The Chrome extension is on the Chrome Web Store
CloakAPI 0.1.58 was published to the Chrome Web Store on 2026-09-29. It is the same build as the zip on Downloads: version 0.1.58, sha256 cc4151794b92…, 18,595,484 bytes.
- Install from the store listing and Chrome keeps it up to date. The same listing installs in Edge and Brave (in Edge, allow extensions from other stores). There is no separate Edge Add-ons listing.
- The zip on Downloads is still there for a developer-mode install. A zip install does not update itself.
- Firefox: no build is offered. The Firefox download answers HTTP 410.
- Older versioned Chrome zips, 0.1.23 to 0.1.57, answer HTTP 410.
Version numbers on this page are a record of the day they were measured, not a live status field. The release-integrity register is the authority for what is served right now.
Desktop 1.2.6 for Windows and Linux
Desktop 1.2.6 was published on 2026-09-26: Windows (portable .exe, NSIS setup, MSI) and Linux (AppImage, .deb). It is the current desktop build.
- Changed: when your prepaid balance is empty, the sample call now says the balance is empty and that no call was made, instead of reporting that the service is starting up.
- Not code-signed. Windows may show “Windows protected your PC” on first run. Check the SHA-256 on Downloads or in the register before you run it. No macOS build is listed.
- Earlier 1.2 builds: Windows 1.2.0 to 1.2.3 were published in September; there is no 1.2.4 build. Windows and Linux 1.2.5 were published on 2026-09-26, the same day as 1.2.6. They remain downloadable as archive builds and none is code-signed. Windows 1.0.0 stays withdrawn (HTTP 410).
Version numbers on this page are a record of the day they were measured, not a live status field. The release-integrity register is the authority for what is served right now.
Chrome extension 0.1.52 to 0.1.58: Claude, Grok and Gemini fixes
Seven builds shipped on 2026-09-26. 0.1.58 is the one on the Chrome Web Store and on Downloads; 0.1.52 to 0.1.57 were each withdrawn when the next one shipped (HTTP 410).
- Claude: chats no longer false-block on receive-only EventSource traffic (0.1.52), and binary attachments are cloaked before upload (0.1.54).
- Grok: attachment hangs clear (0.1.53, 0.1.56). Grok chat works again after the site moved to a WebSocket path (0.1.57), and the connection handshake no longer stalls (0.1.58).
- Images and Gemini: cloaked images work for Claude and Grok, failed-attach notices clear, and Gemini plain-text length handling is corrected (0.1.55).
- The release feed lists 0.1.57 and 0.1.58 as privacy-critical. If you installed from a zip, download the current one; a zip install does not update itself. Keep only one CloakAPI install enabled.
Notes and severity for every build are in the release feed.
Chrome extension 0.1.33 to 0.1.51: protection fixes, ChatGPT and Gemini reliability
Nineteen builds shipped between 2026-09-21 and 2026-09-25. Each was withdrawn (HTTP 410) when the next one shipped. The main changes, from the release feed:
- Protection: 0.1.33 keeps the “send with the layers already loaded” choice on screen and carries the detection engine the gateway accepts (the engine in 0.1.32 was one it does not accept, so sends through the gateway could be rejected). 0.1.37 tokenises text fields in uploads and form posts, and text sent as binary WebSocket frames, instead of blocking the send or forwarding it unchanged. 0.1.38 protects ChatGPT when you are logged out and detects names again when the name models load.
- ChatGPT and Gemini: background requests no longer open the review panel or the “Protection is OFF” notice (0.1.39); Enter sends again on logged-out ChatGPT (0.1.40); logged-out Gemini sends no longer hang (0.1.47); on Gemini only your own text is tokenised and Copy restores your original details (0.1.48).
- Receipts and popup: every send now stores a receipt on your device (0.1.42), and the popup describes deleted or missing receipts, and a chain check that could not run, accurately (0.1.46, 0.1.50). 0.1.48 opened the popup only 25 px wide; 0.1.49 fixes it.
- Small windows and accessibility: the settings page and popup fit 360 px windows (0.1.34 to 0.1.36); the review dialog works with screen readers and Escape sends with your details cloaked (0.1.41); options and onboarding controls meet the 24 px touch target (0.1.51).
- Honest copy: messages that promised more than the extension does now say detection is best-effort (0.1.40), and help text says a file the extension cannot read is sent unchanged and you are told so (0.1.45).
Notes and severity for every build are in the release feed.
Chrome sideload zip was 0.1.32 on this date
Update, 2026-09-29: superseded. 0.1.32 now answers HTTP 410 and the Chrome extension is on the Chrome Web Store (0.1.58); see the 2026-09-29 entry. The rest of this entry records 2026-09-21.
Measured on 2026-09-21: cloakapi-extension-chrome-0.1.32.zip and the unversioned cloakapi-extension-chrome.zip both answer HTTP 200 and are the same 18,561,128-byte artefact (identical sha256). Version numbers on this page are a record of the day they were measured, not a live status field — the release-integrity register is the authority for what is served right now.
