Help

How it works, what to press, and what to do when it does something you did not expect.

Getting started

Install it from the Chrome Web Store at the SourceSecure listing. A link cannot install an extension on its own, since Chrome removed that in 2018, so you will land on the listing page and press Add to Chrome yourself.

Then click the SourceSecure icon in your Chrome toolbar and choose Sign in. Use the email address your firm added, either through Google or through a link we email you. There is no password to remember or to lose.

If you had a chat site open before you installed it, or before an update, that tab needs a reload before it is protected. The popup says Refresh this tab when that is the case, so you are never left guessing.

Which sites it works on

ChatGPT, at chatgpt.com and chat.openai.com. Claude, at claude.ai. Microsoft Copilot, at copilot.com, www.copilot.com, copilot.microsoft.com, copilot.cloud.microsoft and m365.cloud.microsoft. Google Gemini, at gemini.google.com. Perplexity, at perplexity.ai and www.perplexity.ai. Grok, at grok.com. DeepSeek, at chat.deepseek.com. Meta AI, at meta.ai and www.meta.ai. Mistral, at chat.mistral.ai, which the app itself calls Vibe. NotebookLM, at notebook.google.com and notebooklm.google.com, which the app itself now calls Gemini Notebook.

Nowhere else. The extension has no permission to read any other page, which is deliberate: it is the difference between a tool that watches a short list of chat sites and one that watches you. If you are on a supported site and nothing seems to be happening, open the popup, which says whether it can see the page.

What happens when you press send

SourceSecure reads what you are about to send and looks for things that should not leave the firm: client names, account numbers, SINs and SSNs, card numbers, addresses, postal codes, phone numbers, email addresses, company names and places, plus any terms your firm has added.

If it finds nothing, your message goes as you typed it and you never see SourceSecure at all. That is the usual case.

If it finds something, the send pauses and a card opens listing what it found, with a redacted version beside what you typed. There are two buttons. Send redacted version sends the cleaned copy. Send as typed sends exactly what you wrote. It never blocks you, and it never sends anything until you press one of them.

The pause is a fraction of a second. If the check has not finished in about a second, your message goes anyway rather than leaving you waiting.

It flagged something that is not sensitive

This happens, and it is the honest cost of catching names at all. A name is recognised by judgment rather than by a rule, and judgment goes wrong in both directions.

Each item in the card has its own buttons. Not this time leaves it out of the redaction for this message only. Never means stop flagging this exact value on this computer from now on. Always does the opposite and adds it to your watched terms so it is caught every time.

Everything you have silenced is counted in the settings (More settings in the popup, then Your data) under Items you marked not sensitive, with a Forget all button if you change your mind. That list lives on your computer, and your admin cannot see it.

It missed something

It will. SourceSecure is a safety net, not a guarantee, and the terms say so in those words. Account numbers and SINs are matched by shape, so an unusual format can slip past. Names and companies are recognised by a model, and a model is sometimes wrong.

Please tell us when it happens. Email support@sourcesecure.ca with the shape of what was missed rather than the real value. Every miss we hear about is a pattern we can add.

Attachments

Attach a file to a message on a supported site and SourceSecure reads it before it goes: PDFs, Word documents, spreadsheets, PowerPoint decks, plain text, and scanned images.

You see what it found page by page, with black boxes over it. Drag across anything else you want covered, or click a box to undo it. When you send, a redacted copy is attached in place of the original. The file on your own disk is never changed.

It also cleans what you cannot see. Author names, tracked changes that were deleted but never accepted, comment authors and document properties all travel inside an Office file, and they are removed from the copy it attaches.

What your firm can see

Not your messages. No message text and no document ever reaches us, so there is nothing for an admin to read even if they wanted to.

Once a day your browser sends a small report of counts: how many items were caught, of which kinds, and how often a redacted version was sent. Numbers only, stored against the firm rather than against you. There is no field in that report through which a sentence could travel.

On the team page an admin sees firm totals. The only things shown for one person are which kind of seat they have, whether their extension is connected, and when it last checked in.

Prompting tips, on Guard Pro and Guard 360 seats

Guard Pro and Guard 360 seats can suggest how to ask a better question. That needs a model we run rather than the one on your machine, so a redacted copy of the conversation is sent, with every client detail already replaced by stand-ins such as [PERSON_1]. Nothing from it is stored.

