Zero-Trust Architecture: 100% Local In-RAM Processing

Give Enterprise Teams AI Tools Without Server Risk.

Traditional network firewalls and cloud proxies can't inspect encrypted LLM prompts without intercepting corporate data. PrivacyScrubber tokenizes sensitive corporate PII locally at the browser endpoint in under 1.8ms — before prompt payloads reach OpenAI, Anthropic, or external AI models.

Airplane Mode Verified Zero Cloud Egress <1.8ms RAM Latency Patent Pending (App. 331905 · WIPO DAS B17B)
Zero-Trust Data Sanitization Architecture Explainer
3-Min Brief · Sound On

Video Brief: Securing the LLM Layer

Client-Side ZTDS vs Cloud DLP Proxies Explained

02:48
EU AI Act (Art. 50)
NIST AI RMF 1.0
ISO 27001 A.8.11
SOC 2 Type II (CC6.1)
HIPAA Safe Harbor
GDPR Articles 25/32
Executive Paradigm Shift

Shadow AI Governance: The "Yes-to-AI" Framework

Legacy Approach: Wholesale Prohibition

Blocking AI domains at corporate firewalls or MDMs invariably drives employees into unmanaged "Shadow AI" channels — using personal laptops, unencrypted mobile devices, and unmonitored home networks to complete their daily work.

Outcome: Complete Loss of Visibility & Audit Trail

The ZTDS Paradigm: Endpoint Empowerment

Equip workforce teams with approved generative AI workflows by stripping and tokenizing PII at the browser endpoint in volatile memory. CISOs guarantee regulatory compliance without ever storing, seeing, or logging cleartext corporate data.

Outcome: Mathematically Verified Zero-Egress Innovation
Zero-Server Orchestration

Architecture Layer Cake: Client-Side Data Isolation

01

Endpoint Ingestion & Sandboxing

0ms Network Latency

Data remains strictly local; scanned and tokenized entirely in browser RAM using WebAssembly and regex heuristics. Zero bytes leave the physical device perimeter.

02

Deterministic Pseudonymization (ZTDS)

Volatile RAM Seed

Sensitive entities (names, SSNs, MRNs, API tokens) are replaced with role-preserving badges (e.g. [CLIENT_1], [API_KEY_1]). Session map exists strictly in RAM and is permanently purged on tab close.

03

De-Identified Cloud Model Ingestion

0 Bytes Real PII Egress

External LLM servers (ChatGPT, Claude, Gemini) receive only sanitized tokens with full linguistic syntax. Zero real-world customer records or trade secrets can be leaked into model training weights.

Enterprise Playbook

Strategic Implementation Roadmap

Phase 01

Audit & Baseline

Map high-risk generative AI ingestion paths across departments (Legal contracts, HR payroll, Engineering code repos).

Phase 02

Shadow AI Amnesty

Deploy PrivacyScrubber to give employees an approved "safe path" to continue using AI tools without risking exfiltration.

Phase 03

In-DOM Enforcement

Roll out the Chrome Extension via Google Workspace Admin / MDM to enforce local tokenization directly inside ChatGPT & Claude.

Phase 04

Continuous SIEM Telemetry

Stream zero-PII audit heartbeats to corporate SIEM (Splunk, Datadog, Sentinel) for continuous SOC 2 & ISO 27001 proof.

Regulatory Control Frameworks

Standardized Compliance & Control Mappings

OWASP Top 10 for LLMs

Edge-level sanitization addresses three critical OWASP LLM vulnerabilities at the semantic layer:

  • LLM01: Prompt Injection
    Intercepts prompts at the DOM level, neutralizing structural exploits before model inference.
  • LLM02: Insecure Output Handling
    Executes detokenization (Reveal) 100% client-side in RAM, preventing leaks over insecure networks.
  • LLM06: Sensitive Info Disclosure
    Enforces deterministic masking of credentials, API tokens, and customer PII before transmission.
Semantic Protection Layer

NIST AI Risk Management

Direct alignment with NIST AI RMF 1.0 core sub-functions:

