Give Enterprise Teams AI Tools Without Server Risk.
Traditional network firewalls and cloud proxies can't inspect encrypted LLM prompts without intercepting corporate data. PrivacyScrubber tokenizes sensitive corporate PII locally at the browser endpoint in under 1.8ms — before prompt payloads reach OpenAI, Anthropic, or external AI models.
Video Brief: Securing the LLM Layer
Client-Side ZTDS vs Cloud DLP Proxies Explained
Shadow AI Governance: The "Yes-to-AI" Framework
Legacy Approach: Wholesale Prohibition
Blocking AI domains at corporate firewalls or MDMs invariably drives employees into unmanaged "Shadow AI" channels — using personal laptops, unencrypted mobile devices, and unmonitored home networks to complete their daily work.
The ZTDS Paradigm: Endpoint Empowerment
Equip workforce teams with approved generative AI workflows by stripping and tokenizing PII at the browser endpoint in volatile memory. CISOs guarantee regulatory compliance without ever storing, seeing, or logging cleartext corporate data.
Architecture Layer Cake: Client-Side Data Isolation
Endpoint Ingestion & Sandboxing
0ms Network LatencyData remains strictly local; scanned and tokenized entirely in browser RAM using WebAssembly and regex heuristics. Zero bytes leave the physical device perimeter.
Deterministic Pseudonymization (ZTDS)
Volatile RAM SeedSensitive entities (names, SSNs, MRNs, API tokens) are replaced with role-preserving badges (e.g. [CLIENT_1], [API_KEY_1]). Session map exists strictly in RAM and is permanently purged on tab close.
De-Identified Cloud Model Ingestion
0 Bytes Real PII EgressExternal LLM servers (ChatGPT, Claude, Gemini) receive only sanitized tokens with full linguistic syntax. Zero real-world customer records or trade secrets can be leaked into model training weights.
Strategic Implementation Roadmap
Audit & Baseline
Map high-risk generative AI ingestion paths across departments (Legal contracts, HR payroll, Engineering code repos).
Shadow AI Amnesty
Deploy PrivacyScrubber to give employees an approved "safe path" to continue using AI tools without risking exfiltration.
In-DOM Enforcement
Roll out the Chrome Extension via Google Workspace Admin / MDM to enforce local tokenization directly inside ChatGPT & Claude.
Continuous SIEM Telemetry
Stream zero-PII audit heartbeats to corporate SIEM (Splunk, Datadog, Sentinel) for continuous SOC 2 & ISO 27001 proof.
Standardized Compliance & Control Mappings
OWASP Top 10 for LLMs
Edge-level sanitization addresses three critical OWASP LLM vulnerabilities at the semantic layer:
- LLM01: Prompt Injection
Intercepts prompts at the DOM level, neutralizing structural exploits before model inference. - LLM02: Insecure Output Handling
Executes detokenization (Reveal) 100% client-side in RAM, preventing leaks over insecure networks. - LLM06: Sensitive Info Disclosure
Enforces deterministic masking of credentials, API tokens, and customer PII before transmission.
NIST AI Risk Management
Direct alignment with NIST AI RMF 1.0 core sub-functions:
- GOVERN-1.2
Enforces technical boundaries for acceptable enterprise generative AI use. - MAP-1.5
Tracks and neutralizes corporate data leakage vectors prior to network egress. - MEASURE-2.6
Quantifies masked entity volumes via client-side telemetry with zero PII retention. - MANAGE-1.5
Actively mitigates exfiltration risks directly at the prompt perimeter.
Regulatory Data Masking
Automates technical controls required by global privacy and cybersecurity frameworks:
- EU AI Act (Aug 2026): Article 50 pre-AI data minimization & transparency controls.
- ISO 27001 A.8.11: Automates data masking compliance directly at the user endpoint.
- GDPR Articles 25/32: Implements privacy-by-design through ephemeral tokenization.
- HIPAA Safe Harbor: De-identifies 18 PHI elements locally before cloud transit.
