ThreatVec Shadow AI
Discover shadow AI usage across 554 AI services, detect and block PII leakage, and enforce org policy on browser-based AI.
As of June 2026, ThreatVec Shadow AI has — users in the Privacy & Security category.
Usersno change0%
—
—
Ratingno change0%
—
— reviews
Reviewsno change0%
—
Version
1.2.1
Manifest V3
History
1 snapshotsTracking since May 24, 2026.
Not enough history yet for this metric — the chart fills in as we collect more snapshots.
View as table
| Date | Users | Rating | Reviews | Version |
|---|---|---|---|---|
| May 24, 2026 | — | — | — | 1.2.1 |
| Now | — | — | — | 1.2.1 |
Permissions & access
- Permissions
- storagetabsalarms
- Host access
- https://01.ai/*, https://*.01.ai/*, https://abnormalsecurity.com/*, https://*.abnormalsecurity.com/*, https://abridge.com/*, https://*.abridge.com/*, https://activepieces.com/*, https://*.activepieces.com/*, https://ada.cx/*, https://*.ada.cx/*, https://adept.ai/*, https://*.adept.ai/*, https://adobe.com/*, https://*.adobe.com/*, https://agenta.ai/*, https://*.agenta.ai/*, https://agentgpt.reworkd.ai/*, https://*.agentgpt.reworkd.ai/*, https://agpt.co/*, https://*.agpt.co/*, https://ai.360.cn/*, https://*.ai.360.cn/*, https://ai.google.co.jp/*, https://*.ai.google.co.jp/*, https://ai.google.com/*, https://*.ai.google.com/*, https://ai.naver.com/*, https://*.ai.naver.com/*, https://ai.tableau.com/*, https://*.ai.tableau.com/*, https://ai21.com/*, https://*.ai21.com/*, https://aide.dev/*, https://*.aide.dev/*, https://aider.chat/*, https://*.aider.chat/*, https://aidoc.com/*, https://*.aidoc.com/*, https://aikido.dev/*, https://*.aikido.dev/*, https://airbase.com/*, https://*.airbase.com/*, https://airgram.io/*, https://*.airgram.io/*, https://airtable.com/*, https://*.airtable.com/*, https://aistudio.baidu.com/*, https://*.aistudio.baidu.com/*, https://aistudio.google.com/*, https://*.aistudio.google.com/*, https://ajelix.com/*, https://*.ajelix.com/*, https://akkio.com/*, https://*.akkio.com/*, https://aleph-alpha.com/*, https://*.aleph-alpha.com/*, https://alphasense.com/*, https://*.alphasense.com/*, https://ambiencehealthcare.com/*, https://*.ambiencehealthcare.com/*, https://andi.co/*, https://*.andi.co/*, https://anthropic.com/*, https://*.anthropic.com/*, https://anyscale.com/*, https://*.anyscale.com/*, https://anyword.com/*, https://*.anyword.com/*, https://api.ai21.com/*, https://*.api.ai21.com/*, https://api.anthropic.com/*, https://*.api.anthropic.com/*, https://api.cohere.com/*, https://*.api.cohere.com/*, https://api.coze.com/*, https://*.api.coze.com/*, https://api.deepinfra.com/*, https://*.api.deepinfra.com/*, https://api.deepseek.com/*, https://*.api.deepseek.com/*, https://api.fireworks.ai/*, https://*.api.fireworks.ai/*, https://api.groq.com/*, https://*.api.groq.com/*, https://api.hyperbolic.xyz/*, https://*.api.hyperbolic.xyz/*, https://api.meta.ai/*, https://*.api.meta.ai/*, https://api.mistral.ai/*, https://*.api.mistral.ai/*, https://api.openai.com/*, https://*.api.openai.com/*, https://api.perplexity.ai/*, https://*.api.perplexity.ai/*, https://api.reka.ai/*, https://*.api.reka.ai/*, https://api.sambanova.ai/*, https://*.api.sambanova.ai/*, https://api.together.xyz/*, https://*.api.together.xyz/*, https://api.x.ai/*, https://*.api.x.ai/*, https://apollo.io/*, https://*.apollo.io/*, https://app.endpoints.huggingface.cloud/*, https://*.app.endpoints.huggingface.cloud/*, https://app.giskard.ai/*, https://*.app.giskard.ai/*, https://app.glean.com/*, https://*.app.glean.com/*, https://app.mlflow.org/*, https://*.app.mlflow.org/*, https://app.moveworks.com/*, https://*.app.moveworks.com/*, https://app.runwayml.com/*, https://*.app.runwayml.com/*, https://app.slack.com/*, https://*.app.slack.com/*, https://app.snowflake.com/*, https://*.app.snowflake.com/*, https://appzen.com/*, https://*.appzen.com/*, https://arize.com/*, https://*.arize.com/*, https://armorcode.com/*, https://*.armorcode.com/*, https://artbreeder.com/*, https://*.artbreeder.com/*, https://asana.com/*, https://*.asana.com/*, https://ashbyhq.com/*, https