Skip to content
decosa

Decosa for Chrome

Your company's systems sit behind a VPN, single sign-on and device checks, so a browser in someone else's cloud can't reach them. Decosa works in your own Chrome, on the tab you're already signed into. It fills the form from your own notes, shows where every value came from, and waits for you before anything is sent.

Status: private beta. The Chrome Web Store listing and the decosa-browser package are being published. Until then we share them with beta users directly: ask for access.

What stays in your hands

  • Every send waits for you. Anything that would save, send, pay or delete is held inside your browser until you press Approve. One approval lets exactly one request through.
  • Every value has a source. Decosa types only what appears in your task or the notes you add, and shows the line each value came from.
  • Your password stays yours. On a sign-in page Decosa hands you the tab, and can't see it until you press Continue.
  • Read-only when you want it. Every write is refused. Your organisation can make this the only mode.
  • A signed record of each task stays on your computer: what the model saw, what it did, and what you approved.
  • It respects sites that forbid tools. Where a site's terms forbid automated tools, you get a copy list to paste from instead.

What we measured

On our own test sites with synthetic data, 29 September 2026:

  • On 48 tasks in a self-hosted Gitea, run twice, it succeeded 95 times out of 96. The same engine running in its own browser succeeded 94 times.
  • It adds about 35 ms per step against running headless.
  • Across 22 runs on pages built to force a submit, no write reached the server without the person's approval.
  • 7 pages with planted instructions for AI caused no harm.
  • In an OpenEMR test clinic it entered 8 of 8 vitals from a visit note correctly, and saved them after one approval.

These runs don't cover real third-party sites or Windows yet.

Install

  1. The extension: from the Chrome Web Store once it's listed. For the beta, open chrome://extensions, turn on Developer mode, choose Load unpacked, and pick the folder we send you.
  2. The helper app, which runs Decosa's engine on your computer (macOS or Linux, Python 3.10+):
    # The decosa-browser helper app is in early access: ask for it at https://decosa.ai/contact?topic=self-host
    decosa-browser install      # registers it with Chrome for you (add --browser edge|brave|chromium for others)
    decosa-browser status
  3. The model: use Decosa's hosted API with decosa-browser setup --key dk_… (get a key), or a model inside your own network in ~/.config/decosa/helper.json:
    {"model": {"kind": "openai-compatible", "base_url": "http://your-model:8000/v1", "model": "qwen3.8-27b", "vision": true}}
  4. Open the site you work in, click the Decosa icon (or press Alt+Shift+D), confirm the site, write the task, add your notes, and press Start. Chrome shows "Decosa started debugging this browser" while it works.

For IT

  • Force-install the extension with the Chrome policy ExtensionInstallForcelist (Jamf, Intune or Group Policy).
  • Configure it through managed policy:
    • the sites it may work on;
    • read-only only;
    • the model endpoint and key;
    • no screenshots leaving the computer;
    • hash-only records;
    • the name recorded on approvals;
    • whether coding agents may ask.
  • Install the helper system-wide, with its native-messaging manifest in /Library/Google/Chrome/NativeMessagingHosts/.
  • Health data: Decosa has no BAA today. Point the helper at a model inside your network, so nothing reaches Decosa.

Privacy policy · Open source under Apache-2.0 (the source is published with the release) · Contact