ai/*, https://discord.com/*, https://*.discord.com/*, https://docgpt.ai/*, https://*.docgpt.ai/*, https://docs.google.com/*, https://*.docs.google.com/*, https://doubao.com/*, https://*.doubao.com/*, https://dreamstudio.ai/*, https://*.dreamstudio.ai/*, https://drift.com/*, https://*.drift.com/*, https://dropbox.com/*, https://*.dropbox.com/*, https://dust.tt/*, https://*.dust.tt/*, https://e2b.dev/*, https://*.e2b.dev/*, https://eesel.ai/*, https://*.eesel.ai/*, https://eightfold.ai/*, https://*.eightfold.ai/*, https://einstein.salesforce.com/*, https://*.einstein.salesforce.com/*, https://elevenlabs.io/*, https://*.elevenlabs.io/*, https://elicit.com/*, https://*.elicit.com/*, https://endpoints.anyscale.com/*, https://*.endpoints.anyscale.com/*, https://engage-ai.co/*, https://*.engage-ai.co/*, https://eu-de.ml.cloud.ibm.com/*, https://*.eu-de.ml.cloud.ibm.com/*, https://evidently.ai/*, https://*.evidently.ai/*, https://evisort.com/*, https://*.evisort.com/*, https://exa.ai/*, https://*.exa.ai/*, https://exabeam.com/*, https://*.exabeam.com/*, https://factory.ai/*, https://*.factory.ai/*, https://fal.ai/*, https://*.fal.ai/*, https://fathom.video/*, https://*.fathom.video/*, https://fellow.app/*, https://*.fellow.app/*, https://fetcher.ai/*, https://*.fetcher.ai/*, https://figma.com/*, https://*.figma.com/*, https://findem.ai/*, https://*.findem.ai/*, https://fireflies.ai/*, https://*.fireflies.ai/*, https://firefly.adobe.com/*, https://*.firefly.adobe.com/*, https://fireworks.ai/*, https://*.fireworks.ai/*, https://fixie.ai/*, https://*.fixie.ai/*, https://flatiron.com/*, https://*.flatiron.com/*, https://fliki.ai/*, https://*.fliki.ai/*, https://flowiseai.com/*, https://*.flowiseai.com/*, https://flux.ai/*, https://*.flux.ai/*, https://forethought.ai/*, https://*.forethought.ai/*, https://framer.com/*, https://*.framer.com/*, https://freshdesk.com/*, https://*.freshdesk.com/*, https://freshworks.com/*, https://*.freshworks.com/*, https://front.com/*, https://*.front.com/*, https://galileo.ai/*, https://*.galileo.ai/*, https://gamma.app/*, https://*.gamma.app/*, https://gemini.google.com/*, https://*.gemini.google.com/*, https://generativelanguage.googleapis.com/*, https://*.generativelanguage.googleapis.com/*, https://genmo.ai/*, https://*.genmo.ai/*, https://gethugohq.com/*, https://*.gethugohq.com/*, https://getimg.ai/*, https://*.getimg.ai/*, https://getmerlin.in/*, https://*.getmerlin.in/*, https://github.com/*, https://*.github.com/*, https://gitlab.com/*, https://*.gitlab.com/*, https://gitpod.io/*, https://*.gitpod.io/*, https://glasp.co/*, https://*.glasp.co/*, https://globe.engineer/*, https://*.globe.engineer/*, https://gong.io/*, https://*.gong.io/*, https://gorgias.com/*, https://*.gorgias.com/*, https://grain.com/*, https://*.grain.com/*, https://grammarly.com/*, https://*.grammarly.com/*, https://greenhouse.io/*, https://*.greenhouse.io/*, https://grok.com/*, https://*.grok.com/*, https://grok.x.ai/*, https://*.grok.x.ai/*, https://groq.com/*, https://*.groq.com/*, https://gumloop.com/*, https://*.gumloop.com/*, https://h2o.ai/*, https://*.h2o.ai/*, https://hailuoai.com/*, https://*.hailuoai.com/*, https://harpa.ai/*, https://*.harpa.ai/*, https://harvey.ai/*, https://*.harvey.ai/*, https://helicone.ai/*, https://*.helicone.ai/*, https://hex.tech/*, https://*.hex.tech/*, https://heygen.com/*, https://*.heygen.com/*, https://hireez.com/*, https://*.hireez.com/*, https://hirevue.com/*, https://*.hirevue.com/*, https://hix.ai/*, https://*.hix.ai/*, https://hixai.com/*, https://*.hixai.com/*, https://hubspot.com/*, https://*.hubspot.com/*, https://huggingchat.co/*, https://*.huggingchat.co/*, https://huggingface.co/*, https://*.huggingface.co/*, https://humanloop.com/*, https://*.humanloop.com/*, https://humata.ai/*, https://*.humata.ai/*, https://hunyuan.tencent.com/*, https://*.hunyuan.tencent.com/*, https://hyper.ai/*, https://*.hyper.ai/*, https://hyperclova.ai/*, https://*.hyperclova.ai/*, https://hyperwriteai.com/*, https://*.hyperwriteai.com/*, https://ibm.com/*, https://*.ibm.com/*, https://ideogram.ai/*, https://*.ideogram.ai/*, https://imagen3.withgoogle.com/*, https://*.imagen3.withgoogle.com/*, https://inception.ae/*, https://*.inception.ae/*, https://inference.cerebras.ai/*, https://*.inference.cerebras.ai/*, https://insilico.com/*, https://*.insilico.com/*, https://integrate.api.nvidia.com/*, https://*.integrate.api.nvidia.com/*, https://intercom.com/*, https://*.intercom.com/*, https://invideo.io/*, https://*.invideo.io/*, https://ironcladapp.com/*, https://*.ironcladapp.com/*, https://jamie.ai/*, https://*.jamie.ai/*, https://jasper.ai/*, https://*.jasper.ai/*, https://jiaismodel.cloud/*, https://*.jiaismodel.cloud/*, https://jira.atlassian.com/*, https://*.jira.atlassian.com/*, https://julius.ai/*, https://*.julius.ai/*, https://kagi.com/*, https://*.kagi.com/*, https://kakao.com/*, https://*.kakao.com/*, https://kensho.com/*, https://*.kensho.com/*, https://kimi.ai/*, https://*.kimi.ai/*, https://kimi.moonshot.cn/*, https://*.kimi.moonshot.cn/*, https://kira-systems.com/*, https://*.kira-systems.com/*, https://klingai.com/*, https://*.klingai.com/*, https://krea.ai/*, https://*.krea.ai/*, https://krisp.ai/*, https://*.krisp.ai/*, https://krutrim.com/*, https://*.krutrim.com/*, https://kustomer.com/*, https://*.kustomer.com/*, https://labs.perplexity.ai/*, https://*.labs.perplexity.ai/*, https://lacework.com/*, https://*.lacework.com/*, https://lambdalabs.com/*, https://*.lambdalabs.com/*, https://lamini.ai/*, https://*.lamini.ai/*, https://langchain.com/*, https://*.langchain.com/*, https://langflow.org/*, https://*.langflow.org/*, https://langfuse.com/*, https://*.langfuse.com/*, https://laxis.com/*, https://*.laxis.com/*, https://leena.ai/*, https://*.leena.ai/*, https://legal.thomsonreuters.com/*, https://*.legal.thomsonreuters.com/*, https://legitsecurity.com/*, https://*.legitsecurity.com/*, https://leonardo.ai/*, https://*.leonardo.ai/*, https://lepton.ai/*, https://*.lepton.ai/*, https://lever.co/*, https://*.lever.co/*, https://lex.page/*, https://*.lex.page/*, https://lexion.ai/*, https://*.lexion