://*.ashbyhq.com/*, https://ask.tableau.com/*, https://*.ask.tableau.com/*, https://askyourpdf.com/*, https://*.askyourpdf.com/*, https://assemblyai.com/*, https://*.assemblyai.com/*, https://atlassian.com/*, https://*.atlassian.com/*, https://audo.ai/*, https://*.audo.ai/*, https://auth.openai.com/*, https://*.auth.openai.com/*, https://autodraw.com/*, https://*.autodraw.com/*, https://autogpt.net/*, https://*.autogpt.net/*, https://autotrain.huggingface.co/*, https://*.autotrain.huggingface.co/*, https://avoma.com/*, https://*.avoma.com/*, https://aws.amazon.com/*, https://*.aws.amazon.com/*, https://baichuan-ai.com/*, https://*.baichuan-ai.com/*, https://bardeen.ai/*, https://*.bardeen.ai/*, https://baseten.co/*, https://*.baseten.co/*, https://beamery.com/*, https://*.beamery.com/*, https://bearly.ai/*, https://*.bearly.ai/*, https://beautiful.ai/*, https://*.beautiful.ai/*, https://bedrock.aws.amazon.com/*, https://*.bedrock.aws.amazon.com/*, https://bentoml.com/*, https://*.bentoml.com/*, https://beta.character.ai/*, https://*.beta.character.ai/*, https://bigmodel.cn/*, https://*.bigmodel.cn/*, https://bing.com/*, https://*.bing.com/*, https://bitbucket.org/*, https://*.bitbucket.org/*, https://blackboxai.com/*, https://*.blackboxai.com/*, https://bluewillow.ai/*, https://*.bluewillow.ai/*, https://bolt.new/*, https://*.bolt.new/*, https://boomy.com/*, https://*.boomy.com/*, https://botkeeper.com/*, https://*.botkeeper.com/*, https://botpress.com/*, https://*.botpress.com/*, https://box.com/*, https://*.box.com/*, https://braintrustdata.com/*, https://*.braintrustdata.com/*, https://brandmark.io/*, https://*.brandmark.io/*, https://brex.com/*, https://*.brex.com/*, https://build.nvidia.com/*, https://*.build.nvidia.com/*, https://canva.com/*, https://*.canva.com/*, https://casetext.com/*, https://*.casetext.com/*, https://cdn.oaistatic.com/*, https://*.cdn.oaistatic.com/*, https://cerebras.ai/*, https://*.cerebras.ai/*, https://character.ai/*, https://*.character.ai/*, https://chartgpt.dev/*, https://*.chartgpt.dev/*, https://chat.deepseek.com/*, https://*.chat.deepseek.com/*, https://chat.forefront.ai/*, https://*.chat.forefront.ai/*, https://chat.lmsys.org/*, https://*.chat.lmsys.org/*, https://chat.mistral.ai/*, https://*.chat.mistral.ai/*, https://chat.openai.com/*, https://*.chat.openai.com/*, https://chat.together.ai/*, https://*.chat.together.ai/*, https://chatbot.theb.ai/*, https://*.chatbot.theb.ai/*, https://chatglm.cn/*, https://*.chatglm.cn/*, https://chatgpt.com/*, https://*.chatgpt.com/*, https://chathub.gg/*, https://*.chathub.gg/*, https://chatpdf.com/*, https://*.chatpdf.com/*, https://chatsonic.writesonic.com/*, https://*.chatsonic.writesonic.com/*, https://chorus.ai/*, https://*.chorus.ai/*, https://civitai.com/*, https://*.civitai.com/*, https://claude-ai.net/*, https://*.claude-ai.net/*, https://claude.ai/*, https://*.claude.ai/*, https://clay.com/*, https://*.clay.com/*, https://cleanlab.ai/*, https://*.cleanlab.ai/*, https://cleanup.pictures/*, https://*.cleanup.pictures/*, https://cleanvoice.ai/*, https://*.cleanvoice.ai/*, https://clickup.com/*, https://*.clickup.com/*, https://clipdrop.co/*, https://*.clipdrop.co/*, https://close.com/*, https://*.close.com/*, https://cloud.lambdalabs.com/*, https://*.cloud.lambdalabs.com/*, https://cloud.sambanova.ai/*, https://*.cloud.sambanova.ai/*, https://clova.ai/*, https://*.clova.ai/*, https://coda.io/*, https://*.coda.io/*, https://codegen.com/*, https://*.codegen.com/*, https://codeium.com/*, https://*.codeium.com/*, https://coderabbit.ai/*, https://*.coderabbit.ai/*, https://codestral.mistral.ai/*, https://*.codestral.mistral.ai/*, https://cody.sourcegraph.com/*, https://*.cody.sourcegraph.com/*, https://cogniflow.ai/*, https://*.cogniflow.ai/*, https://cognition.ai/*, https://*.cognition.ai/*, https://cognosys.ai/*, https://*.cognosys.ai/*, https://cohere.com/*, https://*.cohere.com/*, https://colibri.ai/*, https://*.colibri.ai/*, https://comet.com/*, https://*.comet.com/*, https://confluence.atlassian.com/*, https://*.confluence.atlassian.com/*, https://consensus.app/*, https://*.consensus.app/*, https://console.anthropic.com/*, https://*.console.anthropic.com/*, https://console.cloud.google.com/*, https://*.console.cloud.google.com/*, https://contentbot.ai/*, https://*.contentbot.ai/*, https://continue.dev/*, https://*.continue.dev/*, https://contractpodai.com/*, https://*.contractpodai.com/*, https://copilot.cloud.microsoft/*, https://*.copilot.cloud.microsoft/*, https://copilot.github.com/*, https://*.copilot.github.com/*, https://copilot.microsoft.com/*, https://*.copilot.microsoft.com/*, https://copy.ai/*, https://*.copy.ai/*, https://coral.cohere.com/*, https://*.coral.cohere.com/*, https://corover.ai/*, https://*.corover.ai/*, https://corti.ai/*, https://*.corti.ai/*, https://cotomi.ntt.com/*, https://*.cotomi.ntt.com/*, https://count.co/*, https://*.count.co/*, https://coupa.com/*, https://*.coupa.com/*, https://coze.com/*, https://*.coze.com/*, https://craft.do/*, https://*.craft.do/*, https://crew.ai/*, https://*.crew.ai/*, https://crewai.com/*, https://*.crewai.com/*, https://crowdstrike.com/*, https://*.crowdstrike.com/*, https://cursor.com/*, https://*.cursor.com/*, https://cursor.sh/*, https://*.cursor.sh/*, https://cybozuai.com/*, https://*.cybozuai.com/*, https://d-id.com/*, https://*.d-id.com/*, https://darktrace.com/*, https://*.darktrace.com/*, https://dashboard.cohere.com/*, https://*.dashboard.cohere.com/*, https://dashscope.aliyuncs.com/*, https://*.dashscope.aliyuncs.com/*, https://databricks.com/*, https://*.databricks.com/*, https://dataplatform.cloud.ibm.com/*, https://*.dataplatform.cloud.ibm.com/*, https://datarobot.com/*, https://*.datarobot.com/*, https://decktopus.com/*, https://*.decktopus.com/*, https://deepbrain.io/*, https://*.deepbrain.io/*, https://deepgram.com/*, https://*.deepgram.com/*, https://deepinfra.com/*, https://*.deepinfra.com/*, https://deepseek.com/*, https://*.deepseek.com/*, https://descript.com/*, https://*.descript.com/*, https://designs.ai/*, https://*.designs.ai/*, https://determined.ai/*, https://*.determined.ai/*, https://devin.ai/*, https://*.devin.ai/*, https://devv.ai/*, https://*.devv.ai/*, https://diagram.com/*, https://*.diagram.com/*, https://dify.ai/*, https://*.dify.ai/*, https://discord.com/*, https://*.discord.com/*, https://docgpt.ai/*, https://*.docgpt.ai/*, https://docs.google.com/*, https://*.docs.google.com/*, https://doubao.com/*, https://*.doubao.com/*, https://dreamstudio.ai/*, https://*.dreamstudio.ai/*, https://drift.com/*, https://*.drift.com/*, https://dropbox.com/*, https://*.dropbox.com/*, https://dust.tt/*, https://*.dust.tt/*, https://e2b.dev/*, https://*.e2b.dev/*, https://eesel.ai/*, https://*.eesel.ai/*, https://eightfold.ai/*, https://*.eightfold.ai/*, https://einstein.salesforce.com/*, https://*.einstein.salesforce.com/*, https://elevenlabs.io/*, https://*.elevenlabs.io/*, https://elicit.com/*, https://*.elicit.com/*, https://endpoints.anyscale.com/*, https://*.endpoints.anyscale.com/*, https://engage-ai.co/*, https://*.engage-ai.co/*, https://eu-de.ml.cloud.ibm.com/*, https://*.eu-de.ml.cloud.ibm.com/*, https://evidently.ai/*, https://*.evidently.ai/*, https://evisort.com/*, https://*.evisort.com/*, https://exa.ai/*, https://*.exa.ai/*, https://exabeam.com/*, https://*.exabeam.com/*, https://factory.ai/*, https://*.factory.ai/*, https://fal.ai/*, https://*.fal.ai/*, https://fathom.video/*, https://*.fathom.video/*, https://fellow.app/*, https://*.fellow.app/*, https://fetcher.ai/*, https://*.fetcher.ai/*, https://figma.com/*, https://*.figma.com/*, https://findem.ai/*, https://*.findem.ai/*, https://fireflies.ai/*, https://*.fireflies.ai/*, https://firefly.adobe.com/*, https://*.firefly.adobe.com/*, https://fireworks.ai/*, https://*.fireworks.ai/*, https://fixie.ai/*, https://*.fixie.ai/*, https://flatiron.com/*, https://*.flatiron.com/*, https://fliki.ai/*, https://*.fliki.ai/*, https://flowiseai.com/*, https://*.flowiseai.com/*, https://flux.ai/*, https://*.flux.ai/*, https://forethought.ai/*, https://*.forethought.ai/*, https://framer.com/