Privacy policy · Browser extension

Sorvek extension · Data and privacy

Last updated: September 25, 2026 · Written with reference to Quebec's Law 25 and Canada's PIPEDA

This policy supplements Sorvek’s main privacy policy and describes the processing specific to the Sorvek Discovery browser extension.

1. Scope and roles

The Sorvek Discovery browser extension is a security tool reserved for organizations that are Sorvek customers. Your employer or organization (the "organization") decides to deploy it and chooses, feature by feature, what it collects.

Your organization is responsible for the personal information processed by the extension. Sorvek processes it on the organization's behalf, under the contract between them. For any question about how your organization uses this data, contact its IT team first.

This policy applies to the extension on Chrome, Edge, Firefox and other Chromium-based browsers, whether it is installed through a device management policy (Intune, GPO, Jamf) or manually.

2. Data sent to Sorvek

Each feature depends on your organization's policy (section 6). The table describes what is sent to Sorvek when a feature is active, and what stays on your device.

FunctionData sent to SorvekWhat stays on your device
EnrollmentWhile you type on the enrollment page: the email address typed, sent in the request address to find your organization's policy (it is not stored at this step). At enrollment: your work email address, a random device identifier, the browser type and the extension version. With Microsoft sign-in: a sign-in code that Sorvek exchanges with Microsoft to confirm your address. In a managed deployment: your organization's deployment key.No Microsoft token is kept.
Browsing
(SaaS visibility feature)
For each page opened, on all sites: the domain name, the navigation type and the time. On a few AI agent platforms (for example chatgpt.com), the page path. The host names of the services contacted by the pages, with the page's domain, grouped every 5 minutes.The rest of the page address (path, parameters, fragment).
Sign-in detection
(SaaS visibility feature)
When you sign in to an application: the site, the sign-in methods offered and the one used (password, SSO, social account), the context (sign-in, sign-up, invitation) and the time. The address used is sent only if it has the same domain as your registered work address; otherwise, only the "personal" or "external" label is.The password: sign-in detection only checks whether the field is filled in. Addresses on a domain other than yours.
AI tools
(AI analysis feature)
For each message sent to one of the AI tools covered (about fifty dedicated tools, including ChatGPT, Copilot, Gemini, Claude and Mistral, and, unless your organization excludes them, the AI assistants built into Gmail, Outlook, Google Docs, Microsoft 365, Notion, HubSpot and Zoom): the tool, the conversation identifier when the tool shows it in its address, a SHA-256 fingerprint, the length, a preview of the first 200 characters (section 3), the types of sensitive data detected, the outcome (sent, warned, cancelled, masked, blocked) and the justification you type, if any. The first 4,096 characters of the message are also sent for a second analysis, then deleted without being stored. For a cancelled or blocked message, no text is kept.Text beyond 4,096 characters. However, when masked data (for example a long private key) takes up the start of the message, the 200-character preview may contain text located further on. Responses from AI tools are not collected.
Files, images and pastes
(AI analysis feature)
For a file or image added to an AI tool (by drag and drop, with the file upload button or, for an image, by pasting), when the analysis finds something or a rule of your organization applies: the file name, its type, the result and coverage of the analysis, the types of sensitive data detected, the outcome and, if any, your justification. For pasted text: an event only if the analysis detects high-risk data (for example a key, token, password, credit card number or SIN) or a pattern specific to your organization, with the types detected and the length.The content of files, images and the text read in images: the analysis, including text recognition, runs on your device. Pasted text is not sent when you paste it; once you send it, it is part of the message ("AI tools" row).
Developer consoles
(SaaS visibility feature)
On GitHub, Vercel, AWS, Google Cloud and Cloudflare, when a key or secret is displayed: the secret type, the count, the page address (Sorvek removes its parameters before storing it on its servers) and an excerpt of up to 100 characters, in which the detected secret is reduced to its first 4 and last 4 characters (for a private key, its header is what is reduced).The full value of the reported secret, unless it appears in the page address. The text around it in the excerpt (up to 15 characters on each side) is not masked and may contain other information, such as a short password.
Extension inventory
(SaaS visibility feature)
For each extension installed in the browser: identifier, name, version, description, state, installation type, permissions, permitted sites and home page.The content and data of other extensions.
Organization policyYour acceptance of your organization's AI acceptable use policy, your requests for access to a tool or site (with your justification) and the blocked sites you tried to open.Nothing else.
Technical dataThe date of last activity and the extension version, updated at each exchange, send-queue counters and capture health signals (the AI tool visited, its host name and the time, even if no message is sent), without message content.Nothing else.

