PrismSek
Products
Data DiscoveryData ClassificationData Loss PreventionMCP & AI Data ProtectionAutonomous SOC Analyst
Solutions
Shadow AIInsider RiskAI SecurityCloud Data SecurityComplianceData MinimizationSecure AI Data Pipeline
Company
PlatformIntegrationsDPDP ComplianceCustomersContact Us
Request a demo
Legal

PrismSek Privacy Policy

Effective Date: September 2, 2026 · Last Updated: September 2, 2026

On this page1. Purpose of the Extension2. Information We May Process3. Data Minimization4. Authentication & Credentials5. How Content Is Processed6. How We Use Information7. Data Sharing & Transfers8. Human Access to User Data9. Data Retention10. Security11. Enterprise Management12. Advertising13. Creditworthiness & Lending14. Limited Use Disclosure15. Changes to This Policy16. Contact Us

This Privacy Policy explains how the PrismSek DLP Browser Extension (“PrismSek DLP”, “Extension”, “we”, “our”, or “us”) handles information when deployed as part of the PrismSek data security platform.

PrismSek DLP is provided by Skyrion Labs and is designed for enterprise data protection, Data Loss Prevention (DLP), and security-policy enforcement.

The Extension is intended primarily for organizations that deploy and manage PrismSek on corporate devices.

1. Purpose of the Extension

The single purpose of PrismSek DLP is to help organizations protect sensitive information during browser-based activity.

The Extension detects supported browser events such as:

  • web uploads;
  • pasted content;
  • supported generative-AI interactions;
  • relevant outbound web requests; and
  • browser activity required to determine whether PrismSek protection is operating correctly.

PrismSek DLP applies or supports security decisions made according to centrally managed PrismSek policies.

The Extension does not use collected information for advertising, marketing profiling, credit scoring, or unrelated purposes.

2. Information the Extension May Process

For Chrome Web Store purposes, PrismSek DLP handles the following categories of user data:

Website Activity

PrismSek may process limited information about browser activity when necessary to provide DLP protection, including:

  • navigation or page-transition events;
  • relevant destination or service information;
  • supported upload or submission events;
  • requests associated with protected data movement;
  • interaction events required to identify a protected action; and
  • technical information necessary to determine whether protection is active.

This information is processed only where necessary to provide PrismSek’s security and DLP functionality.

PrismSek does not use browser activity to create advertising profiles or track users for marketing purposes.

Website Content

When necessary to evaluate a protected action, PrismSek may temporarily process content associated with that action, including:

  • text being pasted or submitted;
  • content entered into supported AI applications;
  • approved content fields associated with a protected request; and
  • content associated with supported upload operations.

Website content is processed for the purpose of determining and enforcing the organization’s data-security policy.

3. Data Minimization

PrismSek is designed to minimize the amount of raw user data that is retained.

The Browser Extension does not normally persist raw:

  • file contents;
  • filenames or local file paths;
  • email addresses or account identifiers;
  • full destination URLs;
  • authentication credentials;
  • cookies;
  • bearer tokens;
  • API keys;
  • passwords;
  • sensitive matched values; or
  • surrounding sensitive text.

Raw filenames, destination/account identifiers and similar values are kept out of persistent Browser Extension logs and telemetry and are cleared when the protected operation ends or the associated transient state expires.

Where possible, PrismSek instead uses privacy-minimized information such as:

  • opaque operation identifiers;
  • sanitized destination information;
  • bounded classifications;
  • cryptographic hashes;
  • content length;
  • policy identifiers;
  • security verdicts; and
  • health or coverage status.

4. Sensitive Authentication and Credential Data

PrismSek treats authentication information as specially protected data.

Credential-related values such as authorization headers, cookies, API keys, passwords, bearer tokens, session tokens, OAuth/OIDC codes, signed-URL credentials and similar authentication material are not intended to be used as DLP inspection content.

Under PrismSek’s privacy architecture, protected credential values are excluded from normal serialization, scanning, hashing, logging, persistent storage, support bundles and normal telemetry.

5. How Website Content Is Processed

Where browser content requires inspection, the Browser Extension sends the required bounded content through PrismSek’s authenticated local communication channel to the locally installed PrismSek Agent / Native Messaging Host.

The Browser Extension does not directly send raw generated browser content to a cloud service.

Generated browser content is treated as temporary inspection material. PrismSek’s design uses memory by default and does not place raw generated content into normal endpoint databases, audit records or general telemetry.

6. How We Use Information

Information handled by PrismSek DLP is used only for purposes directly related to its security function, including:

  • detecting protected browser actions;
  • evaluating DLP policy;
  • preventing unauthorized data movement;
  • obtaining or enforcing centrally determined security verdicts;
  • determining destination and policy context;
  • maintaining the connection between the Extension and PrismSek Agent;
  • maintaining security-policy and application catalog information;
  • identifying degraded or unavailable protection;
  • troubleshooting security or reliability issues; and
  • generating privacy-minimized security and audit evidence.

