Data Sovereignty: Not Your RAM, Not Your Data

Redact PII from AI Prompts, Files & Documents Before ChatGPT, Claude or Gemini See It

The Air-Gapped AI Data Loss Prevention (AI DLP) Engine. Redact sensitive entities like [FINANCIAL_DATA] before LLMs store it.

AI models never forget — data in training weights or RAG vector lakes cannot be deleted. PrivacyScrubber executes 100% in local RAM with zero network packets, zero server logs, zero subprocessors.

Protects:Spreadsheets (.xlsx, .csv)Resumes & Contracts (.docx, .pdf)Databases (.sql, .json)Secrets (.env, .yaml)

PII Sanitization Tool

STEP 1

Input

ZTDS™ VERIFIEDRAM:<1ms·0 B
Sample: HR / General
HIRING REVIEW > Candidate: Sarah Mitchell Email: s.mitchell@talent.io | Phone: +1 (415) 555-0182 Salary Expectation: $165,000.00 | SSN: 987-65-4321 Resume score: 94/100 — Shortlist for Senior Lead role.
Attach File (.docx, .xlsx, .pdf)
Upload documents (.pdf, .docx, .xlsx, .csv, .txt) or scan images with on-device OCR in RAM.
100% Offline
Paste Clipboard
Insert text from your clipboard directly into local RAM without saving to disk.
Instant Input
Custom Rules
Define your own detection rules to detect account numbers, internal codes, and custom PII patterns.
PRO Feature
AI NER (35MB)
Deep contextual NER model to detect complex names, organizations, and locations in RAM.
PRO Feature
0 / 15k
STEP 2

Sanitize Before AI

HIRING REVIEW > Candidate: [NAME_1]Sarah Mitchell Email: [EMAIL_1]s.mitchell@talent.io | Phone: [PHONE_1]+1 (415) 555-0182 Salary Expectation: [FINANCIAL_1]$165,000.00 | SSN: [ID_1]987-65-4321 Resume score: 94/100 — Shortlist for Senior Lead role.
STEP 3

Open in AI

1-Click Launch · Auto-Pastes Clean Prompt
STEP 4Paste AI Response → Reveal Original Data
1-Click Reveal Zero Server
Memory Standby
0 tokens in RAM
Test reveal instantly without switching tabs:
Paste AI response with tokens & click Reveal Original Data to restore original data in local RAM.
Need colleagues to reveal originals? Hand off encrypted session with zero shared servers (TEAMS $99/mo).
Safe Copy Ready Prompt Copied! [NAME_1], [EMAIL_1] securely tokenized in local RAM.

"We run this before every ChatGPT session. Our InfoSec team was satisfied in one audit."

— Marcus T., Lead Compliance Engineer · European Fintech (400 employees)

"Finally — a PII tool that doesn't route my data through someone else's cloud."

— Jordan K., Senior DevOps Engineer · US Healthcare SaaS

"Used this to pass our SOC 2 AI-prompt review. The offline verification is the proof point."

— Priya N., Head of Legal Ops · Series B SaaS, 200 seats

Regulatory Blueprints & Document Workflows

Sanitize High-Liability Documents Before Submitting to Enterprise AI Models

Eliminate PII, PHI, financial ledgers, and trade secrets in local RAM. Select your document type below for verified field-by-field redaction matrices and safe AI prompts.

GLBA • PCI DSS

Finance, Underwriting & Banking

Prevent customer account numbers, SWIFT MT103 instructions, and payroll records from leaking into training corpora.

Zero-Metadata .xlsx Export Finance Hub
FRE 502 • Privilege

Legal Counsel & Court Discovery

Preserve attorney-client privilege under Federal Rule of Evidence 502. Neutralize case numbers and party names.

100% In-RAM Rasterization Legal Hub
HIPAA • 18 Safe Harbor

Healthcare & Life Sciences

Comply with HIPAA 45 CFR § 164.514 Safe Harbor. Mask MRNs, patient names, and dates while preserving clinical symptoms.

BAA Legally Waived Medical Hub
EEOC • GDPR

HR, Recruiting & Compensation

Conduct blind resume screening and salary benchmarking without injecting protected class identifiers or leaking payroll.

Anti-Bias Redaction HR Hub
SOC 2 • ISO 27001 • MCP

DevOps, Secrets & Autonomous AI Coding Agents

Protect internal API keys, database dumps, and cloud infrastructure secrets from entering LLM context windows in Cursor, Windsurf, Claude Code, and Copilot.

Stdio Local Streaming • 0ms Proxy Latency DevSecOps Hub
File-Level Deep Inspection • ZTDS Standard

Zero-Metadata Engine Breakdown: What PrivacyScrubber Strips Beyond Visible Text

Visual redaction alone leaves organizations exposed to court subpoenas and LLM data extraction. Real enterprise documents store deep internal XML structures, revision histories, and hidden text layers that cloud AI parsers automatically ingest.

.DOCX • .XLSX

OpenXML Package Dissection

Word and Excel files are ZIP archives storing internal XML trees. Naive text deletion leaves metadata intact.

docProps/core.xml & app.xml
Stripped: Author usernames, company name, revision count, total editing minutes, template lineage.
word/comments.xml & w:del
Stripped: Uncommitted track changes, reviewer feedback, and deleted text passages.
xl/workbook.xml & calcPr
Stripped: Cached formula values, hidden sheets, internal UNC network paths (\\corp-nas\payroll).
Clean XML re-bundled in RAM via JSZip
.PDF (WASM)

Vector Stream & Text Layer Erasure

Court discovery exhibits and medical records demand the Anti-Manafort standard: 0 underlying text traces.

Tj & TJ Glyph Operator Streams
Obliterated: In Blackout mode, text operators are destroyed at the byte stream level, preventing clipboard extraction.
/Metadata & Info Dictionary
Stripped: Scanner serial numbers, printer GUIDs, PDF producer software, and embedded XML schemas.
Form Fields & JavaScript Streams
Purged: AcroForm interactive fields, annotations, embedded scripts, and hidden non-rendered PDF layers.
Court-proof: pdftotext returns 0 bytes under blackout
OCR • EXIF

Raster Burn-In & Hardware EXIF Purge

Mobile snapshots of driver licenses, invoices, and hospital intakes contain latent geolocation and hardware stamps.

