Skip to content

CyberHQ.ai Browser Extension — Privacy & Data Disclosure

Effective 18 September 2026

CyberHQ.ai is a browser extension built for organisations to detect and prevent risky handling of sensitive data when their people use AI, coding, and other agentic tools at work. This page explains what the extension does, what data it collects while running in your browser, and how that data is used; whether it was installed for you by your employer's IT team, or you installed it yourself from the Chrome Web Store.


If your organisation has deployed CyberHQ.ai, this disclosure covers the extension itself. Your employer's own privacy notice governs how they use information about your work activity more broadly.

What the extension does
CyberHQ.ai discovers use of AI tools, classifies agentic activity, and enforces data-loss-prevention (DLP) controls, to help organisations understand and reduce the risk of sensitive data leaving through AI and coding tools. It can be installed in two ways:

  • Employer force-install: pushed to managed devices by a customer's IT/security administrator via enterprise Chrome policy.

  • Self-serve individual install: installed directly by an individual from the Chrome Web Store, then enrolled against their employer's CyberHQ.ai tenant.


What data the extension collects
The extension collects the following categories of data:

  • AI prompts and responses on named AI and coding tools: the content you send to, and receive from, the AI and coding tools named in the extension's configuration  used to classify AI activity and scan for DLP matches. The extension reads this content on those named tools only, and does not read the content of other pages you visit.

  • General work tools: on a named set of general SaaS and collaboration tools (for example GitHub, GitLab, Slack, Microsoft Teams, Outlook, LinkedIn and Dropbox), the extension observes network-level activity signals only. No page content is read on these sites.

  • Page identifiers: the domain and a truncated page title for every open tab; text that resembles an email subject line is redacted from the title before it is stored.

  • Workspace identity: the signed-in Google Workspace email address, used to enrol the extension and to attribute activity to the correct user within your organisation's tenant. It is not used to access the individual's personal email or other Workspace content.

  • Device and browser metadata: operating system, browser type, and whether Chrome enterprise-installed the extension. This check confirms only whether the extension itself was force-installed; it does not see or report on any other extension installed in the browser.

  • Local device linkage (if applicable): where a customer has also deployed Avertro's companion endpoint sensor, the extension shares a local device identifier with the sensor via native messaging so the two can be correlated to a single device. No page content is shared over this channel.

  • Unrecognised-destination detection (optional, off by default): where an organisation enables this setting, the extension also records the domain name (not the page content or network activity) of other sites visited, in order to flag possible unauthorised use of AI or agentic tools outside the configured list.

  • How long we keep it: activity events collected by the extension are retained for 90 days by default.


Some content scanned for and redacted under this section may itself qualify as “sensitive personal information” under CCPA/CPRA even in redacted form, depending on which detection rules are configured. If you have questions about exercising rights relating to this data, see “Questions or requests” below.

 

What the extension does not do

  • No standing access to all websites. The extension does not request broad, always-on access to every site you visit. A broader host permission (covering the operator-configured backend origin) is optional, requested only once during setup, and requires explicit approval through Chrome's own permission prompt.

  • No sale of data, and no use for advertising. We do not sell data collected via the extension, or share it with third parties for advertising or unrelated purposes.

  • No pooling across customers. Extension data is processed into the customer's own CyberHQ.ai tenant. It is not pooled with, or made visible to otherto, other customers.

How your data is used

  • Data collected by the extension is used only to:

  • classify AI and agentic tool usage

  • detect and prevent data loss (DLP)

  • identify anomalous or risky user behaviour

  • enrol and bind the extension to the correct customer tenant (fleet management)

  • correlate activity with the companion endpoint sensor, where deployed

Data security

Data collected by the extension is encrypted in transit and at rest, and access is restricted to authorised personnel who need it to operate and support the service. Sensitive content identified during DLP scanning is redacted before storage, as described above.

Limited Use compliance

Avertro's use of data collected by this extension complies with the Chrome Web Store User Data Policy, including the Limited Use requirements: data is used only to provide and improve the extension's stated purpose above; it is not transferred except as necessary for that purpose, for legal compliance, or for security; and it is never used for personalised advertising or sold to third parties, including data brokers.

Questions or requests 

If your organisation deployed CyberHQ.ai, please direct questions about how your monitored activity is used to your employer's IT or security team in the first instance. For questions about the extension itself, contact us at legal@avertro.com.

See CyberHQ® configured to your environment

Book a 30-minute interactive session to see how CyberHQ® integrates with your existing tools, frameworks and environment.