Certaines sections détaillées ci-dessous sont encore en anglais. Leur langue est indiquée; elles ne sont pas présentées comme une traduction française complète.
Champ d’application
Agent Guard supervises browser-visible activity performed by AI agents on websites a user explicitly authorizes. It identifies supported high-risk actions and sensitive-data categories, compares actions with user-confirmed intent and deterministic policy, requests approval or blocks supported actions, and keeps a redacted local audit trail.
Agent Guard is not a general chatbot, password manager, tracker blocker, endpoint DLP system, or guarantee against every prompt-injection attack.
Informations traitées
On authorized sites, Agent Guard may transiently process browser-visible field values or metadata to classify personally identifiable information, health information, financial or payment information, authentication information, precise-location fields, and other sensitive categories.
It may inspect bounded page text on authorized webmail, messaging, collaboration, or other pages for prompt-injection signals. It may also process authorized site origin, redacted URL, timestamps, browser-visible clicks, input attempts, submissions, sends, uploads, downloads, navigation, approvals, settings, field labels, target descriptions, links, and destination origins.
Agent Guard does not intentionally perform keystroke logging or retain typed text as a transcript.
Minimisation des données
Raw form values and bounded page text are inspected transiently in the page and are not intentionally stored in the audit model. Persistent records use sensitive-data category indicators, redacted labels, redacted URLs, origin names, amount buckets, action metadata, policy decisions, and other minimized context.
A page-local masked preview can be shown during approval but is not sent to the extension service worker or included in exports. Agent Guard does not intentionally read or retain file contents, Cookie values, browser-storage values, full request bodies, or private keys.
Agent Guard stores categories and decisions—not a copy of the user's conversation or form contents.
Utilisation des informations
Information is used only to show Guard Health and session status; evaluate intent contracts, risk budgets, profiles, and local policy; pause, approve, block, or replay supported actions; build local data-lineage and prompt-risk associations; compare local sessions; generate user-requested exports; link optional cross-tab workflows; and install optional temporary network-quarantine rules.
Policy decisions are deterministic in the current release. Agent Guard does not send prompts or page content to a developer-operated AI service.
Modèles de tâches et tests synthétiques
Trois modèles s’appliquent à l’origine actuelle après confirmation explicite, pour une heure. Ils remplacent l’intention, réinitialisent les budgets et effacent les autorisations temporaires. Les actions en attente ou en cours et un changement de page empêchent un remplacement non sûr.
Les politiques administrées et règles personnalisées restent applicables. Les tests synthétiques exécutent le moteur de politique sans envoi réseau réel ni répétition d’une action; ils ne prouvent pas une protection complète.
Cycle de tâche et autorisations
L’expiration et la commande de fin de tâche avec verrouillage permettent de supprimer les autorisations et d’activer Panic Lock après confirmation. Les actions déjà envoyées ne peuvent pas être rappelées.
L’audit local peut conserver des métadonnées minimisées d’autorisation et de budget. Les tentatives sont comptées prudemment, sans remboursement automatique après échec d’envoi. Un redémarrage du worker ne rejoue pas les actions en cours.
Centre de diagnostic
Les diagnostics sont créés et exportés à la demande. Ils comprennent la version, des états et des compteurs, sans hôtes, URL, identifiants de pages, contenu ou audit détaillé. Les budgets comptent les tentatives d’autorisation; un échec d’envoi ne rembourse pas automatiquement le budget. Aucune nouvelle télémétrie ni IA distante.
Pont local facultatif
Agent Guard can connect locally to the separately installed SiteEgress extension. Both local bridge settings must be enabled before a summary is exchanged.
Agent Guard can receive minimized SiteEgress privacy context for an origin or requested destination, and can return minimized action, destination-category, policy-outcome, and evidence metadata. Sensitive values and raw IP addresses are excluded.
SiteEgress evidence is advisory context. It cannot create an Agent Guard approval, grant, policy decision, or enforcement result.
Exact published extension IDs, sender validation, schema projection, collection limits, and dual opt-in constrain the bridge.
Stockage local et conservation
Live sessions are stored in chrome.storage.session. Settings, user rules, imported policy, and optional bounded history are stored in chrome.storage.local. Administrator policy may be read from chrome.storage.managed.
Users can disable history, set available retention limits, clear local data, remove rules, revoke grants, and uninstall the extension.
Transmission, vente et partage
Agent Guard has no developer-operated analytics, telemetry endpoint, cloud account, remote AI service or remote executable rule feed. It does not automatically upload audit reports, browsing activity, form values, settings or local history to a developer server.
If enabled in both products, the optional local bridge exchanges only the minimized metadata listed in its section. Audit exports are created on your device; you decide whether to share them. Agent Guard does not sell user data or use it for advertising, creditworthiness or lending.
Autorisations et accès aux sites
Default API permissions are activeTab, scripting, sidePanel, and storage. HTTP and HTTPS site access is optional and requested per origin only after the user chooses to authorize that site.
Optional permissions may include notifications for a generic approval notice, webNavigation for local cross-tab workflow linkage and document lifecycle, and declarativeNetRequestWithHostAccess for temporary tab-scoped destination quarantine without reading request bodies. Users can revoke site access and optional permissions.
Sécurité et limites
Agent Guard uses bounded messages and collections, sender and document binding, redaction, export sanitization, packaged executable code, and explicit coverage reporting.
No software can identify every agent, detect every prompt injection, observe server-to-server processing, stop synchronous channels that cannot wait for approval, or guarantee complete security. Page-derived evidence is untrusted and can be influenced by the website.
Contact et modifications
Users may revoke site access and optional permissions, disable Deep Probe and local history, clear history or all extension data, remove rules, reject actions, use Panic Lock, uninstall the extension, and delete exported files.
Privacy questions can be sent to agentguard@siteegress.com or privacy@siteegress.com. Material changes will be reflected in this policy before or when the new processing becomes available.
Cette politique couvre l’extension, pas les statistiques de siteegress.com. Les données d’audit de l’extension ne sont pas envoyées aux statistiques du site.
Consulter les statistiques du site