AI ガードレール · AI-DLP AI guardrails · AI-DLP

Kerb があるから、AI は攻められる。 You can push AI harder, because of the kerb.

Kerb は、AI チャットに送ろうとしたテキストをその場で検査し、機密情報や個人情報が含まれていれば警告します。検査はあなたの手元で完結します。判定はブラウザの中で、記録はあなたのストレージへ。プロンプトが Kerb のサーバーを通ることはありません。 Kerb inspects what your people are about to send to AI chat and warns them on the spot when it finds credentials or personal data. Inspection stays on your side: analysis runs in the browser, records go straight to your own storage. Prompts never pass through Kerb's servers.

Chrome に追加(公開準備中) Add to Chrome (coming soon) Kerb の考え方How we think about it

Chrome ウェブストアでの公開を準備しています。まず一人から、無償で始められます。 We are preparing the Chrome Web Store listing. Start free, on your own.

統制の死角は、会社のアカウントの外にある The blind spot is outside your corporate accounts

AI へのデータ投入の多くは、会社が契約したアカウントではなく、従業員個人のアカウントを経由します。エンタープライズ契約の「学習しない・ゼロ保持」も、プラットフォーム内蔵の DLP も、この経路までは届きません。 Most data that reaches AI does not go through the accounts your company pays for — it goes through your people's personal ones. Enterprise "no training, zero retention" terms and platform-native DLP do not reach that path.

Kerb はブラウザ層で捕捉します。どのアカウントで開いていても、AI に何を渡しかけたのかが見えるようになります。 Kerb works at the browser layer. Whichever account someone signed in with, you can see what was about to be handed to an AI.

プロンプトを、別のクラウドに預けない Your prompts do not go to another cloud

AI-DLP の多くは、プロンプトの中身をベンダーのクラウドに取り込んで分類します。それでは「秘密を守るために、秘密をもう一社に渡す」ことになります。Kerb はそこを通しません。 Most AI-DLP products pull prompt content into the vendor's cloud to classify it — which means handing your secrets to one more company in order to protect them. Kerb does not route them anywhere.

判定はブラウザの中で完結 Analysis never leaves the browser

検出ロジックは拡張機能の中で動きます。判定のためにテキストを外部へ送る仕組み自体がありません。 Detection runs inside the extension. There is simply no mechanism that sends text out for analysis.

個人アカウント経由も見える Personal-account use is visible too

アカウントの契約形態に依存せず、ブラウザ層で捕捉します。契約では埋められない死角を埋めます。 Capture happens at the browser layer, independent of who pays for the account — covering the gap contracts cannot close.

証拠は自社に残る The evidence stays yours

記録の保存先はあなたが接続したストレージです。ベンダーの管理下に証拠を置かず、いつでも自分で取り出せます。 Records are written to the storage you connect. Your evidence never sits under a vendor's control, and you can take it out whenever you want.

拡張機能が通信する先の一覧はプライバシーポリシーに記載しています。 Every endpoint the extension contacts is listed in our Privacy Policy.

送信の瞬間に、その場で At the moment of sending

クラウドに届いてから調べるのでは手遅れです。Kerb は送信ボタンと Enter キーそのものに割り込み、テキストが画面を離れる前に判定します。 Scanning after the text reaches the cloud is too late. Kerb intercepts the send button and the Enter key itself, and decides before the text leaves the screen.

01

送信に割り込むIntercept the send

送信ボタンのクリックと Enter キーを捕捉します。添付したテキストファイルや PDF の中身も対象です。 Both the send button and the Enter key are captured — including the contents of attached text files and PDFs.

02

その場で判定するDecide on the spot

検出ロジックをブラウザ内で実行し、該当があれば警告ダイアログを表示します。 Detection runs locally in the browser, and a warning dialog appears if something matches.

03

記録を自社に残すKeep the record

何を渡しかけたか、どう対応したかを、あなたが接続したストレージへ直接書き込みます。 What was nearly shared, and what the person chose to do, is written straight to the storage you connect.

何を見つけるかWhat it finds

検出ルールは拡張機能のアップデートで継続的に追加されます。あなたが何もしなくても、守備範囲は広がっていきます。 Detection rules keep being added with every extension update. Your coverage grows without you doing anything.

認証情報Credentials

  • クラウドのアクセスキー
  • Cloud access keys
  • 各種サービスの API トークン
  • API tokens for developer services
  • 秘密鍵
  • Private keys
  • データベース接続情報
  • Database connection strings

個人識別情報Personal identifiers

  • マイナンバー・各国の国民識別番号
  • National ID numbers, including Japan's My Number
  • クレジットカード番号
  • Credit card numbers
  • パスポート番号
  • Passport numbers
  • 銀行口座番号
  • Bank account numbers

機密情報Confidential content

  • 社外秘マーカー・弁護士秘匿特権
  • Confidentiality and privilege markers
  • 輸出管理・制裁関連
  • Export control and sanctions
  • 給与額・M&A 関連情報
  • Salary figures and M&A information
  • ソースコードの大きな塊
  • Large blocks of source code
桁数が合うだけでは警告しません。 A matching digit count is not enough to fire. 無駄に止められないことは、見つけることと同じくらい大事だと考えています。 Not interrupting people needlessly matters as much as catching what counts.