- Download on 2026-09-21:
cloakapi-extension-chrome-0.1.32.zip and unversioned cloakapi-extension-chrome.zip (HTTP 200, measured 2026-09-21).
0.1.31 joins 0.1.23–0.1.30 in answering HTTP 410. Firefox XPI remains withdrawn (HTTP 410).
- On 2026-09-21 the Chrome Web Store and AMO listings were not live; sideload from Downloads.
Chrome sideload zip was 0.1.31 on this date
On 2026-09-20 the served Chrome extension zip was 0.1.31, and the unversioned filename cloakapi-extension-chrome.zip pointed at the same artefact. That version has since been superseded and now answers HTTP 410 — see the 2026-09-29 entries for what is served now. This page does not restamp sha256 or signing status; those are the values in the release-integrity register, which is the authority for what is current.
- Download on 2026-09-20:
cloakapi-extension-chrome-0.1.31.zip and the unversioned cloakapi-extension-chrome.zip (HTTP 200, measured that day).
- Older versioned Chrome zips
0.1.23 through 0.1.30 (including the previously advertised 0.1.24) answer HTTP 410. Firefox XPI remains withdrawn (HTTP 410).
- On 2026-09-20 the Chrome Web Store and AMO listings were not live; sideload from Downloads.
Name tokenisation is always on — with a review step before sending
On-device name tokenisation is now always on for everyone, free included. Names are replaced with stand-ins on your device before anything leaves it, and you can review exactly what gets replaced before a message is sent.
- Always-on name tokenisation for every user — no setting to forget. Names the on-device detector does not recognise can still slip through; when it detects a name it cannot place in the text, that span is skipped and the send is not blocked.
- Review before sending shows every detected item and lets you add anything we missed or remove anything you'd rather send as-is — you decide before it leaves your device.
- For the widest name coverage, an optional on-device AI model catches more names than the built-in list.
Files and images are now tokenised on your device — in the SDKs, API, and MCP
You can now send files and images through the SDKs, the API, and the MCP server. Text is extracted on your device — OCR for images, parsing for PDF, DOCX and XLSX — and personal data is tokenised before anything is sent. Extraction and tokenisation run on your device, and the gateway relays the body your device produced. It is content-blind — it does not inspect what it forwards — so what reaches the provider is what your device sent.
- One method handles images, PDFs and documents; extraction and tokenisation run entirely on-device.
- A built-in name list gives baseline coverage with no model to load; the optional neural model is recommended for the best name detection.
- Same on-device path as text: this path does not upload the raw bytes.
The gateway is now a pure blind token relay
Now that tokenisation runs on the customer side across every way of using CloakAPI, the gateway no longer does any content processing of its own — it is a literal blind byte relay. Detected values are replaced on the device before a request reaches the gateway; the gateway relays those bytes without a second detection pass.
- Removed the server-side detectors, the Presidio pass, and the residual-scan 422 enforcer from the gateway: it no longer inspects, detects, or tokenises content on our servers.
- The gateway forwards only what your device sends, signs the receipt, and meters token counts — never content. Billing reads provider-returned usage, not your prompts.
- To tokenise with a plain SDK, point it at the local proxy (Quickstart Option C) so tokenisation stays on your own machine — the gateway blind-relays whatever it receives.
CloakAPI Chat — a private front door you can try without signing up
A client-side chat is now the easiest way to try CloakAPI: open it, type, and personal data is tokenised in your browser before anything is sent. Streaming replies, no account required to start.
- Try free, no signup — an anonymous demo pool is available immediately, protected by per-IP and global daily caps so it stays up for everyone.
- Names, emails, and IDs are tokenised on your device before the request is sent; the gateway is a blind token relay that forwards what the browser produced and does not detect or re-identify on our servers.
- Streaming responses, token by token.
- Register and verify your email to activate the $2 trial credit for account-backed use.
Local proxy, browser extension, and Complete-local desktop
Three ways to keep tokenisation on your own machine — the proxy and extension replace detected values before the request is sent (and in the desktop app's Complete-local mode, the model runs on your own hardware). The homepage now lays out the three ways to use CloakAPI side by side.
- Local proxy (drop-in): point your OpenAI- or Anthropic-compatible SDK at a localhost port and PII is tokenised on your machine by the native Rust engine — only tokens leave. Default port 8799, configurable via CLOAK_PROXY_LISTEN.
- Local proxy ships as a Docker image and a Linux binary on the downloads page; macOS and Windows builds are coming soon via CI.
- Browser extension: files you attach to claude.ai (pdf / docx / xlsx) are extracted and tokenised in your browser before the request is sent. Store listings are pending review; sideload builds are available now.
- Desktop app adds a Complete-local mode — the model runs on your own hardware — alongside the existing Gateway mode. Windows build refreshed; macOS and Linux via CI.