.ai/*, https://lexisnexis.com/*, https://*.lexisnexis.com/*, https://leya.law/*, https://*.leya.law/*, https://lindy.ai/*, https://*.lindy.ai/*, https://linear.app/*, https://*.linear.app/*, https://linkai.com/*, https://*.linkai.com/*, https://litera.com/*, https://*.litera.com/*, https://llama-api.com/*, https://*.llama-api.com/*, https://llama.meta.com/*, https://*.llama.meta.com/*, https://lmarena.ai/*, https://*.lmarena.ai/*, https://longshot.ai/*, https://*.longshot.ai/*, https://looka.com/*, https://*.looka.com/*, https://lovable.dev/*, https://*.lovable.dev/*, https://lovo.ai/*, https://*.lovo.ai/*, https://lucid.app/*, https://*.lucid.app/*, https://luma.ai/*, https://*.luma.ai/*, https://lumalabs.ai/*, https://*.lumalabs.ai/*, https://luminance.com/*, https://*.luminance.com/*, https://mage.space/*, https://*.mage.space/*, https://magician.design/*, https://*.magician.design/*, https://magicslides.app/*, https://*.magicslides.app/*, https://make.com/*, https://*.make.com/*, https://manatal.com/*, https://*.manatal.com/*, https://manus.im/*, https://*.manus.im/*, https://maxai.me/*, https://*.maxai.me/*, https://meetgeek.ai/*, https://*.meetgeek.ai/*, https://mem.ai/*, https://*.mem.ai/*, https://mendel.ai/*, https://*.mendel.ai/*, https://merlin.foyer.work/*, https://*.merlin.foyer.work/*, https://meta.ai/*, https://*.meta.ai/*, https://microsoft365.com/*, https://*.microsoft365.com/*, https://midjourney.com/*, https://*.midjourney.com/*, https://mindsdb.com/*, https://*.mindsdb.com/*, https://minimax.chat/*, https://*.minimax.chat/*, https://miro.com/*, https://*.miro.com/*, https://missiveapp.com/*, https://*.missiveapp.com/*, https://mistral.ai/*, https://*.mistral.ai/*, https://ml.azure.com/*, https://*.ml.azure.com/*, https://mlflow.org/*, https://*.mlflow.org/*, https://modal.com/*, https://*.modal.com/*, https://monday.com/*, https://*.monday.com/*, https://monica.im/*, https://*.monica.im/*, https://morph.studio/*, https://*.morph.studio/*, https://mosaicml.com/*, https://*.mosaicml.com/*, https://motion.so/*, https://*.motion.so/*, https://mubert.com/*, https://*.mubert.com/*, https://murf.ai/*, https://*.murf.ai/*, https://mypptai.com/*, https://*.mypptai.com/*, https://n8n.cloud/*, https://*.n8n.cloud/*, https://n8n.io/*, https://*.n8n.io/*, https://nabla.com/*, https://*.nabla.com/*, https://nanobeep.com/*, https://*.nanobeep.com/*, https://narrativebi.com/*, https://*.narrativebi.com/*, https://nat.dev/*, https://*.nat.dev/*, https://nightcafe.studio/*, https://*.nightcafe.studio/*, https://notes.microsoft.com/*, https://*.notes.microsoft.com/*, https://notion.com/*, https://*.notion.com/*, https://notion.so/*, https://*.notion.so/*, https://noty.ai/*, https://*.noty.ai/*, https://novita.ai/*, https://*.novita.ai/*, https://ntropy.com/*, https://*.ntropy.com/*, https://nuance.com/*, https://*.nuance.com/*, https://numerai.com/*, https://*.numerai.com/*, https://nvidia.com/*, https://*.nvidia.com/*, https://oai.azure.com/*, https://*.oai.azure.com/*, https://obviously.ai/*, https://*.obviously.ai/*