- SOC 2 CC6.1 / CC6.6: Restricts boundary exfiltration with cryptographic audit proofs.
- Patent Pending Architecture: ILPO App. 331905 (Client-Side ZTDS & Cryptographic Handoff).
AI Governance Board Recommendations
When forming your organization's Generative AI Committee, blanket domain blocklists fail because they inevitably trigger unmonitored shadow AI workarounds. Governance committees should implement these three foundational policies:
- Adopt a "Yes-to-AI" Standard: Provide staff with approved productivity tools equipped with client-side sanitization.
- Mandate Endpoint Pre-Sanitization: Ensure prompt payloads pass through local ZTDS filters before transmission.
- Centralize Rules Governance: Distribute unified regex policies for internal codenames, AWS keys, and customer IDs.
TPRM & Vendor Risk Assessment Fast-Track
Standard SaaS procurements stall for 3–6 months during Third-Party Risk Management (TPRM) audits because vendors act as Data Processors. ZTDS eliminates this entire bureaucratic bottleneck:
- No Processor Status: Zero prompt bytes are transmitted to our servers; PrivacyScrubber never acts as a Data Processor under GDPR Art. 28.
- CAIQ Pre-Cleared: Over 80% of standard Cloud Security Alliance CAIQ questionnaire lines resolve to "N/A — Local RAM Execution".
- Same-Day Clearance: Legal and InfoSec committees approve PrivacyScrubber as an air-gapped client utility, bypassing the DPA queue.
Deployment Economics: Time-to-Value
Legacy Cloud DLP Gateway
Requires formal Vendor Risk Assessment (VRA), customized Data Processing Addendum (DPA) legal reviews, root CA certificate installations, and network-wide proxy certification.
ZTDS Client-Side Deployment
Zero data transit means zero regulatory exposure. Bypasses DPA requirements, vendor sub-processor audits, and invasive network proxy re-routing entirely.
CISO Objection Handling Matrix
"Won't masking sensitive data break the AI model's contextual understanding?"
ZTDS deploys semantic role-preserving placeholders (e.g. [PATIENT_1], [ORGANIZATION_2]). The LLM retains 100% of grammatical syntax and relational context, enabling accurate analysis without ever observing real identities.
"How do we verify the engine itself isn't an exfiltration or supply chain risk?"
PrivacyScrubber is 100% auditable via standard browser DevTools and airplane-mode tests. It maintains zero backend API routes, zero phone-home telemetry, and enforces closed Shadow DOM boundaries to prevent script tampering.
"If an employee pastes a secret into an LLM, can't we request prompt deletion later?"
No. Once ingested by foundation models, corporate secrets enter training pipelines or persistent conversational logs. You cannot retract weights from a multi-billion-parameter neural network. Point-of-prompt ZTDS is the only definitive mitigation.
The 5-Step Audit Procedure for Zero-Trust AI Tools
Never take any vendor's privacy claims on faith. Security architects and compliance auditors can verify PrivacyScrubber's zero-exfiltration architecture in under 60 seconds with standard browser developer tools:
Open DevTools
Right-click anywhere on the PrivacyScrubber interface and choose Inspect.
Monitor Network
Navigate to the Network tab and clear existing entries to start with a blank stream.
Simulate Air-Gap
Enable physical Airplane Mode or select Offline from the DevTools throttling dropdown.
Execute Redaction
Paste sample corporate text containing names, emails, and financial data, then click Scrub PII.
Verify 0 Requests
Examine the Network panel. Confirm exactly 0 outbound requests were generated during scrubbing.
SIEM & Webhook Telemetry: Stream Zero-PII Audit Heartbeats
Traditional Data Loss Prevention (DLP) breaks under modern HTTPS AI traffic or requires intrusive SSL-decrypting proxies that centralize cleartext liability. PrivacyScrubber solves this paradox by executing sanitization locally in browser RAM and streaming cryptographically verified Zero-PII heartbeats directly into your corporate SIEM (Splunk, Datadog, Microsoft Sentinel, Elastic) or security Slack channels.