Like any web service, Sorvek's servers see your device's IP address at each exchange, in particular to rate-limit requests. It is not stored with the extension data. The web server's technical logs may contain the IP address and the address of requests, including the email address typed on the enrollment page.

3. Messages sent to AI tools

The preview kept is the first 200 characters of the message, after masking on your device. A message of 200 characters or less is therefore kept in full, with only the masked items replaced by a marker.

Masked in the preview: common API keys and tokens recognizable by their format (OpenAI, Anthropic, GitHub, Google Cloud, Stripe, Slack, GitLab, Twilio identifiers, the AWS access key ID "AKIA…" and others; the matching AWS secret access key is not recognized in its usual form and may remain readable), private keys, the value of a secret preceded by a keyword such as "password=", valid credit card, SIN, US social security, Canadian bank account and IBAN numbers when written in a recognized format (for example, a SIN written as nine consecutive digits or an IBAN written in groups of four is neither detected nor masked), the Quebec health insurance number together with its context, and high-severity patterns specific to your organization.

Detected but not masked: email addresses, phone numbers, some identification numbers (including the NEQ, the Quebec driver's licence and US identifiers), numbers shaped like a SIN without being one, code excerpts, names of employees of your organization and medium- or low-severity patterns specific to your organization. These items remain readable in the preview.

If the server detects a secret that escaped masking, it replaces the whole preview with a generic notice. The justification you type (up to 2,000 characters) is kept as is, without masking.

No detector targets health information or other sensitive categories in free text. If you write such information in a message, a justification or a file name, it may be kept. Avoid entering it in AI tools.

4. What the extension does not send

  • Your passwords: at sign-in, sign-in detection only checks whether the field is filled in. On GitHub, Vercel, AWS, Google Cloud and Cloudflare, API key discovery also reads password fields on your device: if a value looks like a key or token, a short, partly masked excerpt may be sent.
  • Responses from AI tools.
  • The content of the files and images you add: it is analyzed on your device. Text you paste is also analyzed on your device, but if it is part of a message sent to an AI tool, it follows the same rules as that message (section 2).
  • The content of the pages you visit, except what section 2 describes: the text you send to AI tools, the excerpts around secrets in developer consoles, file names and the address used at sign-in.
  • Before you enroll, nothing other than the email address typed on the enrollment page, the extension version, and your choices on that page (options checked, or a refusal). Exception: if enrollment fails (network or server unavailable) while AI analysis is checked, a message you then send to an AI assistant built into an application (Gmail, Outlook, Google Docs, Microsoft 365, etc.) may be sent to Sorvek, which rejects it without storing it.

5. Purposes

PurposeData involved
Identify the SaaS applications and AI tools used in the organization, and the accounts opened on themBrowsing, services contacted, sign-in detection
Prevent data leaks to AI tools and enforce the organization's AI acceptable use policyMessages, files and pastes in AI tools, acceptances, access requests, blocked sites
Flag secrets exposed in developer consolesSecret type, page address, reduced excerpt
Identify risky browser extensionsExtension inventory
Operate and troubleshoot the extensionTechnical data

6. Choices, consent and managed deployment

Your organization sets each of the two features, SaaS visibility and AI analysis, to one of three values: employee's choice, required or disabled.

On an unmanaged device: the enrollment page shows the features. Optional features are checked by default. Signing in with Microsoft enables the features as they are checked at that moment; to uncheck them before activation, first type your work email. A required feature is normally enabled and you cannot uncheck it; on an unmanaged device, however, "Decline all" still stops SaaS visibility, even when it is required. "Decline all" stops collection for optional features; if your organization requires AI analysis, what you send to AI tools may still be recorded.

On a device managed by your organization (Intune, GPO or Jamf policy): the extension enrolls itself with the address provided by your organization, both features are enabled according to its policy and you cannot decline them in the extension. A notice describing the collection is shown at enrollment.

Protection rules: once the extension is enrolled, your organization's rules may block a submission that contains sensitive data, warn you or mask that data, even if you have not consented to AI analysis. If that feature is neither enabled by you nor required by your organization, nothing is sent to Sorvek about that submission. Before enrollment, the extension blocks access to dedicated AI tools.

Changing your mind: on an unmanaged device, the extension's "Open settings" button reopens the enrollment page, where you can change your choices or decline everything. Withdrawing your consent stops collection for optional features; if your organization requires AI analysis, what you send to AI tools may still be recorded. As long as the extension stays installed, it also keeps checking your organization's policy, which updates the last-activity date and the extension version. Uninstalling the extension stops future collection. Neither withdrawing consent nor uninstalling deletes data already sent: for that, see section 11.