- Homepage gains a first-class "Three ways to use CloakAPI" section: API (drop-in proxy / SDK), Chat (browser chat, with the desktop app as a power-up), and the browser extension.
Pre-tokenised passthrough, fail-closed backstop, and wider coverage
The gateway now trusts client-tokenised traffic end to end — issuing receipts and billing without ever tokenising or storing raw PII itself — while adding a fail-closed backstop for anything that still arrives with personal data in the clear.
- Pre-tokenised passthrough: traffic already tokenised on your device gets a receipt and metered billing, with the gateway relaying only tokens.
- Fail-closed backstop: if the gateway still detects raw PII in a sensitive category, it blocks the request rather than forwarding it, and monitor-alarms the rest — defence in depth.
- International coverage hardened across roughly 20 markets — national IDs, tax and VAT IDs, IBAN, cards, and phone numbers are tokenised with the correct categories.
- Honest privacy wording across the site: personal data is tokenised on your device; the gateway relays only tokens and blocks detected raw PII.
- Fixed: the $2 signup trial credit is now reliably granted on email verification.
Launch readiness sweep — iter-14
Nine-wave audit run the day of open access. Every finding was fixed, dispatched, or gated behind a feature flag. Zero fake company names, zero fixture credentials, zero hardcoded numbers remain in user-visible code.
- Receipt verifier shipped on signedreceipts.org — valid, tampered body, swapped signature, and expired-key cases all return the correct HTTP status + reason code.
- 4 backend gaps closed: compliance-pack lifecycle, audit-log filter + CSV export, transparency-log toggle + auto-advance, privacy-tier preview / cancel / commit state machine.
- IP allowlist enforcement on API keys — CIDR validation, per-request middleware, audit-log event on block.
- Sanctum abilities + Spatie permissions on 63 mutation routes — read-only tokens correctly 403 on writes.
- F1–F6 auth flow audit — invite-signup security holes patched: token consumption, email/token binding, expiry enforcement.
- Concurrent dashboard sessions — 10-token retention window + 30-day stale-prune scheduled task.
- SES outbound mail in production — Stockholm region; DMARC alignment via custom MAIL FROM mail.cloakapi.io.
- Stripe live keys + webhook endpoint with HMAC signature verification.
- Trust portal: CAIQ-lite, SLA, BCP, and insurance-status pages published.
- HIPAA data-minimisation primer published.
- Threat model, key-rotation policy, transparency-log spec, detection-coverage doc, and reproducibility roadmap published at docs.cloakapi.io/security/threat-model/.
- OpenReceipt in-browser JS verifier live on signedreceipts.org (Apache-2.0); conformance suite documented. Reference-library source distribution is still being prepared — see signedreceipts.org/source.
- A Chrome sideload zip was listed as 0.1.23 on this date. That filename now answers HTTP 410. Status as of 2026-09-29: the Chrome extension is on the Chrome Web Store (0.1.58, see the 2026-09-29 entry); the Firefox download answers HTTP 410; the current desktop build is 1.2.6 for Windows and Linux, not code-signed, with no macOS build listed. The release-integrity register is the authority for what is current.
- Mobile-responsive portal shell — sidebar collapses below 768 px with hamburger toggle.
- 30+ admin and portal surfaces stripped of fixture data; empty states show graceful copy.
- Fake compliance-auditor claims removed from /trust — now honest "not yet engaged".
Pre-launch sweep — iter-13
Wave-5 walkthrough preparation: role-based test accounts seeded and two auth regressions fixed ahead of the iter-14 launch-readiness run.
- 11 role-based test accounts seeded (admin, owner, billing, developer, read-only, partner-L1/L2, API-only, SSO-only, auditor, org-member).
- Admin gate fixed — user.roles array threaded through shapeUser(); admin layout now reads it correctly.
- Login race condition fixed — await invalidateAll() before goto('/dashboard') prevents stale-data layout bounce.
Production deployment — Hetzner CX43, Nuremberg
All seven public subdomains go live on dedicated bare-metal in Nuremberg. SES SMTP, Cloudflare DNS, and TLS certs provisioned in a single pass.
- Initial deployment of gateway, portal, docs, signedreceipts.org, status, demo, and marketing-site containers.
- SES SMTP wired — Stockholm region, custom MAIL FROM, SPF + DKIM + DMARC aligned.
- Cloudflare DNS configured for the full cloakapi.io zone.
- TLS certificates issued for all subdomains via Let's Encrypt.
Trust
DPA, sub-processor list, and trust portal first cut
trust.cloakapi.io ships the full GDPR Article 28 DPA template, a 21-row sub-processor list with change-notification subscription, and the live per-tenant transparency-log toggle (opt-in / opt-out in settings).
Portal
Onboarding wizard + privacy posture model
Six-step onboarding wizard shipped with provider validation and API-key generation at the final step. Privacy posture model (Max / Balanced / Continuity / No Tokenization) lands as the first configurable privacy tier in the portal.