*, https://*.framer.com/*, https://freshdesk.com/*, https://*.freshdesk.com/*, https://freshworks.com/*, https://*.freshworks.com/*, https://front.com/*, https://*.front.com/*, https://galileo.ai/*, https://*.galileo.ai/*, https://gamma.app/*, https://*.gamma.app/*, https://gemini.google.com/*, https://*.gemini.google.com/*, https://generativelanguage.googleapis.com/*, https://*.generativelanguage.googleapis.com/*, https://genmo.ai/*, https://*.genmo.ai/*, https://gethugohq.com/*, https://*.gethugohq.com/*, https://getimg.ai/*, https://*.getimg.ai/*, https://getmerlin.in/*, https://*.getmerlin.in/*, https://github.com/*, https://*.github.com/*, https://gitlab.com/*, https://*.gitlab.com/*, https://gitpod.io/*, https://*.gitpod.io/*, https://glasp.co/*, https://*.glasp.co/*, https://globe.engineer/*, https://*.globe.engineer/*, https://gong.io/*, https://*.gong.io/*, https://gorgias.com/*, https://*.gorgias.com/*, https://grain.com/*, https://*.grain.com/*, https://grammarly.com/*, https://*.grammarly.com/*, https://greenhouse.io/*, https://*.greenhouse.io/*, https://grok.com/*, https://*.grok.com/*, https://grok.x.ai/*, https://*.grok.x.ai/*, https://groq.com/*, https://*.groq.com/*, https://gumloop.com/*, https://*.gumloop.com/*, https://h2o.ai/*, https://*.h2o.ai/*, https://hailuoai.com/*, https://*.hailuoai.com/*, https://harpa.ai/*, https://*.harpa.ai/*, https://harvey.ai/*, https://*.harvey.ai/*, https://helicone.ai/*, https://*.helicone.ai/*, https://hex.tech/*, https://*.hex.tech/*, https://heygen.com/*, https://*.heygen.com/*, https://hireez.com/*, https://*.hireez.com/*, https://hirevue.com/*, https://*.hirevue.com/*, https://hix.ai/*, https://*.hix.ai/*, https://hixai.com/*, https://*.hixai.com/*, https://hubspot.com/*, https://*.hubspot.com/*, https://huggingchat.co/*, https://*.huggingchat.co/*, https://huggingface.co/*, https://*.huggingface.co/*, https://humanloop.com/*, https://*.humanloop.com/*, https://humata.ai/*, https://*.humata.ai/*, https://hunyuan.tencent.com/*, https://*.hunyuan.tencent.com/*, https://hyper.ai/*, https://*.hyper.ai/*, https://hyperclova.ai/*, https://*.hyperclova.ai/*, https://hyperwriteai.com/*, https://*.hyperwriteai.com/*, https://ibm.com/*, https://*.ibm.com/*, https://ideogram.ai/*, https://*.ideogram.ai/*, https://imagen3.withgoogle.com/*, https://*.imagen3.withgoogle.com/*, https://inception.ae/*, https://*.inception.ae/*, https://inference.cerebras.ai/*, https://*.inference.cerebras.ai/*, https://insilico.com/*, https://*.insilico.com/*, https://integrate.api.nvidia.com/*, https://*.integrate.api.nvidia.com/*, https://intercom.com/*, https://*.intercom.com/*, https://invideo.io/*, https://*.invideo.io/*, https://ironcladapp.com/*, https://*.ironcladapp.com/*, https://jamie.ai/*, https://*.jamie.ai/*, https://jasper.ai/*, https://*.jasper.ai/*, https://jiaismodel.cloud/*, https://*.jiaismodel.cloud/*, https://jira.atlassian.com/*, https://*.jira.atlassian.com/*, https://julius.ai/*, https://*.julius.ai/*, https://kagi.com/*, https://*.kagi.com/*, https://kakao.com/*, https://*.kakao.com/*, https://kensho.com/*, https://*.kensho.com/*, https://kimi.ai/*, https://*.kimi.ai/*, https://kimi.moonshot.cn/*, https://*.kimi.moonshot.cn/*, https://kira-systems.com/*, https://*.kira-systems.com/*, https://klingai.com/*, https://*.klingai.com/*, https://krea.ai/*, https://*.krea.ai/*, https://krisp.ai/*, https://*.krisp.ai/*, https://krutrim.com/*, https://*.krutrim.com/*, https://kustomer.com/*, https://*.kustomer.com/*, https://labs.perplexity.ai/*, https://*.labs.perplexity.ai/*, https://lacework.com/*, https://*.lacework.com/*, https://lambdalabs.com/*, https://*.lambdalabs.com/*, https://lamini.ai/*, https://*.lamini.ai/*, https://langchain.com/*, https://*.langchain.com/*, https://langflow.org/*, https://*.langflow.org/*, https://langfuse.com/*, https://*.langfuse.com/*, https://laxis.com/*, https://*.laxis.com/*, https://leena.ai/*, https://*.leena.ai/*, https://legal.thomsonreuters.com/*, https://*.legal.thomsonreuters.com/*, https://legitsecurity.com/*, https://