It is the one thing that leaves your computer, so it is the one thing you can switch off. Open the popup and turn off Prompting tips. With it off, nothing you type leaves your computer for any reason, and the rest of SourceSecure carries on exactly as before.

Tips are rare on purpose. The conversation is looked at every five messages, and most of the time there is nothing worth saying. The popup tells you when it last checked and what came of it, so that working and broken do not look the same from the outside.

Reply marks, on Guard 360 seats

A Guard 360 seat checks each AI reply once it finishes and faintly underlines the places worth a second look: a decision made for you, an assumption, something stated too surely, or something that contradicts what your firm has told it. Point at an underline to see why. Ask about this puts a follow-up question in the message box for you to edit; nothing is ever sent for you. A reply with nothing worth saying gets nothing.

To check a reply, your message and the reply are sent the same way as tips, redacted first. When your message says something about your work or firm, a few short facts are kept in your vault, in this browser only, so later replies can be checked against them. Switch on Remember personal details too in the popup and it keeps lasting things about your own life as well, like an allergy; those are never offered to your firm, and are sent with reply checks only while the switch is on. When something changes, such as a move to a new tool, the newer fact replaces the old one and the old wording is kept beneath it; a fact you saved yourself is only replaced once the change comes up again, or when you choose Use this instead. Open the popup and choose See what your vault knows to see, change or delete any of them. Select text on a chat page to save it to your vault yourself.

A fact about your firm can be suggested for the firm's profile, which your admin keeps and every Guard 360 seat is checked against. Your admin sees what was suggested and by how many people, never by whom.

Your firm's Guard 360 seats share a number of checked replies each month. Past it, only the most important marks are shown until the 1st, the popup says so, and Check this reply fully beside the marks checks one reply for everything, up to 20 a day.

Turn off Mark AI replies in the popup to stop reply marks. Turning off prompting tips stops them too.

If your firm chose the two-week trial when it bought, your seat works as Guard 360 for two weeks from when you connect, and the popup counts the days. When it ends, SourceSecure says what it did for you and lets you ask your admin to keep it; your admin sees your name if you do. Your vault is paused, not deleted.

For admins

Your team page is at sourcesecure.ca/admin, signed in with the address that bought. It has up to six tabs. Activity shows whether the firm is actually using it. People is where you add and remove members, choose which kind of seat each person has, and move somebody to another kind; adding somebody emails them straight away. Habits shows which habits the team is building. Report, with Guard 360 seats, is a monthly page on how the firm worked with AI, against the month before, ready to print. Settings is where you add terms everyone must always redact, such as the firm's own name or a client company, where you can require that the high risk kinds stay switched on for everybody, and, with Guard 360 seats, where you keep the firm's profile and approve what people suggest for it. Billing is how many seats of each kind, this month's reply marks, invoices and cancelling.

A change in seats is charged or credited for what is left of the month, on your next invoice. Seats of a kind can only go down to the number of people who have that kind, so nobody is thrown off because a number changed.

If people ask to keep Guard 360 after their two weeks, you see who at the top of the team page, and SourceSecure tells you next time you use AI. Give them Guard 360 opens Billing with the seats added; once you have changed seats, move them on the People tab.

A term you add on the Settings tab reaches every browser in the firm with the next daily check, which means within a day rather than instantly. Removing one travels the same way.

Something is wrong

Nothing happens when I send. Open the popup. It will tell you if you are not signed in, if the subscription has lapsed, if the tab needs a reload, or if you are not on a supported site.

It says the subscription is not active. A failed card payment stops protection for the whole team until the card is updated on the Billing tab. Nothing is deleted while that is sorted out.

I cannot sign in. One person belongs to one team. If you already belong to another firm's team, signing in will say so by name. Otherwise check that the address your admin added is the one you are signing in with.

It is slow, or the model will not load. The settings (More settings in the popup, then Protection) have a Name detection line saying whether the model is ready. If it says name detection is unavailable, the pattern checks are still running, so account numbers and SINs are still being caught while names are not.

Anything else, write to support@sourcesecure.ca. Please say which site, which browser, and what you expected to happen. Do not paste a real client detail into the email; the shape of it is enough.

Getting in touch

Email support@sourcesecure.ca. SourceSecure is operated by JOLIVE Labs Inc.