, https://ocrolus.com/*, https://*.ocrolus.com/*, https://octo.ai/*, https://*.octo.ai/*, https://onit.com/*, https://*.onit.com/*, https://openai-hk.com/*, https://*.openai-hk.com/*, https://openai.com/*, https://*.openai.com/*, https://openpipe.ai/*, https://*.openpipe.ai/*, https://openrouter.ai/*, https://*.openrouter.ai/*, https://ora.ai/*, https://*.ora.ai/*, https://oracle.com/*, https://*.oracle.com/*, https://orca.security/*, https://*.orca.security/*, https://orq.ai/*, https://*.orq.ai/*, https://otter.ai/*, https://*.otter.ai/*, https://outreach.io/*, https://*.outreach.io/*, https://paige.ai/*, https://*.paige.ai/*, https://paradox.ai/*, https://*.paradox.ai/*, https://patentpal.com/*, https://*.patentpal.com/*, https://pdfgpt.io/*, https://*.pdfgpt.io/*, https://perplexity.ai/*, https://*.perplexity.ai/*, https://phenom.com/*, https://*.phenom.com/*, https://phind.com/*, https://*.phind.com/*, https://phoenix.arize.com/*, https://*.phoenix.arize.com/*, https://pi.ai/*, https://*.pi.ai/*, https://pictory.ai/*, https://*.pictory.ai/*, https://pika.art/*, https://*.pika.art/*, https://pipedrive.com/*, https://*.pipedrive.com/*, https://pitch.com/*, https://*.pitch.com/*, https://pixai.art/*, https://*.pixai.art/*, https://pixlr.com/*, https://*.pixlr.com/*, https://pixverse.ai/*, https://*.pixverse.ai/*, https://platform.moonshot.cn/*, https://*.platform.moonshot.cn/*, https://platform.openai.com/*, https://*.platform.openai.com/*, https://play.ht/*, https://*.play.ht/*, https://playground.ai/*, https://*.playground.ai/*, https://playgroundai.com/*, https://*.playgroundai.com/*, https://plusdocs.com/*, https://*.plusdocs.com/*, https://poe.com/*, https://*.poe.com/*, https://polyai.com/*, https://*.polyai.com/*, https://popai.pro/*, https://*.popai.pro/*, https://portal.azure.com/*, https://*.portal.azure.com/*, https://portkey.ai/*, https://*.portkey.ai/*, https://predibase.com/*, https://*.predibase.com/*, https://presentations.ai/*, https://*.presentations.ai/*, https://prezi.com/*, https://*.prezi.com/*, https://prodia.com/*, https://*.prodia.com/*, https://promptfoo.dev/*, https://*.promptfoo.dev/*, https://promptlayer.com/*, https://*.promptlayer.com/*, https://qianwen.aliyun.com/*, https://*.qianwen.aliyun.com/*, https://quillbot.com/*, https://*.quillbot.com/*, https://quora.com/*, https://*.quora.com/*, https://ramp.com/*, https://*.ramp.com/*, https://read.ai/*, https://*.read.ai/*, https://reclaim.ai/*, https://*.reclaim.ai/*, https://recordedfuture.com/*, https://*.recordedfuture.com/*, https://recraft.ai/*, https://*.recraft.ai/*, https://regard.com/*, https://*.regard.com/*, https://reka.ai/*, https://*.reka.ai/*, https://relevanceai.com/*, https://*.relevanceai.com/*, https://remove.bg/*, https://*.remove.bg/*, https://replica.ai/*, https://*.replica.ai/*, https://replicate.com/*, https://*.replicate.com/*, https://replit.com/*, https://*.replit.com/*, https://resemble.ai/*, https://*.resemble.ai/*, https://respell.ai/*, https://*.respell.ai/*, https://rev.ai/*, https://*.rev.ai/*, https://rewatch