1. Shadow AI Fleet Visibility
Gain real-time telemetry across thousands of employee browser endpoints without installing intrusive kernel agents or slowing down LLM workflows.
2. Zero-PII Heartbeat Guarantee
The SIEM receives timestamped audit events, node status, and masked entity categories — with 0 bytes of employee prompt text or sensitive PII ever transmitted.
3. Universal SIEM & SOAR Hooks
Connect in 60 seconds using native HTTPS Webhooks compatible with Splunk HTTP Event Collector (HEC), Datadog Logs, Sentinel Data Connector, or Slack Security Channels.
Standardized ZTDS Audit Payload
When employees sanitize data before sending prompts to ChatGPT, Claude, or Gemini, PrivacyScrubber emits structured JSON heartbeats to your configured SIEM endpoint:
{
"event": "ZTDS_AUDIT_HEARTBEAT",
"timestamp": "2026-08-20T02:08:44.000Z",
"node": "Acme Corp - SecOps Fleet #4",
"status": "VERIFIED_ACTIVE",
"zero_server_guarantee": true,
"telemetry": {
"sanitization_engine": "Wasm/Local-Regex",
"entity_categories_neutralized": [
"NAME", "EMAIL", "API_KEY", "SSN_ID"
],
"framework_controls_triggered": [
"EU_AI_ACT_ART50", "SOC2_CC6_1", "ISO27001_A8_11"
],
"raw_pii_exfiltrated_bytes": 0
}
} Provision Webhook Ingest
Create an incoming HTTPS Webhook in Splunk (HEC), Datadog Logs Webhook, Microsoft Sentinel HTTP Data Collector, or your internal Slack Security channel.
Deploy Fleet-Wide via MDM
Push the Webhook endpoint to all corporate laptops using Chrome Enterprise Managed Policies (ps_siem_webhook_url). Zero user configuration required.
Automate Continuous Auditing
SOC analysts receive instant proof that all employee generative AI prompts are sanitized before cloud egress, satisfying continuous SOC 2 & ISO 27001 audit requirements.
Pre-Filled Vendor Security Assessment (VSA / SIG Lite)
Skip the 6-week security questionnaire backlog. Over 85% of standard cloud risk questions resolve to "N/A — 100% Client-Side Local RAM Execution". Filter by domain or export all 40 verified responses directly into OneTrust, ServiceNow, Archer, or Whistic.
Does PrivacyScrubber store, log, or persist customer prompt data or uploaded files on vendor servers?
NO. 100% of data tokenization, entity detection, and de-identification executes inside the client workstation volatile runtime (V8 heap memory or local stdio process). Zero bytes of customer text or files are ever stored, logged, or cached on any remote vendor server.
What is the data retention period for customer prompts and sensitive identifiers?
0 seconds. Data is strictly ephemeral. Session token maps exist in volatile RAM per browser tab or application process and are wiped instantly upon tab closure, window reload, or session termination.
Does PrivacyScrubber maintain backend databases or cloud object stores containing customer records?
NO. The application architecture is 100% serverless and databaseless for operational customer workloads. Static client bundles are distributed via CDN, and all computing operations occur strictly on the user machine.
Can PrivacyScrubber staff, support personnel, or engineers access customer prompts or PII?
NO. Zero vendor access. Because data never transits our infrastructure or reaches any vendor proxy, unauthorized personnel access is physically and mathematically impossible.
Does PrivacyScrubber train AI or machine learning models on customer prompts or sanitized inputs?
NO. PrivacyScrubber does not operate machine learning training pipelines and never ingests customer data for model training, reinforcement learning, or commercial benchmarking.
Are customer prompts or files transmitted over the internet to PrivacyScrubber servers during processing?
NO. Automated CI/CD network listeners and socket-level test harnesses confirm that exactly 0 HTTP, HTTPS, or WebSocket packets are emitted during data sanitization.
