This product was not featured by Product Hunt yet.
It will not be visible on their landing page and won't be ranked (cannot win product of the day regardless of upvotes).

Product Thumbnail

HeimWall

Catch secrets before they leak into Cursor & Claude

Mac
Developer Tools
Artificial Intelligence
Visit WebsiteSee on Product HuntTwitterLinkedIn

Hunted byAta Cinar GencAta Cinar Genc

HeimWall catches leaked secrets, credentials, and PII the moment they're about to reach AI coding assistants like Cursor, Claude Code, and Copilot. A lightweight macOS app, fully on-device: 47 hand-written rules flag leaks in real time. Your prompts never leave your Mac. No content stored, no account, no signup. Free for individual engineers. Next up: a team dashboard showing security leads leak trends without exposing what anyone typed. Signal, not content. Design partners welcome.

Top comment

Hey Product Hunt! Ata here, co-founder of HeimWall, launching this together with my co-founder Safak. We're two technical founders building HeimWall AI. Every developer we know has pasted something into an AI tool and frozen for a second: wait, was there a key in that? Usually there was. When we ran our detection engine over DevGPT, a public corpus of 27,075 real developer prompts to ChatGPT, we found three live-format API keys and 49 real personal email addresses in a single weekly snapshot of conversations people chose to share publicly. The prompts nobody shares are the rest of the iceberg. HeimWall catches that moment. It reads the composer of Cursor, Claude Code, Copilot and friends through the macOS Accessibility API and flags secrets, credentials and PII as you type or paste, before anything leaves your machine. 47 hand-written detection rules, benchmarked against public corpora (CredData, Gretel PII). Everything runs on your Mac. No account, no signup, your prompts are never uploaded. A few honest notes, because that's how we try to operate: •⁠ ⁠Detection is a deterministic rule engine, not a model. That's why the whole app is about 7 MB. An on-device semantic tier is on the roadmap. •⁠ ⁠False positives exist. We published our full noise analysis on the blog, including the two rules we already know we need to tighten. •⁠ ⁠The team side (a dashboard where security leads see leak trends without ever reading anyone's prompts) is next. We're onboarding design partners now. We think of this as step one toward observability for the agentic workforce: protect the individual engineer first, then give teams the same signal without the surveillance. macOS 13+, Apple Silicon. Try it, break it, tell us what it missed. Safak and I will be here all day, ask us anything.

Comment highlights

Congrats on the launch!

Two questions:

1) Claude Code runs in a terminal no structured composer for the Accessibility API to read. How do you handle that surface?

2) The bigger leak vector arguably isn’t what the user pastes, but what the agent itself reads and sends to the API (.env files, configs). Is a local proxy layer for agent traffic on the roadmap?

the DevGPT stat sold it, three live keys and 49 emails in one week of public snapshots is a genuinely alarming stat. since detection is rule-based rather than a model, how do you handle secrets with no recognizable format, like an internal API key using a company-specific naming scheme that just looks like a random string? that seems like the hardest case for a pattern-matching approach

The deterministic 7MB rule engine over the Accessibility API is the right tradeoff here — no model means nothing to phone home, which is the whole point for a leak-prevention tool. Since Cursor and Copilot-in-VSCode are Electron, does the composer read stay reliable there, or does the Accessibility tree get flaky compared to a native field like Claude Code in the terminal? And can I add rules for our own internal token prefixes locally, or does expanding past the 47 built-ins need an app update?

One thing I'd love to see is a simple CLI flag so I can pipe clipboard content through HeimWall's rule set from my terminal without opening the app. That way quick checks during code review stay in my flow.

The on-device approach is a big deal for trust. One thing that would help me roll this out to my team is a dry-run mode that lets me see which of my recent prompts would have been flagged, so I can fix habits without the awkward retroactive alerts.

would love to see a quick test mode where i can paste in a sample prompt and see exactly which rules flagged it, basically a way to tune the 47 rules for my own workflows without needing to trigger real leaks in my actual coding sessions

Really like the signal over content approach. One thing that would help me actually roll this out is a one-click allowlist for the specific secret values I know are safe but get flagged constantly, like local Postgres URLs or my dev API keys. Right now I'd imagine false positives get noisy fast. Persistent per-project overrides with maybe an audit log would make this feel less like babysitting and more like a real safety net.

Love that it's fully on-device, finally something that doesn't sell my clipboard to a cloud. One thing I'd want soon though - a way to whitelist my own throwaway test secrets so I'm not hitting the red on every dummy API key I paste in for debugging.

Have you thought about adding a quick toggle in the menu bar to temporarily disable blocking when I intentionally need to paste a real API key during local testing. A 15 minute pause button would save a lot of friction compared to fully uninstalling and reinstalling every time.

Ran it for an afternoon while pushing code through Cursor and it actually flagged a stray API key I had no business pasting in. The "fully on-device" bit sold me, no setup, no signup, just a quiet macOS app doing its job in the background.

love that this stays fully on-device, that was basically the deciding factor for me. one thing though, would be great if you could add a quick toggle to whitelist specific projects or repos, like a dotfile in the project root, so it doesn't flag test fixtures or seed data as real leaks. right now i imagine anyone with mock credentials in their codebase will get noise.

honestly this looks really useful for anyone paranoid about pasting real keys into copilot by accident. one thing i'd love is a quick "why was this flagged" popover when a rule triggers, basically a one-liner explaining which pattern matched so i can learn what to scrub next time. would make the whole thing way less mysterious

the on-device approach is genuinely refreshing, especially with so many tools phoning home these days. one thing that would make this a no-brainer for me would be git hook integration so it can scan staged diffs before they ever reach an AI tool in the first place, catching leaks at the source rather than only at the prompt boundary.

About HeimWall on Product Hunt

Catch secrets before they leak into Cursor & Claude

HeimWall was submitted on Product Hunt and earned 41 upvotes and 37 comments, placing #12 on the daily leaderboard. HeimWall catches leaked secrets, credentials, and PII the moment they're about to reach AI coding assistants like Cursor, Claude Code, and Copilot. A lightweight macOS app, fully on-device: 47 hand-written rules flag leaks in real time. Your prompts never leave your Mac. No content stored, no account, no signup. Free for individual engineers. Next up: a team dashboard showing security leads leak trends without exposing what anyone typed. Signal, not content. Design partners welcome.

HeimWall was featured in Mac (103.6k followers), Developer Tools (516.3k followers) and Artificial Intelligence (474.3k followers) on Product Hunt. Together, these topics include over 194.7k products, making this a competitive space to launch in.

Who hunted HeimWall?

HeimWall was hunted by Ata Cinar Genc. A “hunter” on Product Hunt is the community member who submits a product to the platform — uploading the images, the link, and tagging the makers behind it. Hunters typically write the first comment explaining why a product is worth attention, and their followers are notified the moment they post. Around 79% of featured launches on Product Hunt are self-hunted by their makers, but a well-known hunter still acts as a signal of quality to the rest of the community. See the full all-time top hunters leaderboard to discover who is shaping the Product Hunt ecosystem.

Want to see how HeimWall stacked up against nearby launches in real time? Check out the live launch dashboard for upvote speed charts, proximity comparisons, and more analytics.