7. Data kept on your device

The extension keeps in the browser's local storage, without its own encryption: its installation token, your work email address, your choices, your organization's policy and a queue of events not yet sent.

When sending fails, this queue may contain, for about 7 days, message previews, justifications, file names, the work address used at sign-in and full console addresses with their reduced secret excerpts. The raw copy of the first 4,096 characters, sent for the second analysis, is never put in this queue; of the message text itself, only the 200-character preview can be stored there. The installation token is kept in hashed form on Sorvek's server.

8. Hosting and recipients

Extension data is sent over HTTPS to Sorvek's servers, hosted on Amazon Web Services in the Canada region (Montréal, ca-central-1), where it is stored.

The extension communicates only with Sorvek's servers and, when you sign in with Microsoft, with Microsoft's sign-in service. The data may then be disclosed to the following recipients:

  • your organization's Sorvek console users, according to their role (message previews, justifications and access requests are limited to administrators);
  • the tools your organization connects itself: its SIEM (without message previews or justification text), its notification channels such as Slack or Teams (an access request is sent there with your address, the target and your justification), and the AI assistants it connects to Sorvek's MCP server, which can read previews and justifications;
  • Anthropic, an AI model provider whose servers may be located outside Canada, for some console features: the name and domain of discovered applications, to categorize them; aggregate counters and, if someone with console access asks for them, the profile of named employees with their applications, for the AI assistant; and, if your organization enables it, for the AI audit: the addresses of the employees who sent the most sensitive messages, with their number, plus accounts discovered in applications (address, name, job title, department, last activity), including those detected by the extension at sign-in. Sorvek sends it neither message previews nor justifications.

9. Retention periods

Data typeRetention period
Messages sent to AI tools, files, blocked sites and developer console secrets90 days by default, adjustable by your organization between 7 and 365 days, then automatic deletion. Some copies last longer: console alerts (your address, the tool and the detected types), which are not deleted automatically, and, if your organization connects a SIEM, its sending queue, for about 30 days.
The first 4,096 characters of a messageNot stored: deleted after the analysis
Browsing, services contacted, detected sign-ins, and the applications and accounts discovered from this dataFor the duration of the service. No age-based deletion is scheduled at this time for this data, except for the detailed log of observed sign-ins, which is deleted automatically after 90 days. A discovered application or account may also be removed automatically, for example when it is no longer recognized as a SaaS application.
Extension inventoryList of each device's extensions, including those removed since: for the duration of the service, even after the Sorvek extension is uninstalled or the device is revoked. Change log: 180 days.
Enrollment, consent choices and their history, AI acceptable use policy acceptances, access requestsFor the duration of the service, as an audit trail. No automatic deletion is scheduled.
Technical data and monthly compliance reports (statistics and most exposed employees)For the duration of the service. No automatic deletion is scheduled.
Send queue on your deviceAbout 7 days per event, then deleted without being sent. If the browser is closed or the extension is disabled, the deletion happens shortly after they resume.

At the end of the contract, your organization may request the deletion of all its data. Server backups may contain deleted data for some time. Copies sent to your organization's own tools (SIEM, notification channels) are under its control.

10. Security measures

  • Encrypted transmission over HTTPS.
  • Masking of secrets and some numbers on your device, before the preview is sent (section 3).
  • Second analysis on the server to catch a secret that masking missed.
  • Installation token unique to each device, kept hashed on the server and revocable by an administrator.
  • Console access depends on role: accounts authorized or invited by your organization, and the Sorvek team for support and operations. By default, a person who signs in with a Microsoft or Google account whose email address belongs to your organization's domain may also automatically get basic access (user role), without an invitation, which includes the application and extension inventory.

11. Your rights

Under Quebec's Law 25 and PIPEDA, you can:

  • Access: obtain the data about you collected by the extension.
  • Correction: have inaccurate data corrected.
  • Deletion: request the deletion of your data.
  • Portability: receive your data in a structured, commonly used technological format.
  • Withdrawal of consent: for optional features, as described in section 6.

Send your request to your organization, which is responsible for this data, or to Sorvek at the address below: we will handle it with your organization and reply within 30 days.

12. Contact us

Organization: Sorvek

Person in charge of the protection of personal information: Florent Vinai

Address: Montreal, Quebec, Canada

Email: contact@sorvek.com

If you believe your rights are not being respected, you may file a complaint with Quebec’s Commission d’accès à l’information (CAI) or the Office of the Privacy Commissioner of Canada (OPC).