EXIF / GPS / IPTC Metadata
Stripped: GPS coordinates (home/office latitude/longitude), camera model, device serial, timestamp.
Multimodal Burn-In Redaction
Overwritten: Solid blackout pixels or token badges are burned directly into bitmap canvas raster memory.
Zero Cloud Vision API
Zero-Egress: Local Tesseract WASM extracts bounding boxes in RAM. 0 bytes ever sent to cloud vision endpoints.
ExifTool clean • Safe buffer deallocation
CISO Verification MatrixAir-Gapped Standard Parity
File Security VectorLegacy / Cloud Redaction ToolsPrivacyScrubber ZTDS Engine
Visible PII Text (Names, SSNs, Accounts)Replaced visually on screenReplaced in-memory with reversible AI tokens or blackouts
Underlying PDF Text Layer (Anti-Manafort)Retained under black rectangles (extractable by AI)Physically destroyed from Tj/TJ vector streams
DOCX/XLSX Author & Company MetadataPreserved in docProps/core.xmlPurged 100% prior to native file export
Track Changes & Deleted CommentsStored in hidden XML revision tagsCompletely stripped from ZIP container
Camera EXIF & Smartphone GPS DataKept in image headers, leaking coordinatesEXIF dropped, raster burned in on HTML5 Canvas
Network Egress & Server StorageUploaded to remote cloud proxy / API server0 bytes sent to network • 100% in local RAM (Airplane Mode)
In-RAM Document Sanitizers

Direct File Format Engines (Zero Cloud Upload)

Evidentiary Sovereignty Manifesto

Which Side of AI Security Are You On? Paper Promises vs Physical Data Sovereignty

Not your RAM, not your data. The fundamental divide between signing legal contracts to allocate post-breach liability versus enforcing mathematical zero-egress before generative models ever see raw text.

Model A • Legacy Cloud Security

Paper Compliance

Post-Breach Liability

Organizations rely on Data Processing Agreements (DPAs), Business Associate Agreements (BAAs), and trust declarations from cloud proxy vendors (Skyflow, Presidio Cloud, AWS Comprehend).

Continuous Third-Party Egress

Unredacted prompt text, client IDs, and financial records transit across external fiber cables to intermediary vendor cloud servers.

Residual Cloud Custody & Subpoena Risk

Ephemeral cloud caches, server crash logs, and worker heaps remain vulnerable to insider threats, infrastructure compromises, and CLOUD Act warrants.

Procurement Drag (6–8 Weeks)

Requires exhaustive InfoSec supplier questionnaires, subprocessor chain audits, and legal review of third-party indemnification caps.

Reactive Financial Exposure

When a cloud subprocessor leaks, the DPA only defines who pays the lawyers. Average IBM Cost of a Data Breach: $4.88M.

Operational Stance: Trust Promises • Sue Post-Breach
Model B • ZTDS™ Open Standard

Physical Data Sovereignty

Zero Egress Immunity

Organizations rely on deterministic CPU tokenization isolated in local workstation RAM (IETF draft-sibiryakov-ztds-protocol).

Strict Zero-Byte Network Transmission

Raw text never hits the network adapter. All tokenization, Luhn checks, and redactions complete inside browser V8 RAM in <2ms.

Mathematical Immunity to Subpoena & Leaks

No cloud server holds your cleartext session map. It is mathematically impossible to breach, leak, or subpoena data that was never transmitted.

0-Day Procurement (DPA Legally Waived)

PrivacyScrubber is not a Data Processor under GDPR Art. 4(8) or HIPAA. InfoSec and Legal grant immediate clearance without 6-week vendor delays.

Empirical Verification (Airplane Mode)

Fully functional with Wi-Fi disabled. Inspect Chrome DevTools Network tab: exactly 0 requests and 0 bytes transferred.

Deep Zero-Metadata Office Sanitization

Beyond visible text, our in-RAM engine purges hidden XML properties (docProps/core.xml, wb.Props), wiping authors, corporate tags, and revision history in DOCX and XLSX before download.

Operational Stance: Mathematical Proof • Hardware Isolation
The 2026 Irreversibility Trap • EU AI Act Article 10

Why Data Deletion from Frontier LLMs is Impossible

Once sensitive data enters an AI model or enterprise RAG vector store, it cannot be selectively deleted—machine unlearning remains unsolved. Network gateway DLPs miss encrypted WebSockets and streaming SSE tokens. PrivacyScrubber enforces source-level sanitization in local RAM before transmission, satisfying EU AI Act governance and DORA resilience mandates.

Do Not Trust Our Word. Audit Your Own RAM in 60 Seconds.

Press F12 → Disconnect Wi-Fi → Scrub any document or prompt. Prove zero bytes leave your machine.

In-DOM AI Gateway

Sanitize AI Prompts Before They Leave Your Browser In-Page Real-Time Protection on ChatGPT, Claude & Gemini

Automatically detect and tokenize customer names, API keys, medical notes, and financial data directly inside your AI chat window. 0ms network latency — 100% local browser RAM processing.

Desktop AI Shield
★ 5.0 CWS

Zero-exfiltration prompt sanitization directly in your AI chat window

Intercepts names, emails, cards, and keys in local RAM before prompt transmission to LLMs. Zero server logs.

ChatGPT Claude Gemini Copilot DeepSeek
Desktop AI Shield · MV3

In-Page Prompt Sanitizer for ChatGPT, Claude & Gemini

Air-gapped client-side interception inside your AI text inputs. Customer identities, credentials, medical notes, and financial records are sanitized in local RAM before prompt transmission.

In-Page Auto-Detection (9 LLMs)

Native injectors for ChatGPT, Claude, Gemini, Copilot, DeepSeek, Perplexity, Poe, HuggingFace, and Mistral.

1-Click Reverse Reveal in Chat

Instantly swaps tokens in the AI response back to original names and data directly in your browser.

100% Offline RAM & ZTDS Receipts

30 industry profiles (HIPAA, GDPR), custom regex rules, and cryptographic audit receipts with zero server telemetry.

Add to Chrome — Free (★ 5.0 CWS)
Free Forever · Installs in 5sArchitecture & Docs
Manifest V3
0-Byte Egress
Local RAM (<1ms)
★ 5.0 CWS Rated
gemini.google.com
PrivacyScrubber detects sensitive items in the prompt

Step 1: Detection

Step 1 of 4

Type or paste your text normally. The extension instantly detects sensitive data like names, emails, or IDs right inside the text box.

Zero-Trust Industry Architecture

How Teams in Finance, Healthcare & Legal Remove PII Before AI

See how PrivacyScrubber anonymizes data for each industry — step by step. Every action runs in local browser RAM with zero server contact.

Risk: Hardcoded Secrets & DB DumpsAvg Breach: $4.9MTarget: In-Process SDK & MCP

In-Process Interception: APIs, DB Dumps & RAG Vector Lakes

Developers and AI agents pipe crash dumps and customer records into LLMs, leaking AWS credentials, JWTs, and consumer PII. The Developer SDK and MCP Server act as an autonomous consumer privacy fiduciary—intercepting sensitive entities at the application boundary in <1ms local RAM before transmission, vector indexing, or logging.

devops_crash_log.log
// Raw text pasted into Cursor/ChatGPT
Error connecting to DB: postgres://admin:superSecretPass2026@prod-db.internal:5432/customers
AWS_KEY: AKIA4X9M2PLRT887NNZZ
// Tokenized in client RAM with Zero Network Transmission
Error connecting to DB: postgres://admin:[PASSWORD_1]@prod-db.internal:5432/customers
AWS_KEY: [API_KEY_1]
// 1-Click Reveal rehydrates original DB credentials on your machine
LLM Solution: Fix connection pooling for postgres://admin:superSecretPass2026@...
"Security analysts tokenize IP addresses, credentials, and hostnames from incident logs locally before running AI root-cause analysis — zero data exposure to cloud APIs."— OSCP Security Analyst • Cloud Infrastructure Team
Risk: PCI-DSS v4.0 & GLBAPenalties: Up to $100k/moTarget: Extension & Web