*.legitsecurity.com/*, https://leonardo.ai/*, https://*.leonardo.ai/*, https://lepton.ai/*, https://*.lepton.ai/*, https://lever.co/*, https://*.lever.co/*, https://lex.page/*, https://*.lex.page/*, https://lexion.ai/*, https://*.lexion.ai/*, https://lexisnexis.com/*, https://*.lexisnexis.com/*, https://leya.law/*, https://*.leya.law/*, https://lindy.ai/*, https://*.lindy.ai/*, https://linear.app/*, https://*.linear.app/*, https://linkai.com/*, https://*.linkai.com/*, https://litera.com/*, https://*.litera.com/*, https://llama-api.com/*, https://*.llama-api.com/*, https://llama.meta.com/*, https://*.llama.meta.com/*, https://lmarena.ai/*, https://*.lmarena.ai/*, https://longshot.ai/*, https://*.longshot.ai/*, https://looka.com/*, https://*.looka.com/*, https://lovable.dev/*, https://*.lovable.dev/*, https://lovo.ai/*, https://*.lovo.ai/*, https://lucid.app/*, https://*.lucid.app/*, https://luma.ai/*, https://*.luma.ai/*, https://lumalabs.ai/*, https://*.lumalabs.ai/*, https://luminance.com/*, https://*.luminance.com/*, https://mage.space/*, https://*.mage.space/*, https://magician.design/*, https://*.magician.design/*, https://magicslides.app/*, https://*.magicslides.app/*, https://make.com/*, https://*.make.com/*, https://manatal.com/*, https://*.manatal.com/*, https://manus.im/*, https://*.manus.im/*, https://maxai.me/*, https://*.maxai.me/*, https://meetgeek.ai/*, https://*.meetgeek.ai/*, https://mem.ai/*, https://*.mem.ai/*, https://mendel.ai/*, https://*.mendel.ai/*, https://merlin.foyer.work/*, https://*.merlin.foyer.work/*, https://meta.ai/*, https://*.meta.ai/*, https://microsoft365.com/*, https://*.microsoft365.com/*, https://midjourney.com/*, https://*.midjourney.com/*, https://mindsdb.com/*, https://*.mindsdb.com/*, https://minimax.chat/*, https://*.minimax.chat/*, https://miro.com/*, https://*.miro.com/*, https://missiveapp.com/*, https://*.missiveapp.com/*, https://mistral.ai/*, https://*.mistral.ai/*, https://ml.azure.com/*, https://*.ml.azure.com/*, https://mlflow.org/*, https://*.mlflow.org/*, https://modal.com/*, https://*.modal.com/*, https://monday.com/*, https://*.monday.com/*, https://monica.im/*, https://*.monica.im/*, https://morph.studio/*, https://*.morph.studio/*, https://mosaicml.com/*, https://*.mosaicml.com/*, https://motion.so/*, https://*.motion.so/*, https://mubert.com/*, https://*.mubert.com/*, https://murf.ai/*, https://*.murf.ai/*, https://mypptai.com/*, https://*.mypptai.com/*, https://n8n.cloud/*, https://*.n8n.cloud/*, https://n8n.io/*, https://*.n8n.io/*, https://nabla.com/*, https://*.nabla.com/*, https://nanobeep.com/*, https://*.nanobeep.com/*, https://narrativebi.com/*, https://*.narrativebi.com/*, https://nat.dev/*, https://*.nat.dev/*, https://nightcafe.studio/*, https://*.nightcafe.studio/*, https://notes.microsoft.com/*, https://*.notes.microsoft.com/*, https://notion.com/*, https://*.notion.com/*, https://notion.so/*, https://*.notion.so/*, https://noty.ai/*, https://*.noty.ai/*, https://novita.ai/*, https://*.novita.ai/*, https://ntropy.com/*, https://*.ntropy.com/*, https://nuance.com/*, https://*.nuance.com/*, https://numerai.com/*, https://*.numerai.com/*, https://nvidia.com/*, https://*.nvidia.com/*, https://oai.azure.com/*, https://*.oai.azure.com/*, https://obviously.ai/*, https://*.obviously.ai/*, https://ocrolus.com/*, https://*.ocrolus.com/*, https://octo.ai/*, https://*.octo.ai/*, https://onit.com/*, https://*.onit.com/*, https://openai-hk.com/*, https://*.openai-hk.com/*, https://openai.com/*, https://*.openai.com/*, https://openpipe.ai/*, https://*.openpipe.ai/*, https://openrouter.ai/*, https://*.openrouter.ai/*, https://ora.ai/*, https://*.ora.ai/*, https://oracle.com/*, https://*.oracle.com/*, https://orca.security/*, https://*.orca.security/*, https://orq.ai/*, https://*.orq.ai/*, https://otter.ai/*, https://*.otter.ai/*, https://outreach.io/*, https://*.outreach.io/*, https://paige.ai/*, https://*.paige.ai/*, https://paradox.ai/*, https://*.paradox.ai/*, https://patentpal.com/*, https://*.patentpal.com/*, https://pdfgpt.io/*, https://*.pdfgpt