Help with MoonGate DLP.
MoonGate DLP is an administrator-managed enterprise extension in private beta. It is not a consumer product, and it does not work on an unmanaged Chrome profile by design.
Contact us
We answer support and privacy mail directly. During the private beta this is a small team, not a ticketing desk; replies are best-effort, typically within two business days.
Installation, managed policy, native agent health, enforcement behavior, and beta access.
Questions about the privacy policy, data handling, retention, or a data request.
Prefix the subject with SECURITY. Please report privately and give us time to remediate before disclosure.
Before you file a report
MoonGate requires three things to enforce anything: the extension installed through managed browser policy, the MoonGate native endpoint agent installed on the same machine, and an administrator-issued policy bundle. If any one of them is missing, the extension intentionally reports an unhealthy or non-enforcing state and fails closed.
The extension was installed by hand rather than force-installed through MDM or Google Admin, so there is no managed configuration and no native messaging host. That is expected behavior, not a defect. Contact your IT administrator before contacting us.
Expected behavior
Some things that look like bugs are deliberate design decisions. These are the ones people ask about most.
The toolbar badge reports an unhealthy or non-enforcing state
The badge is backed by native health checks. It reports unhealthy when the endpoint agent is unreachable, when no administrator policy is present, or when the policy signature does not verify. MoonGate fails closed rather than silently permitting protected actions.
Protected actions pause briefly after a policy change
When managed configuration changes, MoonGate holds protected actions until every affected tab acknowledges the new configuration. Affected tabs may be enumerated or reloaded. This is the fail-closed path during reconfiguration.
Enforcement continues with no network connection
Decisions are made locally against a verified, cached policy bundle. Losing connectivity to the control plane does not open the gate; it delays event delivery, which is reported through enforcement health.
A large file was blocked without being inspected
Files too large to inspect within the enforcement budget fail closed rather than bypassing evaluation. Your administrator sets the thresholds in policy.
An action was not intercepted at all
MoonGate is browser-scoped. It is not system-wide DLP and does not cover unmanaged browsers, desktop applications, screenshots, USB devices, or every programmatic network or API path. Native browser-menu print is detect-only today. If the action falls outside browser-observable enforcement, it is outside the current scope — see what we don't claim.
What to include in a report
Every MoonGate decision carries a correlation ID and a policy version. Those two values let us replay exactly why the gate opened or closed, so include them if you have them.
- extension version and Chrome version
- operating system and version
- correlation ID from the decision
- policy version in effect
- action attempted (copy, paste, upload, download, export, share, publish, print)
- source system and destination origin
- expected verdict vs. observed verdict
- enforcement health state shown on the badge
- raw document text or screenshots of protected content
- clipboard contents
- protected files or file bytes
- credentials, tokens, or policy signing keys
MoonGate is built so that protected content never leaves your endpoint. Please don't send us any in a support ticket — the identifiers above are enough to investigate.
For administrators
- Distribution. MoonGate DLP is a Chrome Web Store item intended to be installed through managed browser policy for a managed organizational unit. It is not publicly listed.
- Prerequisites. The MoonGate native endpoint agent must be deployed to the same managed macOS or Windows endpoint, and the managed-storage policy should ship in the same MDM change as the extension.
- Verification. Confirm the extension cannot be disabled, and that native messaging and policy health are active, before testing with protected content.
- Beta status. The current build is scoped to controlled testing with synthetic Google Drive and Notion fixtures. It is not approved for production deployment or real user data.
Beta scope
MoonGate is pre-pilot. The managed extension, Rust endpoint agent, and signed policy control plane are built and verified against synthetic Drive and Notion fixtures. There is no production deployment and no customer pilot yet.
If you're evaluating MoonGate for a design-partner engagement rather than troubleshooting an install, write to support@moongate.tools.