Zero-Server Sanitization for PAN, IBAN & Wire Transfers

Financial analysts modeling client portfolios or summarizing bank statements risk exposing primary account numbers (PAN) and SWIFT codes. PrivacyScrubber uses Luhn-verified sanitization locally in RAM before transmission.

wire_instruction.txt
// Sensitive wire transfer pasted for LLM review
Wire $450,000.00 to Robert Chen (Acct: 4532-0151-8879-2241, IBAN: US948123490019283, SSN: 203-44-8821).
// Luhn-verified PAN sanitization with contextual token consistency
Wire [FINANCIAL_1] to [NAME_1] (Acct: [CARD_1], IBAN: [IBAN_1], SSN: [SSN_1]).
// AI generates audit memo → Reveal rehydrates real numbers locally
LLM Audit Report: Verified authorization for Robert Chen ($450,000.00) with Goldman Sachs.
"GRC teams sanitize financial reports and operational files offline before AI-powered audit prep — no vendor database storage, no scope extension for external auditors."— Fintech GRC Team • SOC 2 & ISO 27001 Readiness
Explore Financial Compliance
Risk: HIPAA 18 IdentifiersStatutory Fine: $1.9MSafe Harbor Certified

De-Identify EHR Notes & Clinical Diagnostics

Physicians and clinicians summarize EHR records and patient histories without waiting months for signed BAA agreements. PrivacyScrubber implements the HIPAA Safe Harbor standard 100% in local browser RAM.

clinical_chart_ehr.txt
// Unredacted clinical chart
Patient: Sarah Jenkins (DOB: 1984-05-12, SSN: 042-88-9124). Admitted for acute bronchitis. Primary: Dr. Gregory House. Policy #BC-99214.
// 18 HIPAA identifiers tokenized locally in RAM
Patient: [NAME_1] (DOB: [DATE_1], SSN: [SSN_1]). Admitted for acute bronchitis. Primary: [DOCTOR_1]. Policy [POLICY_1].
// AI generates diagnostic plan → Reveal rehydrates patient identity locally
Clinical Care Summary: Recommended antibiotic dosage plan for Sarah Jenkins under care of Dr. Gregory House.
"Clinical teams strip all 18 HIPAA Safe Harbor identifiers from patient notes in browser RAM before using AI summarization — transforms PHI into Safe Harbor de-identified tokens in local browser RAM before transmission."— Clinical Informatics • PHI De-Identification
Risk: EEOC Bias & Candidate PIIGDPR Employee DataTarget: Batch CSV / DOCX

Blind Resume Screening & Bulk Salary Anonymization

HR practitioners analyzing payroll compensation or screening resumes risk leaking salaries and introducing gender/racial bias into AI models. Bulk offline file processing strips identifiers before AI analysis.

candidate_screening.csv
// Candidate resume and compensation history
Candidate: Emily Watson (Email: emily.w@enterprise-tech.io, Salary: $165,000/yr, SSN: 019-48-2910).
// Anonymized profile for bias-free LLM skill evaluation
Candidate: [CANDIDATE_1] (Email: [EMAIL_1], Salary: [SALARY_1], SSN: [SSN_1]).
// AI produces skill ranking → Reveal rehydrates contact details locally
Unbiased Assessment: Candidate Emily Watson meets all L6 Engineering leadership qualifications.
"HR teams batch-anonymize resumes and compensation tables in local memory before feeding to LLMs for skill evaluation — eliminating unconscious gender/ethnic bias and protecting employee GDPR rights."— Head of People Ops • Enterprise Talent Acquisition
Bulk File Sanitizer (PRO)
Architecture: Two-Tier Fleet GovernanceISO 27001 & SOC 2Teams Hub ($99/mo)

Two-Tier Fleet Governance: Central CISO Lock + Local Flexibility

Employees will use generative AI regardless of corporate bans. PrivacyScrubber solves the Shadow AI paradox through a two-tier architecture: Central security officers enforce mandatory regex rules, while employees retain local agility.

Tier 1: Central CISO Hard Lock
Deploy non-negotiable MDM regex rules via Chrome Enterprise. Mandates zero-tolerance blocking for PAN, SSN, API secrets, and proprietary project codes across 10,000+ browser seats.
Tier 2: Local Worker Agility
Engineers and analysts create ad-hoc local sanitization rules for active client projects on the fly, eliminating IT friction and helpdesk change tickets.
Encrypted Handoff via XChaCha20-Poly1305 + Argon2id
Zero-Knowledge Guarantee
"VP InfoSec teams deploy locked Team Blueprints that enforce identical sanitization profiles across 500+ employees — preventing shadow AI data leaks organization-wide."— VP InfoSec & CISO • Enterprise AI Governance
·CISO Blueprint
Verifiable Zero-Trust & Regulatory Coverage

Verify Zero Data Transmission in 60s & Comply with GDPR, HIPAA, SOC 2 & EU AI Act

No auditor or vendor trust needed. Open DevTools to prove PrivacyScrubber sends zero network requests with your data — backed by turnkey statutory compliance for enterprise LLM deployments.

60-Second Proof of Zero Transmission

Independent DevTools verification protocol for InfoSec & SecOps

Airplane Mode Verified
1
Open DevTools

Press F12 or right-click → Inspect

2
Network Tab → Clear

Click the Clear icon to reset active request log

3
Airplane Mode (opt)

Cut Wi-Fi — engine runs 100% offline

4
Paste → Protect

Watch Network tab as text is tokenized

5
Audit Result: 0 Network Requests with PIIVerified

Zero bytes egressed to external endpoints — full mathematical guarantee of zero data leakage.

Network:0 requests|0 B transferred
Architectural Objection Defense

6 Tough Questions Security Architects Ask Us

Direct technical answers addressing the core questions evaluated by CISOs, security researchers, and enterprise review committees.