.io/*, https://perplexity.ai/*, https://*.perplexity.ai/*, https://phenom.com/*, https://*.phenom.com/*, https://phind.com/*, https://*.phind.com/*, https://phoenix.arize.com/*, https://*.phoenix.arize.com/*, https://pi.ai/*, https://*.pi.ai/*, https://pictory.ai/*, https://*.pictory.ai/*, https://pika.art/*, https://*.pika.art/*, https://pipedrive.com/*, https://*.pipedrive.com/*, https://pitch.com/*, https://*.pitch.com/*, https://pixai.art/*, https://*.pixai.art/*, https://pixlr.com/*, https://*.pixlr.com/*, https://pixverse.ai/*, https://*.pixverse.ai/*, https://platform.moonshot.cn/*, https://*.platform.moonshot.cn/*, https://platform.openai.com/*, https://*.platform.openai.com/*, https://play.ht/*, https://*.play.ht/*, https://playground.ai/*, https://*.playground.ai/*, https://playgroundai.com/*, https://*.playgroundai.com/*, https://plusdocs.com/*, https://*.plusdocs.com/*, https://poe.com/*, https://*.poe.com/*, https://polyai.com/*, https://*.polyai.com/*, https://popai.pro/*, https://*.popai.pro/*, https://portal.azure.com/*, https://*.portal.azure.com/*, https://portkey.ai/*, https://*.portkey.ai/*, https://predibase.com/*, https://*.predibase.com/*, https://presentations.ai/*, https://*.presentations.ai/*, https://prezi.com/*, https://*.prezi.com/*, https://prodia.com/*, https://*.prodia.com/*, https://promptfoo.dev/*, https://*.promptfoo.dev/*, https://promptlayer.com/*, https://*.promptlayer.com/*, https://qianwen.aliyun.com/*, https://*.qianwen.aliyun.com/*, https://quillbot.com/*, https://*.quillbot.com/*, https://quora.com/*, https://*.quora.com/*, https://ramp.com/*, https://*.ramp.com/*, https://read.ai/*, https://*.read.ai/*, https://reclaim.ai/*, https://*.reclaim.ai/*, https://recordedfuture.com/*, https://*.recordedfuture.com/*, https://recraft.ai/*, https://*.recraft.ai/*, https://regard.com/*, https://*.regard.com/*, https://reka.ai/*, https://*.reka.ai/*, https://relevanceai.com/*, https://*.relevanceai.com/*, https://remove.bg/*, https://*.remove.bg/*, https://replica.ai/*, https://*.replica.ai/*, https://replicate.com/*, https://*.replicate.com/*, https://replit.com/*, https://*.replit.com/*, https://resemble.ai/*, https://*.resemble.ai/*, https://respell.ai/*, https://*.respell.ai/*, https://rev.ai/*, https://*.rev.ai/*, https://rewatch.com/*, https://*.rewatch.com/*, https://rippling.com/*, https://*.rippling.com/*, https://robin.ai/*, https://*.robin.ai/*, https://rows.com/*, https://*.rows.com/*, https://runpod.io/*, https://*.runpod.io/*, https://runwayml.com/*, https://*.runwayml.com/*, https://rxlogix.com/*, https://*.rxlogix.com/*, https://rytr.me/*, https://*.rytr.me/*, https://saga.so/*, https://*.saga.so/*, https://salesforce.com/*, https://*.salesforce.com/*, https://salesloft.com/*, https://*.salesloft.com/*, https://sambanova.ai/*, https://*.sambanova.ai/*, https://sap.com/*, https://*.sap.com/*, https://sarvam.ai/*, https://*.sarvam.ai/*, https://scale.com/*, https://*.scale.com/*, https://scholarai.io/*, https://*.scholarai.io/*, https://scite.ai/*, https://*.scite.ai/*, https://sdk.vercel.ai/*, https://*.sdk.vercel.ai/*, https://seaart.ai/*, https://*.seaart.ai/*, https://search.brave.com/*, https://*.search.brave.com/*, https://secureworks.com/*, https://*.secureworks.com/*, https://seekout.com/*, https://*.seekout.com/*, https://semanticscholar.org/*, https://*.semanticscholar.org/*, https://sembly.ai/*, https://*.sembly.ai/*, https://sensechat.sensetime.com/*, https://*.sensechat.sensetime.com/*, https://sentinelone.com/*, https://*.sentinelone.com/*, https://servicenow.com/*, https://*.servicenow.com/*, https://servicetitan.com/*, https://*.servicetitan.com/*, https://sheetai.app/*, https://*.sheetai.app/*, https://shortwave.com/*, https://*.shortwave.com/*, https://sider.ai/*, https://*.sider.ai/*, https://slack.com/*, https://*.slack.com/*, https://slidesai.io/*, https://*.slidesai.io/*, https://slidesgo.com/*, https://*.slidesgo.com/*, https://smith.langchain.com/*, https://*.smith.langchain.com/*, https://snowflake.com/*, https://*.snowflake.com/*, https