  • GOVERN-1.2
    Enforces technical boundaries for acceptable enterprise generative AI use.
  • MAP-1.5
    Tracks and neutralizes corporate data leakage vectors prior to network egress.
  • MEASURE-2.6
    Quantifies masked entity volumes via client-side telemetry with zero PII retention.
  • MANAGE-1.5
    Actively mitigates exfiltration risks directly at the prompt perimeter.
NIST AI RMF 1.0 Mapped

Regulatory Data Masking

Automates technical controls required by global privacy and cybersecurity frameworks:

  • EU AI Act (Aug 2026): Article 50 pre-AI data minimization & transparency controls.
  • ISO 27001 A.8.11: Automates data masking compliance directly at the user endpoint.
  • GDPR Articles 25/32: Implements privacy-by-design through ephemeral tokenization.
  • HIPAA Safe Harbor: De-identifies 18 PHI elements locally before cloud transit.
  • SOC 2 CC6.1 / CC6.6: Restricts boundary exfiltration with cryptographic audit proofs.
  • Patent Pending Architecture: ILPO App. 331905 (Client-Side ZTDS & Cryptographic Handoff).
EU AI Act, ISO & GDPR Compliant

AI Governance Board Recommendations

When forming your organization's Generative AI Committee, blanket domain blocklists fail because they inevitably trigger unmonitored shadow AI workarounds. Governance committees should implement these three foundational policies:

  • Adopt a "Yes-to-AI" Standard: Provide staff with approved productivity tools equipped with client-side sanitization.
  • Mandate Endpoint Pre-Sanitization: Ensure prompt payloads pass through local ZTDS filters before transmission.
  • Centralize Rules Governance: Distribute unified regex policies for internal codenames, AWS keys, and customer IDs.

TPRM & Vendor Risk Assessment Fast-Track

Standard SaaS procurements stall for 3–6 months during Third-Party Risk Management (TPRM) audits because vendors act as Data Processors. ZTDS eliminates this entire bureaucratic bottleneck:

  • No Processor Status: Zero prompt bytes are transmitted to our servers; PrivacyScrubber never acts as a Data Processor under GDPR Art. 28.
  • CAIQ Pre-Cleared: Over 80% of standard Cloud Security Alliance CAIQ questionnaire lines resolve to "N/A — Local RAM Execution".
  • Same-Day Clearance: Legal and InfoSec committees approve PrivacyScrubber as an air-gapped client utility, bypassing the DPA queue.
Procurement Economics

Deployment Economics: Time-to-Value

Legacy Cloud DLP Gateway

Requires formal Vendor Risk Assessment (VRA), customized Data Processing Addendum (DPA) legal reviews, root CA certificate installations, and network-wide proxy certification.

3–6 Months

ZTDS Client-Side Deployment

Zero data transit means zero regulatory exposure. Bypasses DPA requirements, vendor sub-processor audits, and invasive network proxy re-routing entirely.

0 Days
Executive Review

CISO Objection Handling Matrix

Common Objection

"Won't masking sensitive data break the AI model's contextual understanding?"

Technical Reality

ZTDS deploys semantic role-preserving placeholders (e.g. [PATIENT_1], [ORGANIZATION_2]). The LLM retains 100% of grammatical syntax and relational context, enabling accurate analysis without ever observing real identities.

Common Objection

"How do we verify the engine itself isn't an exfiltration or supply chain risk?"

Technical Reality

PrivacyScrubber is 100% auditable via standard browser DevTools and airplane-mode tests. It maintains zero backend API routes, zero phone-home telemetry, and enforces closed Shadow DOM boundaries to prevent script tampering.

Immutable Leak Vector

"If an employee pastes a secret into an LLM, can't we request prompt deletion later?"

Technical Reality

No. Once ingested by foundation models, corporate secrets enter training pipelines or persistent conversational logs. You cannot retract weights from a multi-billion-parameter neural network. Point-of-prompt ZTDS is the only definitive mitigation.