.com/*, https://*.rewatch.com/*, https://rippling.com/*, https://*.rippling.com/*, https://robin.ai/*, https://*.robin.ai/*, https://rows.com/*, https://*.rows.com/*, https://runpod.io/*, https://*.runpod.io/*, https://runwayml.com/*, https://*.runwayml.com/*, https://rxlogix.com/*, https://*.rxlogix.com/*, https://rytr.me/*, https://*.rytr.me/*, https://saga.so/*, https://*.saga.so/*, https://salesforce.com/*, https://*.salesforce.com/*, https://salesloft.com/*, https://*.salesloft.com/*, https://sambanova.ai/*, https://*.sambanova.ai/*, https://sap.com/*, https://*.sap.com/*, https://sarvam.ai/*, https://*.sarvam.ai/*, https://scale.com/*, https://*.scale.com/*, https://scholarai.io/*, https://*.scholarai.io/*, https://scite.ai/*, https://*.scite.ai/*, https://sdk.vercel.ai/*, https://*.sdk.vercel.ai/*, https://seaart.ai/*, https://*.seaart.ai/*, https://search.brave.com/*, https://*.search.brave.com/*, https://secureworks.com/*, https://*.secureworks.com/*, https://seekout.com/*, https://*.seekout.com/*, https://semanticscholar.org/*, https://*.semanticscholar.org/*, https://sembly.ai/*, https://*.sembly.ai/*, https://sensechat.sensetime.com/*, https://*.sensechat.sensetime.com/*, https://sentinelone.com/*, https://*.sentinelone.com/*, https://servicenow.com/*, https://*.servicenow.com/*, https://servicetitan.com/*, https://*.servicetitan.com/*, https://sheetai.app/*, https://*.sheetai.app/*, https://shortwave.com/*, https://*.shortwave.com/*, https://sider.ai/*, https://*.sider.ai/*, https://slack.com/*, https://*.slack.com/*, https://slidesai.io/*, https://*.slidesai.io/*, https://slidesgo.com/*, https://*.slidesgo.com/*, https://smith.langchain.com/*, https://*.smith.langchain.com/*, https://snowflake.com/*, https://*.snowflake.com/*, https://socure.com/*, https://*.socure.com/*, https://sora.com/*, https://*.sora.com/*, https://soundraw.io/*, https://*.soundraw.io/*, https://sourcegraph.com/*, https://*.sourcegraph.com/*, https://speechify.com/*, https://*.speechify.com/*, https://spellbook.legal.ai/*, https://*.spellbook.legal.ai/*, https://stability.ai/*, https://*.stability.ai/*, https://stablecog.com/*, https://*.stablecog.com/*, https://stablediffusionweb.com/*, https://*.stablediffusionweb.com/*, https://stack-ai.com/*, https://*.stack-ai.com/*, https://stackblitz.com/*, https://*.stackblitz.com/*, https://stampli.com/*, https://*.stampli.com/*, https://steamship.com/*, https://*.steamship.com/*, https://stepfun.com/*, https://*.stepfun.com/*, https://steve.ai/*, https://*.steve.ai/*, https://stockimg.ai/*, https://*.stockimg.ai/*, https://storyd.ai/*, https://*.storyd.ai/*, https://sudowrite.com/*, https://*.sudowrite.com/*, https://suki.ai/*, https://*.suki.ai/*, https://suno.ai/*, https://*.suno.ai/*, https://suno.com/*, https://*.suno.com/*, https://superagi.com/*, https://*.superagi.com/*, https://superhuman.com/*, https://*.superhuman.com/*, https://supermaven.com/*, https://*.supermaven.com/*, https://supernormal.com/*, https://*.supernormal.com/*, https://superpower.chat/*, https://*.superpower.chat