://socure.com/*, https://*.socure.com/*, https://sora.com/*, https://*.sora.com/*, https://soundraw.io/*, https://*.soundraw.io/*, https://sourcegraph.com/*, https://*.sourcegraph.com/*, https://speechify.com/*, https://*.speechify.com/*, https://spellbook.legal.ai/*, https://*.spellbook.legal.ai/*, https://stability.ai/*, https://*.stability.ai/*, https://stablecog.com/*, https://*.stablecog.com/*, https://stablediffusionweb.com/*, https://*.stablediffusionweb.com/*, https://stack-ai.com/*, https://*.stack-ai.com/*, https://stackblitz.com/*, https://*.stackblitz.com/*, https://stampli.com/*, https://*.stampli.com/*, https://steamship.com/*, https://*.steamship.com/*, https://stepfun.com/*, https://*.stepfun.com/*, https://steve.ai/*, https://*.steve.ai/*, https://stockimg.ai/*, https://*.stockimg.ai/*, https://storyd.ai/*, https://*.storyd.ai/*, https://sudowrite.com/*, https://*.sudowrite.com/*, https://suki.ai/*, https://*.suki.ai/*, https://suno.ai/*, https://*.suno.ai/*, https://suno.com/*, https://*.suno.com/*, https://superagi.com/*, https://*.superagi.com/*, https://superhuman.com/*, https://*.superhuman.com/*, https://supermaven.com/*, https://*.supermaven.com/*, https://supernormal.com/*, https://*.supernormal.com/*, https://superpower.chat/*, https://*.superpower.chat/*, https://sweep.dev/*, https://*.sweep.dev/*, https://synthesia.io/*, https://*.synthesia.io/*, https://t3nsor.com/*, https://*.t3nsor.com/*, https://tabnine.com/*, https://*.tabnine.com/*, https://tactiq.io/*, https://*.tactiq.io/*, https://talkie-ai.com/*, https://*.talkie-ai.com/*, https://taskade.com/*, https://*.taskade.com/*, https://teams.microsoft.com/*, https://*.teams.microsoft.com/*, https://tempus.com/*, https://*.tempus.com/*, https://tensor.art/*, https://*.tensor.art/*, https://tiangong.cn/*, https://*.tiangong.cn/*, https://tldv.io/*, https://*.tldv.io/*, https://together.ai/*, https://*.together.ai/*, https://tome.app/*, https://*.tome.app/*, https://tongyi.aliyun.com/*, https://*.tongyi.aliyun.com/*, https://traceloop.com/*, https://*.traceloop.com/*, https://truefoundry.com/*, https://*.truefoundry.com/*, https://trullion.com/*, https://*.trullion.com/*, https://typingmind.com/*, https://*.typingmind.com/*, https://udio.com/*, https://*.udio.com/*, https://uizard.io/*, https://*.uizard.io/*, https://us-central1-aiplatform.googleapis.com/*, https://*.us-central1-aiplatform.googleapis.com/*, https://us-east-1.console.aws.amazon.com/*, https://*.us-east-1.console.aws.amazon.com/*, https://uxpilot.ai/*, https://*.uxpilot.ai/*, https://v0.dev/*, https://*.v0.dev/*, https://vast.ai/*, https://*.vast.ai/*, https://vectra.ai/*, https://*.vectra.ai/*, https://veed.io/*, https://*.veed.io/*, https://vellum.ai/*, https://*.vellum.ai/*, https://venice.ai/*, https://*.venice.ai/*, https://veracyte.com/*, https://*.veracyte.com/*, https://vertexai.google.com/*, https://*.vertexai.google.com/*, https://vic.ai/*, https://*.vic.ai/*, https://viggle.ai/*, https://*.viggle.ai/*, https://visily.ai/*, https://*.visily.ai/*, https://visme.co/*, https://*.visme.co/*, https://vmaker.com/*, https://*.vmaker.com/*, https://voiceflow.com/*, https://*.voiceflow.com/*, https://wandb.ai/*, https://*.wandb.ai/*, https://webex.com/*, https://*.webex.com/*, https://webpilot.ai/*, https://*.webpilot.ai/*, https://wellsaidlabs.com/*, https://*.wellsaidlabs.com/*, https://wenxin.baidu.com/*, https://*.wenxin.baidu.com/*, https://whylabs.ai/*, https://*.whylabs.ai/*, https://windsurf.com/*, https://*.windsurf.com/*, https://wiseone.app/*, https://*.wiseone.app/*, https://wistia.com/*, https://*.wistia.com/*, https://wiz.io/*, https://*.wiz.io/*, https://wordtune.com/*, https://*.wordtune.com/*, https://workday.com/*, https://*.workday.com/*, https://writer.com/*, https://*.writer.com/*, https://writesonic.com/*, https://*.writesonic.com/*, https://wrtn.io/*, https://*.wrtn.io/*, https://www.perplexity.ai/*, https://*.www.perplexity.ai/*, https://x.ai/*, https://*.x.ai/*, https://xinghuo.xfyun.cn/*, https://*.xinghuo.xfyun.cn/*, https://yiyan.baidu.com/*, https://*.yiyan.baidu.com/*, https://you.com/*, https://*.you.com/*, https://zapier.com/*, https://*.zapier.com/*, https://zendesk.com/*, https://*.zendesk.com/*, https://zhipu.ai/*, https://*.zhipu.ai/*, https://zoom.com/*, https://*.zoom.com/*, https://zoom.us/*, https://*.zoom.us/*
