If you've just paid, this usually clears within a minute. Check again, and if it still doesn't appear, email [email protected] — nothing is lost, your seats will attach to this team.
Overview
What your team's extensions caught, and the seats you're paying for.
Detections over time
What was caught
Where it was headed
What people chose
Activity is shown for the team as a whole. SecureIntent never receives the text anyone pastes — only that something was caught, what kind, and where it was going.
People
Who holds a seat, who has been invited, and how many seats you pay for.
Available once your payment completes
| Person | Role |
|---|
A seat is a person. Removing someone frees their seat but keeps you on the same subscription — use Change seats to pay for fewer.
Policy
Rules that travel to the extension on every seat and are applied on the device. They change what your colleagues can do, so read what each one costs them.
Normally the extension warns and leaves the choice with the person: paste anyway, paste an anonymised copy, or cancel. Turn this on and Paste anyway disappears — when a secret is found, the original text cannot be pasted at all. Only the anonymised paste and cancel remain. That also means a false positive becomes a hard stop with no way round it, so expect a few "it won't let me paste" messages in the first week.
Switches the PIN lock on for every seat and stops people turning it off. After a few minutes of inactivity or a tab away, high-risk cloud consoles (AWS, GCP, Azure, Cloudflare, and the rest) are covered until the PIN is re-entered. Anyone who hasn't set a PIN yet is asked to choose one the first time it fires.
Blocked destinations
On these hostnames the extension refuses every paste, whether or not it finds
a secret — for sites your team shouldn't be feeding data into at all. Everywhere
else behaves normally. One hostname per entry, no https:// and no path.
Custom patterns
Anything matching one of these counts as a secret on every seat, alongside the built-in detectors — for your own token formats. The regular expression is evaluated on the device against the pasted text; the text still never leaves it. Keep patterns tight: one that fires on ordinary prose teaches people to click through warnings, which costs you more than it catches. The label is what your colleague reads in the warning.
Normally your patterns run alongside ours. Turn this on and they run instead of ours: SecureIntent's own catalogue — AWS keys, private keys, GitHub and Slack tokens, database URLs, the lot — stops being checked for everyone on the team. An AWS key pasted into a chat would go through without a word. Only switch it on if the patterns above really are the only things you want caught.
One safeguard, so this can't quietly turn detection off: if your team has no usable patterns, our catalogue keeps running anyway. A pattern the extension can't compile doesn't count, so an empty or broken list always falls back to full coverage.
There are no patterns above yet, so this changes nothing for now — our catalogue keeps running until you add one. Add a pattern before you save, or leave this off.
Alerts
Where SecureIntent posts the moment the extension catches something on one of your seats.
Post a message to Slack, Teams, or any HTTPS endpoint. The alert says what kind of secret it was and where it was headed — never the text itself, which never leaves the machine.
Card numbers are always checked. Emails and IP addresses are only caught in large log pastes, where they aren't everyday chatter.
Leave the URL empty to turn alerts off. The test posts to the saved URL, so save first if you've just changed it. Alerts and policy are one record — either Save button writes both.