ND4AI
Non-disclosure for artificial intelligence

A free instrument from AI Factories

An NDA that follows your document into the machine.

A standard NDA stops a person re-sharing your file. It says nothing about that person pasting it into an AI that may retain, log, or train on it. ND4AI closes that gap: a binding restriction on the recipient, a visible notice on the page, and a reference marker that can flag when the document is fetched.

Sealed
reference
token

Each agreement is issued a unique reference.
It ties the document notice to the signed NDA.

01 — Agreement

A binding restriction

Fill in the parties and terms. ND4AI builds a full NDA with an explicit clause prohibiting submission of your information into third-party AI systems — enforceable, with injunctive relief and 72-hour breach notice.

02 — Notice

A notice on the page

Paste the generated notice into your document header or footer. It warns the human recipient and asks well-behaved assistant tools to stop processing. Plain-text and HTML versions are provided.

03 — Marker

A reference that reports back

Every agreement carries a unique reference and an embedded marker. When the file is fetched over a link, the canary service logs it and notifies you — detection layered under the contract.

The generator

Build your agreement

Fill in the parties below, generate your NDA, and copy the matching notice and marker into your own files.

Parties & terms

Disclosing party

Where fetch alerts are sent. Registered with the marker only — never embedded in the recipient's copy.

Recipient
Scope and terms
Agreement reference
—

Notice and marker to embed

Generate an agreement to see the document notice and the header marker you paste into your own files.

In plain terms

What this does, and what it does not do

ND4AI is detection and deterrence layered under a real contract. It is honest about its limits — and so are we.

The honest scope

What ND4AI does

  • Binds the human recipient, by contract, not to feed your document into risky AI systems.
  • Gives you injunctive-relief and 72-hour breach-notification terms you can actually enforce.
  • Places a visible notice that some well-behaved assistant tools may honour.
  • Issues a unique reference and marker that can flag when the file is fetched over a link.

What ND4AI cannot do

  • It cannot make an AI obey the notice. Models treat embedded text as data, not commands.
  • It cannot bind the AI or its operator. They are not parties to your agreement.
  • The marker fires on any fetch, so a hit may be a link-preview bot, not an AI.
  • It is detection and deterrence, not prevention. It does not make a document AI-proof.

Try it

Test the reference marker

Simulate what happens when your marker URL is fetched. In production the marker points at your canary service, which logs the request and emails you.

Marker fetch simulator

This runs locally so you can see the shape of a logged event. Leave the demo value to see a simulated log, or point it at your live canary base URL.

no events yet.

For operators

Deploying ND4AI.com

The site is a static front end plus a small canary service. Everything below ships in this package.

Package layout

/  (web root — deploy to ND4AI.com)
├─ index.html  this page
├─ ND4AI_NDA_Template.docx  blank template
├─ robots.txt · sitemap.xml · favicon.svg · og-image.png
├─ .htaccess  Apache routing
└─ canary/  blocked from the web, except app.php
   ├─ app.php  marker, register and hits endpoints
   ├─ lib.php · cli.php · router.php
   ├─ make_pixel.php · pixel.png
   ├─ make_template.php
   ├─ config.example.php
   ├─ deploy/  Caddy · nginx · cron
   └─ README.md

Plain PHP, no Composer packages. Your web server serves this page and the template as static files and hands the marker endpoints to canary/app.php. Markers resolve at https://nd4ai.com/c/<token>.

Run it

cp canary/config.example.php canary/config.php
# edit config.php: secret, mail_from or SMTP, webhook
php canary/make_pixel.php
# dev:
php -S 127.0.0.1:8000 -t . canary/router.php   # :8000
# production: Caddy or nginx + php-fpm (canary/deploy/),
# or Apache — the .htaccess files do the routing
  • Needs PHP 8.1+ with pdo_sqlite. No daemon, no Composer.
  • Serve it over TLS. Caddy and nginx blocks ship in canary/deploy/.
  • POST /register is public — the generator calls it same-origin.
  • GET /hits/<token> stays protected by ND4AI_SECRET (config.php or environment).
  • Set mail_from, SMTP, or a webhook for email/Slack alerts.
  • Records IP + user agent — add a privacy notice and the cron retention job (see README).