For partners, directors and compliance leads
Saying no has not kept AI out of the office. Nonimo lets your people keep using ChatGPT, Claude, Copilot or Gemini, with rules you set for each type of client data, applied before anything is sent. You can start with a single department.
The desktop app is available on both platforms, Mac and Windows; the browser extension and the compliance panel are in development. Each person can install the desktop app on their own computer and mask with one key. Across a department, IT deploys the browser extension by policy: it covers text without being asked and, where you decide, blocks. The security page sets out what leaves each computer.
Why saying no is not enough
In October 2025, Censuswide surveyed 2,003 employees in the UK for Microsoft. 71% said they had used unapproved consumer AI tools at work (Microsoft UK, October 2025).
When the official answer is no, the work does not stop. It goes to personal accounts, where nobody has set a rule and nobody can see what went in. The alternative is to let people use AI, with the rules in place before a client’s details are sent.
Start small
Your IT team, or your IT provider, installs the browser extension by policy on the department’s browsers, Chrome and Edge. No drivers, no traffic interception.
Anyone who wants to mask with one key can add the desktop app, for Mac and Windows.
Begin with a pilot in observe mode for two to four weeks. It measures what would have left, by category, without changing anyone’s work. Then, with real numbers, you choose per category of data: observe, warn, mask in the open, clean silently or block.
The compliance panel runs on your own server and gives you a monthly report for the organisation. Metrics, not data: how many, in which category, under which policy version. Never the text, and never who did what, so it cannot become a way of monitoring staff.
The page you show an auditor, your DPO or the board.
Once the department runs smoothly, extend it to the rest of the organisation with the same policy.
Day to day
Very little. They keep using ChatGPT, Claude, Copilot or Gemini as they already do. The extension covers client details without being asked and, where you have decided so, blocks what must never leave: a card number, a password or key, a client file. Anything masked is visible to them and can be undone with one click.
What gets covered and why, sector by sector.
Metrics for the organisation as a whole: how many items were caught, in which category of data, under which version of your policy. Never the text, and never who did what. The compliance panel that produces it runs on your own server.
They cannot. An extension installed by policy cannot be removed or disabled by the user: that is how forced installation works in Chrome and Edge. The desktop app is there for each person to use when they want to; what applies to the whole department is the extension and its policy.
Yes. Your own IT team or your IT provider deploys the extension by policy, like any other managed extension. If you do not have one, ask us and we will introduce one.
No. They keep using ChatGPT, Claude, Copilot or Gemini as they already do. Anything masked is visible to them and can be undone with one click.
Nowhere new. Only the masked version reaches the AI, your clients’ details stay on the computer, and not one word of the text reaches us. The compliance panel receives counts per category, never the text, and it runs on your own server.
Yes, per category of data, in the extension’s policy: observe, warn, mask in the open, clean silently or block. IT applies it centrally, ideally once a pilot in observe mode has shown you the real numbers.