We do not use Browser Extension data for unrelated commercial purposes.

7. Data Sharing and Transfers

PrismSek does not sell user data.

PrismSek does not transfer user data to:

  • advertising networks;
  • data brokers;
  • information resellers; or
  • organizations for creditworthiness or lending decisions.

Information may be processed by PrismSek systems and authorized service providers only where necessary to operate, secure, maintain or support the PrismSek service.

Information may also be disclosed where required:

  • to comply with applicable law or legal process;
  • to investigate or prevent security threats, fraud, abuse or malicious activity; or
  • as part of a corporate merger, acquisition or sale of assets where legally permitted and subject to applicable consent requirements.

8. Human Access to User Data

PrismSek does not permit employees or other personnel to routinely read raw user content collected through the Extension.

Human access may occur only where:

  • the customer or user has provided appropriate consent for specific support;
  • access is necessary to investigate a security incident or abuse;
  • access is required to comply with applicable law; or
  • information has been appropriately aggregated or anonymized for legitimate internal operational purposes.

Access is subject to applicable authorization and security controls.

9. Data Retention

The Browser Extension is designed not to retain raw website content or raw file contents as normal persistent Browser Extension state.

Transient inspection information is retained only for the period necessary to complete the relevant protected operation and is cleared according to PrismSek’s bounded lifecycle and privacy controls.

PrismSek may retain privacy-minimized security, audit and operational metadata where necessary to:

  • provide the service;
  • maintain security evidence;
  • investigate incidents;
  • meet customer-configured requirements; or
  • comply with applicable legal obligations.

Endpoint data is subject to purpose-specific retention limits rather than indefinite storage. PrismSek’s internal retention contract specifically requires bounded local state and prohibits normal endpoint stores from retaining raw customer-file content or raw detector values.

10. Security

PrismSek uses technical and organizational safeguards designed to protect information processed through the Extension.

These include, where applicable:

  • authenticated communication with the locally installed PrismSek Agent;
  • organization-managed deployment and policy controls;
  • access controls;
  • data minimization;
  • bounded retention;
  • secure deletion or cryptographic erasure where applicable;
  • privacy-safe logging and telemetry; and
  • modern cryptographic protection for information transmitted over external networks.

The Extension does not execute remotely hosted JavaScript or WebAssembly as part of its production operation.

11. Enterprise Management

PrismSek DLP may be installed and managed by an employer, organization, IT administrator or security administrator.

In an enterprise deployment, the organization determines the security policies that PrismSek DLP enforces and may receive security events or audit information generated under those policies.

Users should contact their organization’s administrator for questions about their organization’s particular monitoring, security or retention policies.

12. Advertising

PrismSek DLP does not:

  • display targeted advertising;
  • use browsing activity for advertising;
  • sell data for advertising;
  • create advertising profiles; or
  • transfer Browser Extension data to advertising platforms or data brokers.

13. Creditworthiness and Lending

PrismSek does not use or transfer information collected through the Browser Extension to determine:

  • creditworthiness;
  • credit scores;
  • lending eligibility; or
  • financial lending decisions.

14. Chrome Web Store Limited Use Disclosure

The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.

PrismSek limits the collection, use and transfer of user data to information that is necessary to provide and improve the Extension’s disclosed single purpose: enterprise data protection and DLP enforcement.

Google currently requires extensions handling user data to publish an accurate policy explaining collection, use and sharing, and its Limited Use policy restricts use of such data to the extension’s disclosed single purpose.

15. Changes to This Privacy Policy

We may update this Privacy Policy when PrismSek functionality, privacy practices, legal requirements or Chrome Web Store requirements change.

If a change materially affects how the Browser Extension handles user data, we will update the applicable disclosures and policy before introducing the changed data practice where required.

The latest version of this Privacy Policy will be published on the PrismSek website.

16. Contact Us

For privacy questions or requests relating to PrismSek DLP, contact:

Skyrion Labs
Product: PrismSek
Website: https://prismsek.com/
Privacy email: contact@prismsek.com
General contact: https://prismsek.com/contact

PrismSek — Secure What Moves

AI-native data security across SaaS, GenAI, cloud, and endpoints.

Enter the experience →

Products

Data DiscoveryData ClassificationData Loss PreventionMCP & AI Data ProtectionAutonomous SOC Analyst

Solutions

AI SecurityShadow AIInsider RiskCloud Data SecurityComplianceData MinimizationSecure AI Data Pipeline

Company

PlatformIntegrationsDPDP ComplianceCustomersContact Us
© 2026 Skyrion Labs Private LimitedSecurityPrivacyResponsible disclosure