01Why not Presidio or cloud NER models?
Cloud NER sends raw text to remote servers, violating Zero-Trust before masking occurs. ZTDS executes deterministic lookaround regexes locally in RAM (<1ms) with zero cloud leaks.
Deterministic RAM Engine · 0ms Network Hops
02How is browser memory protected from extraction?
PrivacyScrubber operates under strict CSP (script-src 'self') with zero external scripts. The volatile sessionMap is strictly tab-isolated, never stored on disk or cookies, and wiped on tab close.
Volatile V8 Heap · Zero Persistence
03What happens if generative AI alters synthetic tokens?
Our patent-pending engine uses Tolerant Fuzzy Unscrubbing to handle model case changes, whitespace shifts, and markdown styling. Omitted tokens are flagged in the local audit log without corrupting text.
Algorithmic Fuzzy Reveal · U.S. & Int'l Patents Pending
04How does InfoSec audit compliance without central servers?
PrivacyScrubber generates cryptographically verifiable CISO receipts (SHA-256 hash, entity count) directly on-device. Enterprise teams stream zero-PII telemetry locally to internal SIEMs (Splunk, Datadog) via our Node.js SDK and MCP.
Local SHA-256 Proof · Zero-PII SIEM Webhooks
05Why use ZTDS if our enterprise signed an Azure OpenAI or ChatGPT Enterprise BAA?
Enterprise BAAs and DPAs establish who pays the lawyers and regulatory fines after an incident, but they cannot prevent raw customer IDs, trade secrets, and API keys from landing in cloud provider crash logs or being reached via CLOUD Act subpoenas. A paper contract protects legal counsel during discovery; physical ZTDS ensures the data was never transmitted in the first place.
Physical Immunity vs Paper Contracts • Not Your RAM, Not Your Data
06What if our documents contain rare or proprietary PII?
Beyond 30 pre-built industry profiles, users and admins can define custom client-side regular expressions or import MDM-locked company dictionaries that execute 100% locally in device memory.
30 Profiles · Custom Regex · MDM Policy Lock
Architecture Benchmark

Paper Contracts vs Physical Immunity: Local RAM vs Cloud DLP

Sign a DPA to allocate liability after an incident, or isolate memory so a breach is physically impossible. Why enterprise security architects choose in-memory client-side ZTDS over cloud DLP proxies.

Cloud DLP Proxies & Gateways

High Overhead
  • Network Egress: Transmits unredacted prompt payloads over the internet to intermediate cloud proxy servers.
  • High Latency: 250ms – 600ms latency penalty per AI query due to multi-tenant cloud roundtrips.
  • Probabilistic NLP: Cloud LLM redactions risk hallucinating tokens, skipping entities, or rewriting prompt semantics.
  • Procurement Overhead: Requires 6–8 week legal reviews, BAAs, DPAs, and third-party vendor risk questionnaires.

PrivacyScrubber Client-Side ZTDS

Zero Risk
  • 0-Byte Transmission: 100% volatile local RAM processing. Fully functional offline in Airplane Mode.
  • Sub-2ms Latency: Near-zero latency overhead (<2ms local CPU tokenization). Zero network queues.
  • Deterministic Precision: Rigorous pattern engines (Luhn, RFC 5322, RegExp). Zero token hallucinations.
  • 0-Day Clearance: Zero third-party data processing — DPAs and BAAs are legally non-applicable.
Sub-2ms In-Memory

100% reproducible RAM tokenization

30 Industry Profiles

HIPAA Safe Harbor, GDPR, PCI DSS

Custom Regex & WASM OCR

Air-gapped scanned PDF processing

6 Global Statutory Frameworks · 0 Payload Packets · Zero Subprocessors
Transparent Value · Zero Per-Seat Tax

Transparent Pricing. Zero Subprocessor Risk.

Sanitize enterprise prompts locally in browser RAM before sending to ChatGPT, Claude, Gemini, or Cursor. Zero servers, zero per-seat tax, 100% GDPR, HIPAA & SOC 2 compliant.

Zero Accounts•Offline Cryptographic Key•100% In-Browser RAM
Swipe cards or tap arrows 1 of 4 · Free
Community Tier
$0
Universal consumer PII · Free forever · Zero accounts
100% In-Browser RAM — No passwords, no logins, no cloud tracking
  • Swaps Names, Phones, Emails, SSN, Credit Cards, URLs & IPs with safe tokens before AI ingestion.

  • Paste AI responses back to reveal original client data locally in browser RAM without server leaks.

  • Zero servers, zero telemetry, zero logs. Verified offline in Airplane Mode with sub-millisecond speed.

  • In-Page Shield & Web App

    Use via keyboard hotkey Alt+Shift+X directly in ChatGPT, Claude, Gemini or full web app.

  • Free Volume & Single File Trial

    15,000 chars general + 5,000-char trial across all 30 Specialized Profiles. Single document sanitization (.pdf/.docx/.xlsx).

Scrub Prompts Free (15,000 Chars) Test Speed vs Cloud DLP (<2ms) →
15,000 Chars Free•Zero Accounts•RAM-Only
Zero-Server Client-Side ZTDS
PRO Tier
$15/ mo
For solo practitioners, lawyers & devs · $110 Lifetime
Includes Web App + Chrome Extension + Local MCP Server
Instant Key•Zero Accounts•Cancel Anytime
Best Value
TEAMS Plan
$99/ mo flat
Domain-wide protection for law firms, clinics & teams
Full Company Domain — Unlimited StaffFlat Rate
0-Day Procurement: Bypasses 6-week vendor reviews — DPA legally waived (0 bytes egress).
Unlimited Seats•Zero Accounts•No Per-User Tax
Zero-Server Client-Side ZTDS
Developer SDK
Free Quota Built-in
$299/ mo
Free for local dev with quota · $299/mo for unlimited production nodes
Free with Quota — Test locally in 30s. Zero card or sign-up.<0.4ms
Zero Subprocessor Drag: Runs 100% in your microservice RAM. Zero third-party network egress.
Free Local Quota
Free Quota Built-in•Zero Accounts•<0.4ms In-Process
Headless Node.js & WASM Core
44,000x Liability Mitigation Asymmetry

The True Cost of AI Privacy: Breach vs. DIY vs. ZTDS™

Zero Subprocessors · No DPA Needed
Swipe to compare risk vs solution 1 of 3 · Breach Cost
Cost of Inaction
$4,880,000

Average cost of a GenAI corporate data breach according to the IBM Security Report.

  • Up to €20M or 4% turnover (GDPR & EU AI Act Art. 50).
  • $50,000/violation statutory HIPAA willful neglect fines.
  • 6–12 week enterprise procurement stalling for vendor reviews.
Verdict: Catastrophic Downside
In-House DIY Trap
$50,000+/yr

Internal engineering salary to build, test and maintain custom regex DLP logic.

  • $500–$2,000/mo server bills for centralized cloud proxy nodes.
  • 200–500ms network roundtrip latency on every developer prompt.
  • Ongoing regex drift, edge-case false positives & triage drag.
Verdict: High Maintenance Drag
Zero-Trust Protocol (ZTDS™)
$99/mo flat

Flat-rate team protection with 100% in-memory client-side sanitization.

  • 0-Day Approval: Zero subprocessors, no DPA paperwork needed.
  • <2ms local RAM execution with 0 bytes network egress.
  • Turnkey compliance proofs: SOC 2 Type II & ISO 27001 mapping.
Verdict: Pure Mathematical Asymmetry
Zero-Database Architecture

How PrivacyScrubber Licensing Actually Works

We refuse to store your passwords or track your identity in a central database. Privacy is an engineering guarantee, not a marketing promise.

1. Zero Accounts & No Passwords

You never create an account, set a password, or trust us with login credentials. There is no cloud user database to be breached, scraped, or subpoenaed.

0 Credentials Stored • 100% Anonymous

2. Offline Cryptographic Keys

Paid tiers (PRO, TEAMS, SDK) activate via an offline cryptographic license key. Validation occurs mathematically in your local RAM without cloud telemetry or pingbacks.