Does the application function in an air-gapped or offline environment?
YES. Once static client bundles are loaded, all regex tokenization, OCR parsing, and pseudonymization run without an active internet connection, verified in physical Airplane Mode.
What Content Security Policy (CSP) directives are enforced?
Strict CSP headers enforce connect-src 'self' for static assets and billing validation only. Background web workers operate in isolated sandboxes with zero network permissions.
Does the Chrome Extension require elevated permissions to read all external network traffic?
NO. PrivacyScrubber operates under Chrome Manifest V3 with minimal host permissions scoped strictly to supported AI interface DOMs (ChatGPT, Claude, Gemini). It does not intercept external network sockets.
How can internal enterprise security teams independently verify zero egress?
Directly via standard browser Developer Tools (F12 -> Network tab). Security engineers can observe zero outbound requests in real time without proprietary auditing software.
How many third-party subprocessors process or touch customer prompts or PII?
Exactly ZERO (0). No third-party APIs, OCR cloud services, or microservices are involved in the prompt sanitization pathway.
What third-party infrastructure is utilized for administrative and billing services?
Vercel (Edge CDN for static, public JavaScript/HTML asset delivery only) and PayPal / Paddle (B2B payment processing and invoice settlement). Neither receives prompt payloads.
Are standard Data Processing Agreements (DPAs) required with subprocessors?
NO. Under GDPR Article 28, subprocessor obligations apply only where customer data is transferred down a processing chain. With 0 subprocessors receiving data, the subprocessor liability chain is eliminated.
Are customer data subjects exposed to cross-border international data transfers (Schrems II)?
NO. Because data never leaves the client endpoint, cross-border transfers do not occur. Local data sovereignty is preserved without Standard Contractual Clauses (SCCs).
Do employees need individual logins or passwords to activate PrivacyScrubber?
NO. For TEAMS and Enterprise, activation is centralized via Master License Key and Chrome Enterprise Managed Policies (MDM / ExtensionInstallForcelist), eliminating employee credential sprawl.
Can employees disable or bypass corporate PII protection policies?
NO. When deployed via MDM, IT administrators can enforce ps_strict_enforce: true and lock configuration menus, preventing users from altering compliance profiles or disabling the shield.
How is role-based access control (RBAC) enforced across enterprise teams?
Two-Tier Fleet Governance: Central CISO hard lock defines immutable compliance baselines across the fleet, while local users can define temporary, local-only deal codenames in isolated tab memory.
What telemetry is transmitted for software license compliance?
Opaque license key validation only (checked every 24h). Zero prompt text, user identity, or sanitized metrics are included in the license validation call.
What encryption algorithms protect session data and peer transfers?
XChaCha20-Poly1305 authenticated symmetric encryption with 256-bit keys via libsodium WebAssembly for zero-knowledge session handoff.
How are master keys derived for encrypted session handoff?
Argon2id (password-based key derivation function, resistant to GPU and ASIC brute-force attacks) configured with 64MB memory limit and 3 iterations.
Where are cryptographic encryption keys stored?
Strictly in local client volatile RAM. Keys are never transmitted to PrivacyScrubber or third-party servers.
How does PrivacyScrubber support GDPR Article 17 ('Right to be Forgotten') in RAG vector databases?
O(1) Cryptographic Erasure. By rotating or deleting the ephemeral session key, all vector embeddings derived from that session become irrecoverable noise without expensive index rebuilds.
Does PrivacyScrubber use proprietary, closed-source encryption ciphers?
NO. Only standardized, audited open-source cryptographic primitives from libsodium (WASM) and the Web Crypto API are utilized.
Can the client-side code be inspected and audited by customer AppSec teams?
YES. The codebase consists of open, unminified or source-mapped client JavaScript, CSS, and WebAssembly directly inspectable in browser developer tools.
Does the application execute dynamic remote code (eval or remote script injection)?
NO. Strictly forbidden by Manifest V3 and CSP. All execution logic is pre-compiled and bundled within the extension package with zero dynamic remote eval.