Independent Verification

The 5-Step Audit Procedure for Zero-Trust AI Tools

Click Steps to Audit · 0/5 Verified

Never take any vendor's privacy claims on faith. Security architects and compliance auditors can verify PrivacyScrubber's zero-exfiltration architecture in under 60 seconds with standard browser developer tools:

Step 01

Open DevTools

Right-click anywhere on the PrivacyScrubber interface and choose Inspect.

Option + Cmd + I
Step 02

Monitor Network

Navigate to the Network tab and clear existing entries to start with a blank stream.

Track Outbound Packets
Step 03

Simulate Air-Gap

Enable physical Airplane Mode or select Offline from the DevTools throttling dropdown.

Hardware Sovereignty
Step 04

Execute Redaction

Paste sample corporate text containing names, emails, and financial data, then click Scrub PII.

Step 05

Verify 0 Requests

Examine the Network panel. Confirm exactly 0 outbound requests were generated during scrubbing.

100% Local Proven
Continuous Telemetry & SIEM Ingestion

SIEM & Webhook Telemetry: Stream Zero-PII Audit Heartbeats

Traditional Data Loss Prevention (DLP) breaks under modern HTTPS AI traffic or requires intrusive SSL-decrypting proxies that centralize cleartext liability. PrivacyScrubber solves this paradox by executing sanitization locally in browser RAM and streaming cryptographically verified Zero-PII heartbeats directly into your corporate SIEM (Splunk, Datadog, Microsoft Sentinel, Elastic) or security Slack channels.

1. Shadow AI Fleet Visibility

Gain real-time telemetry across thousands of employee browser endpoints without installing intrusive kernel agents or slowing down LLM workflows.

Continuous Visibility

2. Zero-PII Heartbeat Guarantee

The SIEM receives timestamped audit events, node status, and masked entity categories — with 0 bytes of employee prompt text or sensitive PII ever transmitted.

Zero Toxic Data Debt

3. Universal SIEM & SOAR Hooks

Connect in 60 seconds using native HTTPS Webhooks compatible with Splunk HTTP Event Collector (HEC), Datadog Logs, Sentinel Data Connector, or Slack Security Channels.

Instant Ingestion
Heartbeat Data Schema

Standardized ZTDS Audit Payload

When employees sanitize data before sending prompts to ChatGPT, Claude, or Gemini, PrivacyScrubber emits structured JSON heartbeats to your configured SIEM endpoint:

Timestamp & Node ID: Identifies the corporate department, node UUID, or fleet container.
Zero-Server Verification: Confirms local-only in-memory RAM processing at time of execution.
Regulatory Mappings: Logs compliance coverage (GDPR Art. 32, SOC 2 CC6.1, ISO 27001 A.8.11, HIPAA).
POST https://siem.corp.internal/v1/ztds-events200 OK
{
  "event": "ZTDS_AUDIT_HEARTBEAT",
  "timestamp": "2026-08-20T02:08:44.000Z",
  "node": "Acme Corp - SecOps Fleet #4",
  "status": "VERIFIED_ACTIVE",
  "zero_server_guarantee": true,
  "telemetry": {
    "sanitization_engine": "Wasm/Local-Regex",
    "entity_categories_neutralized": [
      "NAME", "EMAIL", "API_KEY", "SSN_ID"
    ],
    "framework_controls_triggered": [
      "EU_AI_ACT_ART50", "SOC2_CC6_1", "ISO27001_A8_11"
    ],
    "raw_pii_exfiltrated_bytes": 0
  }
}
Step 01

Provision Webhook Ingest

Create an incoming HTTPS Webhook in Splunk (HEC), Datadog Logs Webhook, Microsoft Sentinel HTTP Data Collector, or your internal Slack Security channel.

Step 02

Deploy Fleet-Wide via MDM

Push the Webhook endpoint to all corporate laptops using Chrome Enterprise Managed Policies (ps_siem_webhook_url). Zero user configuration required.

Step 03

Automate Continuous Auditing

SOC analysts receive instant proof that all employee generative AI prompts are sanitized before cloud egress, satisfying continuous SOC 2 & ISO 27001 audit requirements.