Airplane Mode Verified • Zero Pingbacks

3. 1-Year G2 Reviewer Pass

Solo practitioners and engineers can claim a full 1-year PRO license key ($180 value) 100% free by publishing an honest, verified practitioner review on G2.

Procurement & CISO Total Cost of Ownership (TCO)

Traditional Cloud DLP vs. PrivacyScrubber TEAMS — 94% Cost Reduction

Cloud DLP vendors charge $30–$50/user/mo ($18,000–$30,000/yr for 50 seats), introduce 250ms+ network latency, and require months of vendor security assessments. PrivacyScrubber TEAMS costs $99/mo flat ($1,188/yr) for unlimited seats with zero server-side subprocessor liability.

Annual Savings
$16,800+ / yr
Air-Gapped Enterprise & Source Code EscrowCustom SLA

Complete on-premise source code licensing, 100% air-gapped sovereign deployment, proprietary patent-pending architecture (U.S. & Int'l Patents Pending), custom SIEM log integration, dedicated GRC support & bilateral DPA for healthcare systems, banks, defense, and 10,000+ seat organizations.

Talk to Enterprise
What You Get & Why It Matters

Role & feature entitlements across Free, PRO, TEAMS, and Enterprise tiers

Compare All Specifications →
Module & FeatureOutcome & Problem SolvedWho Uses ItTiers
In-Page Chrome Shield Sanitizes prompts right inside ChatGPT, Claude, and Gemini with hotkey Alt+Shift+X without switching tabs. All AI Users & AnalystsFree (15k) / PRO / TEAMS
30 Industry PII Profiles Pre-configured detection for HIPAA health data, legal court filings, IBAN bank numbers, and payroll records. Doctors, Lawyers, AccountantsPRO & Above
IDE MCP Server (stdio) Strips database credentials, JWTs, and secret tokens before Cursor or Claude Code AI agents read your source repository. Free with session quota. Software Engineers, DevOpsFree (Quota) / PRO / TEAMS
Offline PDF & OCR Extracts and sanitizes scanned contracts and screenshots in volatile RAM without sending images to cloud vision APIs. Legal, HR, ProcurementPRO & Above
Excel & CSV Cell Scrub Cell-by-cell PII sanitization in local memory preserving formulas, spreadsheet structures, and numeric salary sums. Data Analysts, UnderwritersPRO & Above
Zero-Metadata File Stripping Physically strips OpenXML revisions (w:del), hidden comments, calcPr UNC paths, PDF Tj/TJ vector streams, and EXIF stamps. Lawyers, Auditors, HR, CISOsPRO & Above
Custom Regex & Secrets Custom regex builder to sanitize proprietary internal project codenames, custom customer IDs, and API secrets. Security Engineers, R&DPRO & Above
1-Click Reverse Reveal Instant local rehydration restoring real customer names and parameters into AI responses inside browser memory. Support, Sales, RecruitersFree / PRO / TEAMS
Zero-Knowledge Session Handoff Securely transfer sanitized AI prompt sessions to colleagues via encrypted P2P links without storing data in any central server database. Cross-functional TeamsTEAMS & Above
Central Rules & Policy Governance Distribute company-wide PII policies, proprietary codenames, and custom regex across employee browsers with zero server sync. Security Officers, IT DirectorsTEAMS & Above
Cryptographic Audit Receipts 1-click signed PDF certificate with SHA-256 session hashes proving zero confidential data left your premises. Compliance Officers, DPOsPRO & TEAMS
Developer SDK & CLI In-process consumer privacy fiduciary (@privacyscrubber/sdk) embedded into Node.js / WASM. Pre-emptively intercepts PII at the application boundary with zero data loss, zero third-party DLP proxies, and <1ms execution before vector indexing or LLM egress. Backend Developers, AI Engineers, RAG ArchitectsFree (Quota) / $299 Prod
License Custody & Kill Switch
Zero-server key custody with instant emergency revocation (KRL) if a key is leaked. Master Admin Key isolation for teams. All License Holders, CISOsAll Paid Tiers
Air-Gapped RAM Operation Verified 0-byte outbound network egress in Airplane Mode, bypassing DPAs and third-party vendor audits. CISOs, Defense, BanksAll Tiers
Accepted Payment Methods
Wire / Invoice
PCI-DSS Compliant · 30-Day Refund
Full Pricing & ROI Calculator
Answers & Security FAQ

Frequently Asked Questions

Everything you need to know about browser-based PII redaction, compliance scope, and AI safety.