What is the vulnerability disclosure and patching SLA?
Documented policy at /vulnerability-disclosure/. Critical security patches are deployed within 24 hours to the public registry.
Does PrivacyScrubber perform automated Dependency Scanning and SAST?
YES. Automated CI/CD pipelines run pre-commit dependency audits, IP guards, single-source checks, and socket egress listeners before every release.
Are software dependencies pinned with cryptographic hash integrity?
YES. All npm packages and WASM binaries enforce Subresource Integrity (SRI) hashes and locked package-lock.json version pinning.
What happens to employee AI sanitization if PrivacyScrubber servers experience an outage?
Zero Impact. Because execution is 100% local, the extension and SDK continue sanitizing prompts normally even during a total vendor network outage.
What is the recovery point objective (RPO) and recovery time objective (RTO) for customer data?
RPO = 0s / RTO = 0s. Because customer data is never stored on vendor servers, disaster recovery of vendor servers never impacts customer data integrity.
Can the organization maintain an air-gapped or on-premise source code escrow?
YES. Enterprise licenses include an on-premise source code license and local private build pipeline support.
What uptime SLA is provided for hosted endpoints?
99.9% for static CDN delivery and license validation endpoints. Local runtime uptime is 100% bound to the host workstation.
How does PrivacyScrubber address GDPR Article 25 ('Data Protection by Design and Default')?
By enforcing point-of-prompt de-identification at the client boundary before network transmission, data minimization is automated by default.
How does PrivacyScrubber address HIPAA Safe Harbor (45 CFR § 164.514)?
Built-in HIPAA detection profile strips all 18 PHI identifiers (names, dates, geographic data, MRNs, SSNs, phone numbers) in local memory prior to AI ingestion.
How does PrivacyScrubber satisfy SOC 2 Type II controls?
Directly satisfies CC6.1, CC6.6, and CC6.7 (Boundary Protection and Data Exfiltration Prevention) by ensuring sensitive data never leaves endpoint control.
How does PrivacyScrubber comply with the EU AI Act (Article 50)?
Prevents unredacted corporate records and personal profiles from being processed by high-risk or general-purpose AI models without data minimization.
What patent protection governs the Zero-Trust Data Sanitization architecture?
Protected under Israel Patent Office (ILPO) Patent Application No. 331905 (filed 14/09/2026), titled 'SYSTEM AND METHOD FOR CLIENT-SIDE ZERO-TRUST DATA SANITIZATION AND CRYPTOGRAPHIC SESSION HANDOFF IN ARTIFICIAL INTELLIGENCE WORKFLOWS'. Paris Convention & 35 U.S.C. § 119 priority locked through 14/09/2027.
What is the WIPO DAS Access Control Code for automated electronic priority document retrieval?
WIPO DAS Access Control Code: B17B (Office: IL, Application: 331905). Enables automated zero-paper electronic priority document retrieval by USPTO, EPO, JPO, CNIPA, UK IPO, and PCT receiving offices.
Is the trademark ZTDS legally registered?
YES. Registered word mark ZTDS (Zero-Trust Data Sanitization) with the Israel Patent Office (Order #182655957, Nice Classes 9 & 42), with Paris Convention international priority through 20/03/2027.
Is the technical architecture published on international standards bodies and peer-reviewed repositories?
YES. Published on the official IETF standards track (draft-sibiryakov-ztds-protocol-00), CERN Zenodo (DOI 10.5281/zenodo.22058770), Center for Open Science OSF (DOI 10.17605/OSF.IO/5BYJF), and SSRN Elsevier (Abstract 7335581).
DPA Subprocessor Waiver & Legal Exemption Certificate
Standard legal determination for General Counsel, Data Protection Officers (DPO), and Vendor Procurement Committees.