Screenshots
About
ThreatVec Shadow AI gives security teams visibility into the 554+ AI tools their employees use in the browser, and blocks accidental data leaks before they leave the page. WHAT IT DOES • Auto-discovers AI services visited in the browser across 554 named products in 24 categories — including the ChatGPT, Claude, Gemini, Perplexity, Copilot, Mistral, and DeepSeek web apps, AWS Bedrock, Azure OpenAI, plus coding assistants (Cursor, Codeium, Tabnine, Aider, v0), image generators (Midjourney, Firefly, Leonardo, Ideogram), agent frameworks (AutoGPT, Lindy, n8n), meeting AI (Otter, Fireflies, tl;dv), healthcare AI, legal AI, finance AI, and customer-service AI tools — and feeds an inventory back to your ThreatVec dashboard. • Scans content typed into AI prompt fields for PII (email, SSN, credit-card, API keys, AWS keys, Anthropic/OpenAI keys, JWT tokens, internal hostnames, phone numbers, passwords). Detected leaks are blocked or masked client-side BEFORE the prompt is sent to the AI service, and a redacted record is logged to your ThreatVec audit trail. • Enforces org policy: your security team can mark each AI service as sanctioned, restricted, or blocked, and choose per-PII-class actions (block / mask / warn / allow). The extension applies the policy at the browser, even on unmanaged personal AI accounts. • Surfaces a per-user activity summary in the popup so end users understand which AI tools they've touched, what was blocked, and why. WHAT IT DOES NOT DO • It does NOT inject into or modify the behavior of any specific AI service (no ChatGPT-integration, no Copilot-augmentation — it observes browser traffic and acts only on outbound prompts the user is about to send). • It does NOT send the content of prompts to ThreatVec servers. Only metadata (service name, time, PII-class fingerprint, action taken) is reported. PERMISSIONS RATIONALE • storage: persist per-user policy + activity log locally. • tabs: detect which AI service is open in the active tab. • alarms: periodic local sync of policy from the ThreatVec dashboard. • host permissions (1,136 explicit URL patterns for 568 hostnames across 554 named AI services): every pattern is anchored to a documented AI tool in our public service registry at https://app.threatvec.com/ai-services-catalogue. Content scripts inject ONLY on these explicit hosts. The extension does NOT inject into or watch any non-AI sites the user visits. • optional_host_permissions (https://*/*): NOT requested at install time. An admin can grant this at runtime ONLY for org-defined custom AI services (e.g. an internal in-house LLM at internal-chat.acme.com). Chrome prompts the user explicitly before any per-domain grant is added. PRIVACY • No prompt content leaves the browser. • No PII leaves the browser (it is detected client-side and stripped before submission). • Per-org pseudonymization with HMAC: even the "we saw a PII attempt" telemetry doesn't carry the raw user identifier. • See https://threatvec.com/privacy for the full policy. REQUIREMENTS A ThreatVec account is required to receive policy + see telemetry in the dashboard. The extension works in passive-observe mode without an account but cannot enforce policy or report to a SOC. Sign up free at https://app.threatvec.com (180-day free trial).
Technical
- Version
- 1.2.1
- Manifest
- V3
- Size
- 69.19KiB
- Min Chrome
- 88
- Languages
- 1
- Featured
- No
Metadata
- ID
- akmohmegmejcgplmfodboibobhalljpj
- Developer ID
- u497fd091d83a29fdae1c90bef76961ba
- Developer Email
- [email protected]
- Created
- May 23, 2026
- Last Updated (Store)
- May 23, 2026
- Last Scraped
- Jun 14, 2026
- Website
- —
- Support URL
- —
- Privacy Policy
- https://threatvec.com/privacy
Data sourced from the Chrome Web Store · last verified Jun 14, 2026.