Scope
Agent Guard supervises browser-visible activity performed by AI agents on websites a user explicitly authorizes. It identifies supported high-risk actions and sensitive-data categories, compares actions with user-confirmed intent and deterministic policy, requests approval or blocks supported actions, and keeps a redacted local audit trail.
Agent Guard is not a general chatbot, password manager, tracker blocker, endpoint DLP system, or guarantee against every prompt-injection attack.
Information processed
On authorized sites, Agent Guard may transiently process browser-visible field values or metadata to classify personally identifiable information, health information, financial or payment information, authentication information, precise-location fields, and other sensitive categories.
It may inspect bounded page text on authorized webmail, messaging, collaboration, or other pages for prompt-injection signals. It may also process authorized site origin, redacted URL, timestamps, browser-visible clicks, input attempts, submissions, sends, uploads, downloads, navigation, approvals, settings, field labels, target descriptions, links, and destination origins.
Agent Guard does not intentionally perform keystroke logging or retain typed text as a transcript.
Data minimization
Raw form values and bounded page text are inspected transiently in the page and are not intentionally stored in the audit model. Persistent records use sensitive-data category indicators, redacted labels, redacted URLs, origin names, amount buckets, action metadata, policy decisions, and other minimized context.
A page-local masked preview can be shown during approval but is not sent to the extension service worker or included in exports. Agent Guard does not intentionally read or retain file contents, Cookie values, browser-storage values, full request bodies, or private keys.
Agent Guard stores categories and decisions—not a copy of the user's conversation or form contents.
How information is used
Information is used only to show Guard Health and session status; evaluate intent contracts, risk budgets, profiles, and local policy; pause, approve, block, or replay supported actions; build local data-lineage and prompt-risk associations; compare local sessions; generate user-requested exports; link optional cross-tab workflows; and install optional temporary network-quarantine rules.
Policy decisions are deterministic in the current release. Agent Guard does not send prompts or page content to a developer-operated AI service.
Task templates and synthetic tests
Three templates apply to the current origin only after explicit confirmation in the extension UI and expire after one hour. Applying one replaces task intent, resets budgets and clears temporary grants. Pending or in-flight actions and changed page identity prevent unsafe replacement.
Managed policy remains authoritative and existing custom rules still apply. Synthetic tests run the policy engine with synthetic inputs, without live network sends or real action replay. Results are not proof of full browser enforcement.
Task lifecycle and authorization records
Task expiry and End task & lock let the user clear task authorizations and activate Panic Lock after confirmation. Already-dispatched actions cannot be recalled.
Minimized authorization and budget metadata may be retained in the local audit. Budgets count authorization attempts conservatively; failed delivery is not automatically refunded. After a worker restart, in-flight actions are not replayed automatically.
Diagnostic Center
Diagnostics are generated on request and exported only by the user. Diagnostic files contain version, status codes, aggregate counts and local feature toggles, but no website hosts, URLs, tab/document IDs, page text, values or audit events. Authorization budgets count attempts conservatively; a failed delivery is not automatically refunded. No new telemetry or remote AI is added.
Optional local bridge
Agent Guard can connect locally to the separately installed SiteEgress extension. Both local bridge settings must be enabled before a summary is exchanged.
Agent Guard can receive minimized SiteEgress privacy context for an origin or requested destination, and can return minimized action, destination-category, policy-outcome, and evidence metadata. Sensitive values and raw IP addresses are excluded.
SiteEgress evidence is advisory context. It cannot create an Agent Guard approval, grant, policy decision, or enforcement result.
Exact published extension IDs, sender validation, schema projection, collection limits, and dual opt-in constrain the bridge.
Local storage and retention
Live sessions are stored in chrome.storage.session. Settings, user rules, imported policy, and optional bounded history are stored in chrome.storage.local. Administrator policy may be read from chrome.storage.managed.
Users can disable history, set available retention limits, clear local data, remove rules, revoke grants, and uninstall the extension.
Transmission, sale and sharing
Agent Guard has no developer-operated analytics, telemetry endpoint, cloud account, remote AI service or remote executable rule feed. It does not automatically upload audit reports, browsing activity, form values, settings or local history to a developer server.
If enabled in both products, the optional local bridge exchanges only the minimized metadata listed in its section. Audit exports are created on your device; you decide whether to share them. Agent Guard does not sell user data or use it for advertising, creditworthiness or lending.
Permissions and website access
Default API permissions are activeTab, scripting, sidePanel, and storage. HTTP and HTTPS site access is optional and requested per origin only after the user chooses to authorize that site.
Optional permissions may include notifications for a generic approval notice, webNavigation for local cross-tab workflow linkage and document lifecycle, and declarativeNetRequestWithHostAccess for temporary tab-scoped destination quarantine without reading request bodies. Users can revoke site access and optional permissions.
Security and limitations
Agent Guard uses bounded messages and collections, sender and document binding, redaction, export sanitization, packaged executable code, and explicit coverage reporting.
No software can identify every agent, detect every prompt injection, observe server-to-server processing, stop synchronous channels that cannot wait for approval, or guarantee complete security. Page-derived evidence is untrusted and can be influenced by the website.
Contact and policy changes
Users may revoke site access and optional permissions, disable Deep Probe and local history, clear history or all extension data, remove rules, reject actions, use Panic Lock, uninstall the extension, and delete exported files.
Privacy questions can be sent to agentguard@siteegress.com or privacy@siteegress.com. Material changes will be reflected in this policy before or when the new processing becomes available.
This policy covers the extension, not analytics on siteegress.com. Extension audit data is not sent to the website’s analytics service.
Website analytics is documented separately