Verified architecture & compliance answers
Features & FilesHow does the Zero-Trust Agentic Guard work in practice when AI agents run shell commands or edit code?
PrivacyScrubber Agentic Guard acts as a local in-memory proxy between your workstation and autonomous AI coding agents (Cursor, Windsurf, Claude Code, Copilot). When an agent executes shell commands (guard_exec) or reads credentials (guard_read_file), output is intercepted in local RAM and secrets are replaced with anonymous tokens ([API_KEY_1], [EMAIL_1]). The remote LLM reasons exclusively over tokenized placeholders. When applying code changes (guard_apply_patch), tokens are reversed back to authentic local secrets in memory and written to disk with an automatic .bak backup. Zero secrets leave your device.
Security & ZTDSDoes PrivacyScrubber send my data to any server?
No. Every detection and sanitization operation runs locally inside your browser's RAM. Zero bytes of your text, documents, or session tokens leave your device. Verify this yourself: open DevTools → Network tab, test our DLP speed benchmark, or disconnect from the internet entirely — our air-gapped local processing keeps working offline.
Security & ZTDSDoes dropping or uploading a transcript or document into PrivacyScrubber transmit my file to a server?
No. When you drop or upload a document (.txt, .docx, .pdf, or client meeting transcript) into PrivacyScrubber, the file never travels across the internet. The entire webpage operates like a self-contained local application inside your browser: file parsing, text extraction, and PII redaction execute exclusively in your computer's local RAM. You can verify this complete data isolation by turning your computer's Wi-Fi completely off (Airplane Mode) before dropping your file — the tool continues to sanitize your documents with 100% functionality and zero network connectivity.
Features & FilesWhich AI platforms does the browser extension support?
The PrivacyScrubber Chrome extension injects real-time PII sanitization directly inside ChatGPT, Claude, Gemini, Microsoft Copilot (Bing Chat), Grok, Perplexity, DeepSeek, Qwen, Kimi, and Zendesk. For coding agents and autonomous workflows, explore our AI Agents Protection guide, or use the web app at privacyscrubber.com to sanitize text before pasting it into any interface.
Pricing & TeamsWhat does the free version include?
The free Community Tier includes universal consumer PII masking (Names, Phones, Emails, National IDs, Credit Cards, IPs, URLs) with 15,000 characters per scrub, a 5,000-character free quota across all 30 specialized industry profiles, single-file upload (.txt, .docx), and PDF extraction up to 3 pages. It also includes free access to the Developer SDK (@privacyscrubber/sdk) and IDE MCP Server (@privacyscrubber/mcp-server) with built-in session quotas — zero credit card, zero passwords, and zero accounts required. For solo practitioners and developers, you can also claim a 1-Year PRO Reviewer Pass ($180 value) 100% free with an honest review on G2.
Features & FilesDo I need to create an account or provide a password?
No. PrivacyScrubber is architected with Zero Accounts and Zero Passwords. We do not maintain a central user database or store login credentials. Upgrades (PRO, TEAMS, Developer SDK) are activated purely via an offline cryptographic license key entered into your browser or local SDK environment. Validation executes mathematically in volatile device RAM with zero phone-home user tracking.
Features & FilesCan PrivacyScrubber sanitize W-2 forms, paystubs, and payroll documents?
Yes. Our specialized financial PII profile natively detects Employer Identification Numbers (EIN/FEIN), payroll-format names (LASTNAME, FIRSTNAME), corporate employer names with legal suffixes (Inc, LLC, Corp), and US street addresses. All wage amounts, tax withholdings, hourly rates, and financial figures are preserved untouched — essential for loan underwriting and HR payroll compliance.
Features & FilesCan I get my original data back after the AI responds?
Yes. Paste the AI's response back into the tool and click Reveal. The 1-Click Reveal engine swaps every token ([NAME_1], [EMAIL_2], etc.) back to the original value using your volatile local session map — zero server round-trips, zero database storage.
Compliance & LegalDoes this help with HIPAA, GDPR, or SOC 2 compliance?
PrivacyScrubber is designed to support de-identification under HIPAA Safe Harbor (45 CFR §164.514) for 18 PHI identifiers, GDPR Article 25/32 data minimization, and SOC 2 Type II controls by stripping identifiers in browser RAM before prompt submission. Review our Top 20 Corporate PII Guide and CISO AI Security Blueprint for detailed governance controls.
Compliance & LegalWhat is the CISO Procurement Memo and how do enterprise teams use it?
The CISO Procurement Memo is a standardized, copy-ready compliance document for enterprise IT, security architects, and procurement officers. It provides General Counsel, DPOs, and InfoSec committees with formal statutory evidence (GDPR Art. 4(8)/28, HIPAA 45 CFR § 164.502(e), CCPA § 1798.140) proving that because PrivacyScrubber runs 100% in local client RAM with 0 bytes transmitted to any server, third-party DPA/BAA contracts and lengthy vendor risk questionnaires (SIG/CAIQ) are legally non-applicable, enabling fast-track 0-day software approval.
Security & ZTDSHow does PrivacyScrubber prove zero network egress and lightweight memory usage?
Every software build undergoes an automated 13-suite security and performance QA pipeline in continuous integration (CI). Automated headless network sniffers verify that during PII sanitization, exactly 0 HTTP, WebSocket, or background telemetry packets leave the browser. In-memory heap profiling enforces an ultra-lightweight ceiling under 6MB RAM (5.68 MB JS Heap) and sub-75ms streaming DOM mutation scans across 5,000 live nodes, ensuring zero laptop heating and zero CPU throttle. Review the full audit in our Technical Security Specifications.
Security & ZTDSWhat happens to the session map when I close the tab?
The session map exists exclusively in volatile browser RAM and is strictly isolated per tab. The moment you close the tab, reload the page, or navigate away, the entire mapping — including all original PII values and cryptographic keys — is permanently purged from memory. Read more in our Technical Security Architecture.
Features & FilesWhat is the difference between AI Tokens mode and Blackout mode in PrivacyScrubber?
AI Tokens mode replaces sensitive entities with structured badges like [NAME_1] and [EMAIL_1], preserving contextual roles for LLMs (ChatGPT, Claude) and allowing 1-click restoration via Reveal Originals. Blackout mode applies permanent, solid black raster bars over sensitive pixel coordinates, physically destroying vector text layers for court filings, legal discovery, and FOIA releases with zero underlying text leakage.
Features & FilesWhy do standard PDF blackout tools leak data, and how does PrivacyScrubber prevent it?
Most conventional PDF editors and markup tools merely overlay black rectangles as a visual layer, leaving underlying OCR text, character coordinates, and metadata intact and extractable via Cmd+A copy or pdftotext. PrivacyScrubber executes true Secure Raster Flattening: pages are re-rendered in local RAM, PII coordinates are overwritten at the pixel level, and a fresh PDF is synthesized with zero underlying text layers, guaranteeing 100% leak-proof redactions.
Features & FilesWhat file formats can I sanitize, and what do I get back?
Supported formats include .txt, .docx, .pdf (text-layer and scanned images via Tesseract OCR), .xlsx, and .csv. With Batch File Redaction and Excel Spreadsheet Scrub, you can download sanitized files with PII removed or export redacted PDFs with permanent raster flattening (zero underlying text layers).
Features & FilesDoes PrivacyScrubber sanitize hidden document metadata (author, company name, revision history) in Word (DOCX) and Excel (XLSX) files?
Yes. Most conventional redaction tools only mask visible text or cell contents, leaving hidden document properties intact. Microsoft Word (.docx) and Excel (.xlsx) files are compressed XML archives that store author identity (<dc:creator>), modifying users (<cp:lastModifiedBy>), corporate affiliation (<Company>), and revision timestamps inside docProps/core.xml, docProps/app.xml, and workbook properties. PrivacyScrubber's in-RAM sanitizer intercepts these archives in local browser memory, wipes original author and organization tags, eliminates custom metadata, and overwrites properties with anonymous synthetic signatures (PrivacyScrubber (Zero-Trust)) before export. Your exported files are completely clean both visibly and metadata-wise, with zero network transmission.