0-Day Vendor Approval · 40-Point SIG Lite & CAIQ Matrix

Pre-Filled Vendor Security Assessment (VSA / SIG Lite)

Skip the 6-week security questionnaire backlog. Over 85% of standard cloud risk questions resolve to "N/A — 100% Client-Side Local RAM Execution". Filter by domain or export all 40 verified responses directly into OneTrust, ServiceNow, Archer, or Whistic.

DC-01Data Custody
N/A — Client RAM Only

Does PrivacyScrubber store, log, or persist customer prompt data or uploaded files on vendor servers?

NO. 100% of data tokenization, entity detection, and de-identification executes inside the client workstation volatile runtime (V8 heap memory or local stdio process). Zero bytes of customer text or files are ever stored, logged, or cached on any remote vendor server.

Reference: Architecture: 100% Client-Side In-Memory Execution
DC-02Data Custody
0 Seconds (Ephemeral)

What is the data retention period for customer prompts and sensitive identifiers?

0 seconds. Data is strictly ephemeral. Session token maps exist in volatile RAM per browser tab or application process and are wiped instantly upon tab closure, window reload, or session termination.

Reference: RAM Heap Isolation & Ephemeral Destruction
DC-03Data Custody
Zero Database Infrastructure

Does PrivacyScrubber maintain backend databases or cloud object stores containing customer records?

NO. The application architecture is 100% serverless and databaseless for operational customer workloads. Static client bundles are distributed via CDN, and all computing operations occur strictly on the user machine.

Reference: Zero Data Custody Posture
DC-04Data Custody
Zero Vendor Access

Can PrivacyScrubber staff, support personnel, or engineers access customer prompts or PII?

NO. Zero vendor access. Because data never transits our infrastructure or reaches any vendor proxy, unauthorized personnel access is physically and mathematically impossible.

Reference: Zero Custody Boundary
DC-05Data Custody
Zero Model Training

Does PrivacyScrubber train AI or machine learning models on customer prompts or sanitized inputs?

NO. PrivacyScrubber does not operate machine learning training pipelines and never ingests customer data for model training, reinforcement learning, or commercial benchmarking.

Reference: Zero Training Data Policy
NE-01Network & Egress
0 Outbound Egress Packets

Are customer prompts or files transmitted over the internet to PrivacyScrubber servers during processing?

NO. Automated CI/CD network listeners and socket-level test harnesses confirm that exactly 0 HTTP, HTTPS, or WebSocket packets are emitted during data sanitization.

Reference: Verified via: scripts/verify-zero-egress.js (0 sockets, 0 bytes)
NE-02Network & Egress
100% Offline Capable

Does the application function in an air-gapped or offline environment?

YES. Once static client bundles are loaded, all regex tokenization, OCR parsing, and pseudonymization run without an active internet connection, verified in physical Airplane Mode.

Reference: Air-Gapped Operation Protocol
NE-03Network & Egress
Strict connect-src 'self'

What Content Security Policy (CSP) directives are enforced?

Strict CSP headers enforce connect-src 'self' for static assets and billing validation only. Background web workers operate in isolated sandboxes with zero network permissions.

Reference: W3C CSP Level 3 Compliance
NE-04Network & Egress
Scoped DOM Only (MV3)

Does the Chrome Extension require elevated permissions to read all external network traffic?

NO. PrivacyScrubber operates under Chrome Manifest V3 with minimal host permissions scoped strictly to supported AI interface DOMs (ChatGPT, Claude, Gemini). It does not intercept external network sockets.

Reference: Chrome Extension MV3 Least-Privilege Architecture
NE-05Network & Egress
60-Second DevTools Audit

How can internal enterprise security teams independently verify zero egress?

Directly via standard browser Developer Tools (F12 -> Network tab). Security engineers can observe zero outbound requests in real time without proprietary auditing software.

Reference: Forensic Network Verification Protocol
SP-01Subprocessors
0 Subprocessors (Prompt Path)

How many third-party subprocessors process or touch customer prompts or PII?

Exactly ZERO (0). No third-party APIs, OCR cloud services, or microservices are involved in the prompt sanitization pathway.