/*, https://sweep.dev/*, https://*.sweep.dev/*, https://synthesia.io/*, https://*.synthesia.io/*, https://t3nsor.com/*, https://*.t3nsor.com/*, https://tabnine.com/*, https://*.tabnine.com/*, https://tactiq.io/*, https://*.tactiq.io/*, https://talkie-ai.com/*, https://*.talkie-ai.com/*, https://taskade.com/*, https://*.taskade.com/*, https://teams.microsoft.com/*, https://*.teams.microsoft.com/*, https://tempus.com/*, https://*.tempus.com/*, https://tensor.art/*, https://*.tensor.art/*, https://tiangong.cn/*, https://*.tiangong.cn/*, https://tldv.io/*, https://*.tldv.io/*, https://together.ai/*, https://*.together.ai/*, https://tome.app/*, https://*.tome.app/*, https://tongyi.aliyun.com/*, https://*.tongyi.aliyun.com/*, https://traceloop.com/*, https://*.traceloop.com/*, https://truefoundry.com/*, https://*.truefoundry.com/*, https://trullion.com/*, https://*.trullion.com/*, https://typingmind.com/*, https://*.typingmind.com/*, https://udio.com/*, https://*.udio.com/*, https://uizard.io/*, https://*.uizard.io/*, https://us-central1-aiplatform.googleapis.com/*, https://*.us-central1-aiplatform.googleapis.com/*, https://us-east-1.console.aws.amazon.com/*, https://*.us-east-1.console.aws.amazon.com/*, https://uxpilot.ai/*, https://*.uxpilot.ai/*, https://v0.dev/*, https://*.v0.dev/*, https://vast.ai/*, https://*.vast.ai/*, https://vectra.ai/*, https://*.vectra.ai/*, https://veed.io/*, https://*.veed.io/*, https://vellum.ai/*, https://*.vellum.ai/*, https://venice.ai/*, https://*.venice.ai/*, https://veracyte.com/*, https://*.veracyte.com/*, https://vertexai.google.com/*, https://*.vertexai.google.com/*, https://vic.ai/*, https://*.vic.ai/*, https://viggle.ai/*, https://*.viggle.ai/*, https://visily.ai/*, https://*.visily.ai/*, https://visme.co/*, https://*.visme.co/*, https://vmaker.com/*, https://*.vmaker.com/*, https://voiceflow.com/*, https://*.voiceflow.com/*, https://wandb.ai/*, https://*.wandb.ai/*, https://webex.com/*, https://*.webex.com/*, https://webpilot.ai/*, https://*.webpilot.ai/*, https://wellsaidlabs.com/*, https://*.wellsaidlabs.com/*, https://wenxin.baidu.com/*, https://*.wenxin.baidu.com/*, https://whylabs.ai/*, https://*.whylabs.ai/*, https://windsurf.com/*, https://*.windsurf.com/*, https://wiseone.app/*, https://*.wiseone.app/*, https://wistia.com/*, https://*.wistia.com/*, https://wiz.io/*, https://*.wiz.io/*, https://wordtune.com/*, https://*.wordtune.com/*, https://workday.com/*, https://*.workday.com/*, https://writer.com/*, https://*.writer.com/*, https://writesonic.com/*, https://*.writesonic.com/*, https://wrtn.io/*, https://*.wrtn.io/*, https://www.perplexity.ai/*, https://*.www.perplexity.ai/*, https://x.ai/*, https://*.x.ai/*, https://xinghuo.xfyun.cn/*, https://*.xinghuo.xfyun.cn/*, https://yiyan.baidu.com/*, https://*.yiyan.baidu.com/*, https://you.com/*, https://*.you.com/*, https://zapier.com/*, https://*.zapier.com/*, https://zendesk.com/*, https://*.zendesk.com/*, https://zhipu.ai/*, https://*.zhipu.ai/*, https://zoom.com/*, https://*.zoom.com/*, https://zoom.us/*, https://*.zoom.us/*