Features & FilesWhy does the Chrome extension convert uploaded files (PDF/DOCX) into .txt, and how do file upload quotas work?
When users upload or drop documents (such as resumes or legal agreements) into ChatGPT or Claude, PrivacyScrubber intercepts the file in local browser RAM. Binary formats (.pdf, .docx) contain hidden metadata, revision histories, and XML streams that can expose personal identity even if visible text is edited. PrivacyScrubber extracts document text in memory, replaces sensitive PII with tokens, strips names from the filename, and injects a clean synthetic .txt file into the AI prompt window. This eliminates 100% of binary metadata leakage while preserving full LLM analytical utility. The Free tier includes a daily allowance of 3 document uploads per 24 hours (and up to 15,000 characters per scrub), while PRO and TEAMS provide unlimited document processing.
Security & ZTDSWhat is AI DLP and how does client-side browser sanitization differ from a legacy cloud proxy?
AI Data Loss Prevention (AI DLP) refers to specialized security controls engineered to inspect and sanitize unstructured conversational prompts, streaming tokens, and file uploads before ingestion by generative AI models. Traditional gateway DLPs (like Zscaler, Netskope, or Cloudflare proxies) sit downstream in the network and struggle with encrypted WebSockets, streaming Server-Sent Events (SSE), and conversational context—often causing latency or failing to de-identify data before transit. PrivacyScrubber executes AI DLP directly at the source: inside local browser RAM (<2ms latency). Sensitive entities are converted into contextual tokens ([NAME_1], [ACCOUNT_1]) before packets ever reach the network adapter, guaranteeing zero vendor data custody and mathematical immunity to cloud leaks.
Security & ZTDSWhat is the AI data irreversibility problem and why must PII redaction happen at the client endpoint?
The AI Irreversibility Problem stems from the mathematical impossibility of selectively 'unlearning' or excising data once it has been digested into large language model neural weights or stored in multi-tenant RAG (Retrieval-Augmented Generation) vector databases. Machine unlearning remains an unsolved scientific challenge; post-hoc deletion requests (such as GDPR Article 17 'Right to be Forgotten') cannot be reliably enforced against fine-tuned weights or vector embeddings. Consequently, regulatory bodies (under the EU AI Act Article 10 and HIPAA Safe Harbor) require data sanitization to occur strictly prior to ingestion. PrivacyScrubber's endpoint-only RAM architecture guarantees that sensitive identifiers never enter LLM training corpora or remote vector caches.
Pricing & TeamsHow does TEAMS encrypted session handoff work?
PrivacyScrubber TEAMS uses Argon2id key derivation and XChaCha20-Poly1305 authenticated encryption (via libsodium WASM). Through encrypted team session handoff, colleague Alice sanitizes prompts and shares a cryptographic blueprint; colleague Bob reveals original values locally with zero server intermediary.
Security & ZTDSHow does Shadow DOM sandboxing protect against malicious scripts?
PrivacyScrubber wraps editor inputs and tokenized outputs inside closed Shadow DOM roots. This makes unredacted sensitive text completely inaccessible to DOM-scraping scripts, third-party analytics, or unauthorized browser extensions running on the host page. Learn more about our in-DOM prompt sandbox.
Features & FilesCan I use PrivacyScrubber as an MCP server in Cursor, Windsurf, or Claude Desktop?
Yes. The official @privacyscrubber/mcp-server package runs as a local stdio-based Model Context Protocol server for Cursor, Windsurf, Claude Desktop, and VS Code. It intercepts codebase prompts, sanitizes database passwords and API tokens in RAM, and protects your software development workflows with zero external calls.
Pricing & TeamsIs there a developer SDK for integrating PII sanitization, and is it free to try?
Yes. The @privacyscrubber/sdk NPM package exposes the headless sanitization engine as a programmatic Node.js & ESM library. It is 100% free to test locally in under 30 seconds with a permanent free quota (15k characters General / 5k characters Specialized per session)—no credit card, no account sign-up, and zero expiring trials. Call scrubText() and unscrubText() directly in local dev environments, CI/CD gates, and RAG pipelines. Commercial licensing ($299/mo or $2,990/yr) is only required for unlimited production nodes and continuous high-throughput backend services.
Features & FilesHow do developers integrate @privacyscrubber/sdk out of the box, and what are the operational capabilities and state risks?
Developers integrate @privacyscrubber/sdk with zero dependencies using a 1-line wrapper like wrapOpenAI(new OpenAI()), or via standalone sanitize() and restore() in <1ms local RAM latency. It intercepts outbound prompts before network transmission, tokenizes PII and infrastructure secrets into semantic placeholders ([NAME_1], [AWS_KEY_1]), and rehydrates LLM responses locally—including streaming SSE tokens via sliding window reconstruction. Operation is completely plug-and-play with zero background servers or Python/spaCy daemons. The primary operational risk to manage is state custody in distributed microservices: tokenMap is volatile and RAM-only, requiring stateless microservices to preserve or pass the token map between pre-processing and post-processing nodes.
Features & FilesDoes changing the detection profile reset my session?
No. Switching between our 30 specialized industry detection profiles (e.g. from General to Legal & Contracts or Medical) preserves active tokens and session maps. Tokens remain restorable via Reveal until you click the Clear button explicitly.
Security & ZTDSHow does PrivacyScrubber prevent data residue in system RAM?
After processing documents (PDF, DOCX, XLSX), the engine immediately overwrites all temporary ArrayBuffers at the byte level with zeroes (Uint8Array.fill(0)) before releasing them to garbage collection. Pair this with our tamper-evident audit receipts for verifiable forensic compliance.
Pricing & TeamsCan enterprise or accounting teams pay via invoice or wire transfer?
Yes. For organizations requiring formal vendor onboarding, purchase orders (PO), or SWIFT/SEPA bank wire transfers, we provide custom invoicing with EU VAT reverse-charge support. Check our transparent pricing matrix or visit our Enterprise Solutions Hub.
Security & ZTDSDoes PrivacyScrubber load any third-party analytics or tracking scripts?
No. The platform loads zero analytics trackers, third-party cookies, or fingerprinting scripts. Maintaining strict Content Security Policies (CSP) ensures third-party endpoints cannot inspect memory or DOM states. Review our full commitments in our Zero-Server Privacy Policy.
Compliance & LegalHow are TEAMS admin roles managed without a backend?
There are no centralized accounts. Team administrators configure mandatory regex rules and compliance profiles locally in the Teams Deployment Hub, then generate a cryptographically signed Blueprint URL. When team members open this link, the configuration locks client-side without any backend database.
Compliance & LegalWhat rights does a Team Administrator have compared to Managed Team Members in TEAMS?
The purchaser acts as the Team Administrator with exclusive authority to configure organization-wide custom Regex rules, corporate token taxonomy (e.g. [PATIENT_ID]), and default compliance profiles in the Teams Dashboard. When the Admin exports a cryptographically signed Blueprint with Lock Rules enabled, Managed Team Members receive a locked, read-only configuration across their Web App and Chrome Extension (badged as [ENTERPRISE]), preventing employees from altering or bypassing corporate DLP policies.
Features & FilesWhat is the difference between Custom Regex Rules and Token Labels?
Our Custom Regex Rules Engine discovers proprietary data formats (custom ticket IDs, project codes like PROJ-1234, internal server URLs). Token Labels, in contrast, customize the replacement placeholder (e.g. renaming [NAME] to [PATIENT_ID]) to give LLMs optimal domain context without modifying regex patterns.
Security & ZTDSHow does PrivacyScrubber detect PII without AI hallucinations or latency?