TO: Office of General Counsel · Data Protection Officer (DPO) · Enterprise Procurement Board
SUBJECT: Determination of Non-Applicability of Third-Party DPA / BAA for PrivacyScrubber (ZTDS Architecture)
1. STATUTORY CONTROLLER-TO-PROCESSOR ANALYSIS:
Under European Union General Data Protection Regulation (GDPR) Article 4(8) and UK GDPR, a "Processor" is defined as a natural or legal person that processes personal data on behalf of the controller. Because PrivacyScrubber operates strictly as an in-memory client-side software utility executing within endpoint host memory (V8 heap / local stdio), PrivacyScrubber never takes custody, possession, transmission, or storage of customer data. Consequently, the statutory relationship of Controller-to-Processor does not arise, rendering standard 30-page Data Processing Agreements legally non-applicable.
2. HIPAA SAFE HARBOR & BUSINESS ASSOCIATE EXEMPTION:
Under 45 CFR § 160.103 and § 164.502(e), a Business Associate Agreement (BAA) is required only when a vendor receives Protected Health Information (PHI) from a covered entity. Because all 18 HIPAA Safe Harbor identifiers are stripped in local memory before prompt transmission, 0 bytes of PHI ever reach vendor infrastructure, eliminating statutory BAA obligations.
3. SUBPROCESSOR CHAIN LIABILITY (GDPR ART. 28):
Exactly ZERO (0) third-party subprocessors participate in the prompt data processing path. Administrative CDNs (Vercel) deliver static public JavaScript code, and payment gateways (PayPal/Paddle) process invoice transactions strictly decoupled from customer prompt payloads.
4. INTELLECTUAL PROPERTY & GOVERNMENT PRIORITY VERIFICATION:
The Zero-Trust Data Sanitization (ZTDS) architecture is protected under Israel Patent Office Patent Application No. 331905 (Tracking ID: 94221, filed 14/09/2026). International priority is electronically certifiable via WIPO DAS Access Control Code: B17B (Office: IL, priority locked through 14/09/2027 under Paris Convention and 35 U.S.C. § 119). Word mark ZTDS is registered under Order #182655957 (Classes 9 & 42).
5. FINAL PROCUREMENT DETERMINATION:
PrivacyScrubber is approved for rapid enterprise onboarding under standard commercial software license terms across TEAMS ($99/mo flat rate) and Developer SDK ($199/mo or $1,990/yr) with zero vendor security review delays.
Download the Printable CISO AI Security Guide
Join 3,000+ security engineering leaders. Instantly access the mathematical proofs, local execution benchmarks, and our SOC 2 compliance checklist.
- VDI & Air-gapped Deployment Protocol
- Pre-filled Vendor Risk Questionnaire (VRQ)
Unlock Enterprise Benchmarks
Enter your work email to download the CISO Whitepaper and receive a 14-day TEAMS trial key.
By authenticating, you agree to our Zero-Trust data policy.
Technical Governance FAQ
How does PrivacyScrubber prevent "Model Learning" from sensitive data?
By tokenizing PII at the semantic boundary (the prompt input) prior to network transmission, foundational models (ChatGPT, Claude, Gemini) never receive the original data. This eliminates sensitive company data from ever entering training datasets or short-term context cache.
Is ZTDS auditable for SOC 2 Type II compliance?
Yes. Because data sanitization is independently verifiable in the browser's Network tab with zero network egress, CISOs provide forensic proof that customer PII never leaves the corporate endpoint, satisfying SOC 2 CC6.1 and CC6.6 Trust Services Criteria without complex third-party vendor audits.
How does SIEM & Webhook logging work without collecting sensitive data?
PrivacyScrubber emits structured telemetry heartbeats containing timestamp, fleet node identifier, and sanitized entity categories. Prompt content and raw PII values are mathematically excluded from the payload, providing 100% SIEM compliance visibility with zero toxic data custody.
Does this work in air-gapped and offline VDI environments?
PrivacyScrubber operates 100% offline once the client bundle is loaded. For secure enterprise enclaves and SCIF/VDI environments, we provide pre-packaged self-contained deployments with zero remote dependencies.