Screenshots

ThreatVec Shadow AI screenshot 1ThreatVec Shadow AI screenshot 2ThreatVec Shadow AI screenshot 3

About

ThreatVec Shadow AI gives security teams visibility into the 554+ AI
tools their employees use in the browser, and blocks accidental data
leaks before they leave the page.

WHAT IT DOES

• Auto-discovers AI services visited in the browser across 554
  named products in 24 categories — including the ChatGPT, Claude,
  Gemini, Perplexity, Copilot, Mistral, and DeepSeek web apps, AWS
  Bedrock, Azure OpenAI, plus coding assistants (Cursor, Codeium,
  Tabnine, Aider, v0), image generators (Midjourney, Firefly,
  Leonardo, Ideogram), agent frameworks (AutoGPT, Lindy, n8n),
  meeting AI (Otter, Fireflies, tl;dv), healthcare AI, legal AI,
  finance AI, and customer-service AI tools — and feeds an inventory
  back to your ThreatVec dashboard.

• Scans content typed into AI prompt fields for PII (email, SSN,
  credit-card, API keys, AWS keys, Anthropic/OpenAI keys, JWT
  tokens, internal hostnames, phone numbers, passwords). Detected
  leaks are blocked or masked client-side BEFORE the prompt is sent
  to the AI service, and a redacted record is logged to your
  ThreatVec audit trail.

• Enforces org policy: your security team can mark each AI service
  as sanctioned, restricted, or blocked, and choose per-PII-class
  actions (block / mask / warn / allow). The extension applies the
  policy at the browser, even on unmanaged personal AI accounts.

• Surfaces a per-user activity summary in the popup so end users
  understand which AI tools they've touched, what was blocked, and
  why.

WHAT IT DOES NOT DO

• It does NOT inject into or modify the behavior of any specific
  AI service (no ChatGPT-integration, no Copilot-augmentation —
  it observes browser traffic and acts only on outbound prompts
  the user is about to send).

• It does NOT send the content of prompts to ThreatVec servers.
  Only metadata (service name, time, PII-class fingerprint, action
  taken) is reported.

PERMISSIONS RATIONALE

• storage: persist per-user policy + activity log locally.
• tabs: detect which AI service is open in the active tab.
• alarms: periodic local sync of policy from the ThreatVec dashboard.
• host permissions (1,136 explicit URL patterns for 568 hostnames
  across 554 named AI services): every pattern is anchored to a
  documented AI tool in our public service registry at
  https://app.threatvec.com/ai-services-catalogue. Content scripts
  inject ONLY on these explicit hosts. The extension does NOT inject
  into or watch any non-AI sites the user visits.
• optional_host_permissions (https://*/*): NOT requested at install
  time. An admin can grant this at runtime ONLY for org-defined
  custom AI services (e.g. an internal in-house LLM at
  internal-chat.acme.com). Chrome prompts the user explicitly before
  any per-domain grant is added.

PRIVACY

• No prompt content leaves the browser.
• No PII leaves the browser (it is detected client-side and stripped
  before submission).
• Per-org pseudonymization with HMAC: even the "we saw a PII
  attempt" telemetry doesn't carry the raw user identifier.
• See https://threatvec.com/privacy for the full policy.

REQUIREMENTS

A ThreatVec account is required to receive policy + see telemetry in
the dashboard. The extension works in passive-observe mode without an
account but cannot enforce policy or report to a SOC. Sign up free at
https://app.threatvec.com (180-day free trial).

Technical

Version
1.2.1
Manifest
V3
Size
69.19KiB
Min Chrome
88
Languages
1
Featured
No

Metadata

ID
akmohmegmejcgplmfodboibobhalljpj
Developer ID
u497fd091d83a29fdae1c90bef76961ba
Developer Email
[email protected]
Created
May 23, 2026
Last Updated (Store)
May 23, 2026
Last Scraped
Jun 14, 2026
Website
Support URL

Data sourced from the Chrome Web Store · last verified Jun 14, 2026.