The on-device approach here is smart - most devs are copy-pasting raw API keys and database passwords into Claude/Copilot without thinking about it, and it's happening thousands of times a day. The fact that you catch this in milliseconds without uploading the prompts is the privacy+security win that's been missing. Hand-written detection rules instead of ML is interesting too - that probably means way less false positives than neural approaches would give you.
For the team dashboard roadmap, the "show signal not content" angle is exactly right for security leads. One question: how does this scale beyond Cursor/Claude/Copilot? What happens when someone uses Aider with Claude, or when custom LLM integrations start proliferating? And are there enterprise deployment options for teams that can't use the cloud dashboard?
Two questions that actually matter for deploying past one laptop.
Coverage: HeimWall watches the surfaces where prompts are entered and where data leaves, not per-tool integrations, for instance: Aider, a custom LLM setup, whatever ships next month gets caught at the same layer instead of needing a new connector each time. Chasing tools one-by-one would be a treadmill; that's the design choice that avoids it. So, HeimWall can catch secrets no matter the platform its written at.
Deployment: yes, a self-hosted/on-prem option for the team layer is on the roadmap, and it's the consistent path since detection already runs fully on-device. It's early access now, so if you've got a team with hard no-cloud requirements, reach out and let's talk specifics.