対応状況What's supported

現在は次の AI サービスとブラウザに対応しています。いずれも順次拡大します。 These are the AI services and browsers supported today. All three rows keep expanding.

提供中Available 順次拡大Expanding
AI サービスAI services ChatGPT / Gemini / Claude Microsoft Copilot、Perplexity ほか Microsoft Copilot, Perplexity and more
ブラウザBrowsers Chrome Edge / Safari
保存先ストレージStorage Dropbox OneDrive / Google Drive / Box、S3 / Azure Blob / GCS(組織向けプラン) OneDrive / Google Drive / Box, plus S3 / Azure Blob / GCS (organization plans)

これから向かう先Where Kerb is going

「気づかせる」段階から、「組織で運用できる」段階へ。 From helping one person notice, to something an organization can run on.

  • 送信の自動ブロック — いまは警告で気づく段階です。いずれ、ポリシーに応じて送信そのものを止められるようにします。
  • Automatic blocking — today Kerb warns so people notice. In time, it will be able to stop a send outright according to policy.
  • 組織で使う — メンバー招待・チーム・管理画面・健全度スコア。誰がどこで何を渡しかけたかを、組織の単位で把握できるようにします。
  • Run it as an organization — invitations, teams, an admin console and a health score, so you can see what is being handed to AI across the whole company.
  • 自社ルール — 標準ルールに加えて、自社の機密語やプロジェクトのコードネームを自分で登録できるようにします。
  • Your own rules — register your own confidential terms and project code names alongside the standard rule set.
  • 検査範囲の拡大 — 画像や Office 文書、さらにブラウザ以外の経路(エージェント・MCP・業務アプリに埋め込まれた AI)へ。
  • Wider coverage — images and Office documents, then paths beyond the browser: agents, MCP, and AI embedded in business applications.
  • 判定の高度化 — ブラウザ内で動くローカル AI 分類器により、形式だけでなく文脈を見た判定へ。
  • Smarter decisions — a local AI classifier running in the browser, judging context rather than shape alone.

料金Pricing

まず一人で始めて、必要になったら組織へ広げられます。 Start on your own, then extend it across the organization.

Free 提供中Available
¥0Free

一人で使う。検出と警告のすべて、あなたのストレージへの記録。アカウント登録は不要です。 For one person. Full detection and warnings, with records written to your own storage. No account required.

組織向けFor organizations 準備中In preparation
準備中Coming

チームで使う。メンバー管理・管理画面・健全度スコア・自社ルール。価格は公開時にお知らせします。 For teams. Member management, an admin console, a health score and your own rules. Pricing will be announced at launch.

よくある質問Frequently asked questions

送信は自動で止まりますか? Does Kerb stop the send automatically?
いまは警告を出して気づいてもらう段階で、送るか書き直すかは利用者が決めます。誤って業務を止めてしまわないための形です。ポリシーに応じた自動ブロックは、この先に搭載します。 Today Kerb warns and the person decides whether to send or revise, so nobody's work is halted by mistake. Policy-driven automatic blocking comes later.
検出漏れや誤検知はありますか? Can it miss things, or fire wrongly?
あります。Kerb は既知のパターンとの照合であり、すべての機密情報を検出できることを保証するものではありません。精度は継続的に改善していきますが、最終的な判断と責任は利用者にあります。 Yes. Kerb matches known patterns and cannot guarantee that everything sensitive is caught. We keep improving accuracy, but the final judgement and responsibility rest with the user.
保存先のストレージは必須ですか? Do I need to connect storage?
記録を残すには接続が前提です。未接続の間も検出と警告は動作し、記録はブラウザ内に暗号化して一時保持され、接続した時点で書き出されます。容量が増えても自動では削除しません。 Yes — keeping records depends on it. Detection and warnings still work before you connect: records are held encrypted in the browser and flushed once storage is connected. They are never auto-deleted to save space.
組織で使えますか? Can we deploy it across a team?
現在は一人ひとりが個別に使う形です。メンバー管理・管理画面・組織単位の可視化を備えた組織向けの提供を準備しています。 Right now Kerb is used per person. An organization-wide offering — member management, an admin console and company-level visibility — is in preparation.

公開までもう少しお待ちください Almost ready

Chrome ウェブストアでの公開を準備しています。ご質問・不具合のご報告はお問い合わせからどうぞ。 We are preparing the Chrome Web Store listing. Questions and bug reports are welcome via the contact form.