Skip to main content

The Sonar Browser Extension

In this article, learn how the Sonar browser extension works.

1️⃣ What the Sonar browser extension does

Your teams use AI tools in their browser, including tools that aren't approved by your organization. The Sonar browser extension automatically anonymizes sensitive data before it's entered into these tools.

The goal: keep control of your data without slowing your employees down. The extension doesn't block tools — it anonymizes what needs to be anonymized and points employees toward approved tools.

2️⃣ What the extension covers

👉 Browsers

  • Google Chrome and Microsoft Edge (more browsers to come).

  • The employee must be signed into the browser with their work account.

👉 Tools concerned

  • AI tools accessed in the browser (such as ChatGPT, Claude, Perplexity…).

  • Desktop apps aren't covered, since they run outside the browser.

👉 Action detected

  • For now, the extension only intercepts sensitive copy-paste actions. Manual typing and file uploads will follow soon.

💡 Pre-requisites:

  • Use Google Chrome or Microsoft Edge.

  • Be signed into the browser with your work account.

3️⃣ What the extension intercepts exactly

Redaction only applies within a specific scope. Knowing it saves you from promising your teams broader coverage than there actually is.

👉 Browsers

Google Chrome and Microsoft Edge, provided the employee is signed into the browser with their work account. Other browsers will follow.

👉 Actions

  • copy-pasting sensitive content;

  • uploading files, in .txt, .csv, .pdf, .docx and .xlsx formats.

Typing on the keyboard and other file formats aren't covered yet.

⚠️ Important: for .pdf, .docx and .xlsx formats, on-the-fly redaction isn't possible: the upload is blocked rather than redacted. So employees see different behaviour depending on the file type — expect questions about it.

👉 Sites

AI tools accessible in the browser. Desktop applications are not covered, since they run outside the browser.

👍 Good to know: redaction also triggers on an AI tool that is approved at your company, if the employee isn't signed into it with their work account. That is deliberate: on a personal account, your contractual guarantees don't apply.

4️⃣ The employee experience

When an employee pastes sensitive data into an unapproved AI tool:

  • Albert pops up and anonymizes the data on the fly, before it reaches the AI tool.

  • Albert tells them what was anonymized and which approved AI tool to use instead.

  • If the employee disagrees, they can override the redaction in one click (if you allow it — see step 2 below).

5️⃣ What you configure, and what you see

👉 Your three settings

  • which AI tools are approved at your company;

  • which types of sensitive data Albert should redact;

  • whether your employees can override redaction or not.

👉 What you see in the analytics

You never see your employees' prompts, nor individual events. You get aggregated statistics on how often redaction happens, broken down by employee, by data type and by unapproved AI tool.

👍 Good to know: sensitive data doesn't leave the browser. Analysis is performed locally, on the employee's machine. That is the key argument when addressing concerns from your employee representative bodies, and a notable difference from the content analysis of files stored in the Drive.

6️⃣ Deploying and configuring the extension

The extension is included in your Sonar subscription, at no extra cost.

Step 1: Deploy the extension. From your Sonar settings, enable the extension in just a few clicks, then follow our installation guide for Chrome or Edge.

Step 2: Configure the policy. Everything else happens in Sonar's Sensitive data redaction in AI tools policy. There you define:

  • the tools concerned (those that aren't approved at your organization);

  • the sensitive data types Albert should anonymize;

  • whether employees can or cannot override Albert's decision.

Step 3: Track the events. Once the extension is enabled, the first events appear in Sonar's Insights tab (top-right of your screen).

7️⃣ The three deployment routes

The Hub guides you step by step. Which route applies depends on your directory.

👉 Google

The extension is force-installed on managed Chrome browsers, from the Google Admin console. Only employees signed into Chrome with their work account receive it.

👉 Microsoft in the cloud

The extension is force-installed on managed Edge browsers, with no additional tooling. For managed Chrome browsers, deployment goes through Microsoft Intune.

👉 Microsoft on-premise

Several methods exist depending on your setup; we provide guides for the most common ones. Two steps are specific to this case:

  • a secret must be added to the extension to identify your workspace;

  • the employee must sign in to the Riot portal once after installation, so they can be identified.

⚠️ Important: if your environment is entirely on-premise, enabling Sonar can't be done through the usual journey, which is designed for cloud environments. Contact us via the chat: our team will handle it.

💡 Restricting the rollout to a few employees: this is possible on the Microsoft side, for the Edge deployment only, by selecting a group during the procedure

8️⃣ Try the extension

A demo interface lets you try the extension live, with no setup required: demo interface. Just follow the steps to see in real time what Albert can anonymize before data reaches AI tools.

👍 Good to know: Sensitive data doesn't leave the browser: anonymization happens locally, which addresses data privacy concerns.


Key takeaways

  • The Sonar browser extension anonymizes sensitive data before it reaches unapproved AI tools.

  • Available on Chrome and Edge, included in Sonar at no extra cost.

  • For now: copy-paste only (manual typing and file uploads coming soon).

  • You stay in control: approved tools, data types to anonymize, override permission.

Did this answer your question?