PrivacyScrubber utilizes a high-performance deterministic pattern matching engine running natively in browser RAM (sub-2ms execution time). Unlike cloud LLM-based redaction which can hallucinate, omit tokens, or introduce network latency, our deterministic parser guarantees 100% reproducible tokenization across 18 core Safe Harbor/GDPR entity types (names, emails, phones, SSNs, credit cards, IBANs, medical MRNs, API tokens). PRO users can also inject custom regex rules or run local offline OCR for documents.
Pricing & TeamsHow does license key custody, non-transferability, and emergency revocation work without user tracking?
Because PrivacyScrubber maintains a Zero-Trust Data Sanitization (ZTDS) architecture with zero server databases and zero phone-home user tracking, license custody is sovereign to the purchaser. All license tiers are strictly non-transferable. If a key is accidentally leaked or exposed, the billing owner can immediately request emergency revocation via support@privacyscrubber.com. We append the SHA-256 hash of the compromised key to our global Key Revocation List (KRL), instantly invalidating it across all client instances within 24 hours while reissuing a secure replacement.
Pricing & TeamsWhat are the exact operational boundaries between Personal PRO, Team Workspace, and Developer SDK licenses?
PRO ($15/mo or $110 Lifetime) is a single-user personal license valid on up to 3 personal devices (Web, Chrome, IDE MCP). TEAMS ($99/mo flat) is an organization-wide internal workspace covering unlimited internal staff with Master Key Isolation. The Developer SDK ($299/mo or $2,990/yr) covers headless execution across unlimited internal backend nodes, microservices, ETL pipelines, and internal RAG vector databases. Embedding into customer-facing commercial SaaS for third-party resale requires an OEM/Enterprise contract.
Security & ZTDSIs the PrivacyScrubber MCP Server completely air-gapped, and is it free to use?
Yes. The @privacyscrubber/mcp-server package executes strictly in local machine memory over standard stdio JSON-RPC transport with zero outbound network requests, zero telemetry, and 100% volatile RAM mapping. It is 100% free to use with built-in session quota directly in Cursor, Windsurf, Claude Code, and VS Code without requiring a credit card or account registration. PRO and TEAMS tiers provide unlimited character volume and enterprise policy synchronization.
Features & FilesHow can solo coaches, therapists, and executive consultants sanitize client meeting transcripts (Zoom, Teams, Google Meet) without cloud exposure?
Solo practitioners handling confidential client sessions (ADHD coaching, therapy, executive consulting) can execute a 100% offline, zero-cloud workflow: First, transcribe your locally recorded Zoom or Teams meeting on your own device using an offline Speech-to-Text engine (such as MacWhisper or Whisper.cpp running natively on Apple Silicon / local GPU). Second, drop the resulting .txt or .docx transcript into PrivacyScrubber at privacyscrubber.com (even with your device Wi-Fi completely turned off). PrivacyScrubber strips client names, sensitive disclosures, neurodiversity/medical conditions, and identifying details into safe tokens ([NAME_1], [ORGANIZATION_1]) in volatile RAM. Third, submit the sanitized transcript to Claude or ChatGPT to extract themes, check coaching quality, or draft session summaries. Finally, click Reveal in PrivacyScrubber to rehydrate original client names locally. Zero client personal data ever touches third-party servers.
Features & FilesHow does PrivacyScrubber handle European names with initials and national identity numbers like Dutch BSN, German Steuer-ID, or French NIR?
PrivacyScrubber features dedicated pattern recognition engines for European business and civil nomenclature. Our punctuation-aware lookahead models accurately tokenize initial-prefixed names with noble particles (e.g., 'J. de Ruiter', 'K. van den Berg', 'M. de Jong') without prematurely splitting or dropping initials. For statutory identity tokens, PrivacyScrubber embeds native checksum and format validators in client-side RAM for European national IDs—including the Dutch 11-test checksum for BSN/SOFI numbers, 11-digit German Steuer-ID, 16-character Italian Codice Fiscale, Spanish DNI/NIE, French NIR/INSEE, and Dutch KvK commercial register numbers.
Compliance & LegalHow does PrivacyScrubber protect enterprise RAG vector databases and prevent GDPR Article 17 re-indexing costs?
Embedding raw personal data into vector databases (Pinecone, Qdrant, Weaviate, Milvus) creates permanent regulatory liability: fulfilling a single GDPR Article 17 'Right to Erasure' request requires locating all high-dimensional embeddings containing that person's data and recalculating vector indexes—costing upwards of $14,000 per deletion cycle. By embedding the headless @privacyscrubber/sdk into your ingestion pipeline, raw PII is swapped with deterministic cryptographic tokens in Node.js heap (<0.065ms) before vector embedding. When a deletion request arrives, organizations simply purge the local key mapping, achieving instantaneous O(1) mathematical erasure at $0 infrastructure cost.
Compliance & LegalWhy does PrivacyScrubber NOT require a Data Processing Agreement (DPA) or Business Associate Agreement (BAA)?
Under GDPR Article 4(8)/Article 28 and HIPAA 45 CFR § 164.502(e), Data Processing Agreements (DPAs) and Business Associate Agreements (BAAs) are legally required only when an external vendor processes or hosts protected data on remote infrastructure on your behalf. Because PrivacyScrubber executes 100% in local client-side RAM with zero server data transmissions, zero external telemetry, and zero subprocessors, PrivacyScrubber is legally classified as a software vendor rather than a data processor. Enterprise security and compliance committees can fast-track clearance in hours using our standardized CISO Procurement Memo.
Security & ZTDSWhy deterministic rules instead of cloud NER models like Microsoft Presidio or BERT?
Sending text to remote Named Entity Recognition (NER) models leaks raw data before masking can occur. ZTDS executes deterministic lookaround regular expressions and 30 specialized industry vocabularies 100% locally in device memory (<1ms latency), providing 100% reproducible compliance proofs without stochastic AI hallucinations or model drift.
Security & ZTDSHow is browser heap memory protected against local memory extraction, XSS, or process dumping?
PrivacyScrubber enforces strict Content Security Policy (script-src 'self') with zero external scripts or analytics trackers. Session maps exist strictly in volatile, tab-isolated RAM, are never written to disk, localStorage, or cookies, and are permanently wiped on tab close. Host RAM dumping requires prior OS root compromise, which affects all workstation secrets regardless of software.
Security & ZTDSWhat happens if generative AI models alter, drop, or hallucinate synthetic tokens?
Our patent-pending engine incorporates an algorithmic Tolerant Fuzzy Unscrubbing parser that resolves model case changes, whitespace shifts (such as [NAME 1]), and markdown formatting. If a model completely omits a token from its response, the local audit view immediately flags the missing identifier without corrupting surrounding text.
Compliance & LegalHow can an enterprise CISO or SOC audit compliance without central servers?
Zero server processing does not mean zero auditability. PrivacyScrubber generates cryptographically verifiable CISO Audit Receipts (SHA-256 integrity hash, triggered regulatory frameworks, timestamp, entity counts) directly on the client. Enterprise teams stream zero-PII telemetry locally to internal SIEM (Splunk, Datadog) via our Node.js SDK and MCP server.
Compliance & LegalWhy do organizations need ZTDS if they already have Azure OpenAI or ChatGPT Enterprise with a BAA?
Business Associate Agreements (BAAs) provide legal recourse after a breach, not physical prevention. They do not protect against cloud logging errors, insider snooping, model jailbreaks, or US CLOUD Act subpoenas. Data that never leaves the workstation in the first place cannot be breached, inspected, or subpoenaed.
Features & FilesWhat if our organization handles rare, proprietary, or highly specialized PII formats?
Beyond 30 pre-configured industry profiles (HIPAA, GLBA, FINRA, FAR/DFARS, GDPR), PrivacyScrubber PRO and TEAMS allow security administrators to define custom client-side regular expressions or import MDM-locked company dictionaries that execute 100% locally in device memory with zero cloud egress.
Zero-Vendor-Risk Clearance

Need CISO, Legal, or Procurement Clearance?

Our 100% in-RAM architecture eliminates DPA negotiations, vendor risk questionnaires, and third-party data processor audits.