Reference: Authorized Subprocessors Register (https://privacyscrubber.com/subprocessors/)
SP-02Subprocessors
Administrative Decoupling

What third-party infrastructure is utilized for administrative and billing services?

Vercel (Edge CDN for static, public JavaScript/HTML asset delivery only) and PayPal / Paddle (B2B payment processing and invoice settlement). Neither receives prompt payloads.

Reference: Administrative Boundary Isolation
SP-03Subprocessors
Subprocessor Chain Exempt

Are standard Data Processing Agreements (DPAs) required with subprocessors?

NO. Under GDPR Article 28, subprocessor obligations apply only where customer data is transferred down a processing chain. With 0 subprocessors receiving data, the subprocessor liability chain is eliminated.

Reference: GDPR Article 28 Statutory Analysis
SP-04Subprocessors
Zero Cross-Border Transfer

Are customer data subjects exposed to cross-border international data transfers (Schrems II)?

NO. Because data never leaves the client endpoint, cross-border transfers do not occur. Local data sovereignty is preserved without Standard Contractual Clauses (SCCs).

Reference: GDPR Chapter V Workstation Sovereignty
IA-01Identity & Fleet
Zero Password Sprawl

Do employees need individual logins or passwords to activate PrivacyScrubber?

NO. For TEAMS and Enterprise, activation is centralized via Master License Key and Chrome Enterprise Managed Policies (MDM / ExtensionInstallForcelist), eliminating employee credential sprawl.

Reference: Chrome Enterprise MDM Blueprint
IA-02Identity & Fleet
CISO Policy Hard Lock

Can employees disable or bypass corporate PII protection policies?

NO. When deployed via MDM, IT administrators can enforce ps_strict_enforce: true and lock configuration menus, preventing users from altering compliance profiles or disabling the shield.

Reference: Two-Tier Fleet Governance Architecture
IA-03Identity & Fleet
Central Lock + Local Flexibility

How is role-based access control (RBAC) enforced across enterprise teams?

Two-Tier Fleet Governance: Central CISO hard lock defines immutable compliance baselines across the fleet, while local users can define temporary, local-only deal codenames in isolated tab memory.

Reference: TEAMS Governance Hub ($99/mo flat)
IA-04Identity & Fleet
Opaque ID Only (Zero PII)

What telemetry is transmitted for software license compliance?

Opaque license key validation only (checked every 24h). Zero prompt text, user identity, or sanitized metrics are included in the license validation call.

Reference: Approved Network Exceptions SSOT
CR-01Cryptography
XChaCha20-Poly1305 (256-Bit)

What encryption algorithms protect session data and peer transfers?

XChaCha20-Poly1305 authenticated symmetric encryption with 256-bit keys via libsodium WebAssembly for zero-knowledge session handoff.

Reference: IETF RFC 8439 Cryptographic Standard
CR-02Cryptography
Argon2id (Memory-Hard)

How are master keys derived for encrypted session handoff?

Argon2id (password-based key derivation function, resistant to GPU and ASIC brute-force attacks) configured with 64MB memory limit and 3 iterations.

Reference: Password Hashing Competition (PHC) Standard
CR-03Cryptography
Volatile RAM Only

Where are cryptographic encryption keys stored?

Strictly in local client volatile RAM. Keys are never transmitted to PrivacyScrubber or third-party servers.

Reference: Zero Server Key Custody
CR-04Cryptography
O(1) Cryptographic KMS Erasure

How does PrivacyScrubber support GDPR Article 17 ('Right to be Forgotten') in RAG vector databases?

O(1) Cryptographic Erasure. By rotating or deleting the ephemeral session key, all vector embeddings derived from that session become irrecoverable noise without expensive index rebuilds.

Reference: LlamaIndex & LangChain Vector Sanitizer
CR-05Cryptography
Standardized Open Cryptography

Does PrivacyScrubber use proprietary, closed-source encryption ciphers?

NO. Only standardized, audited open-source cryptographic primitives from libsodium (WASM) and the Web Crypto API are utilized.

Reference: Open Cryptographic Verification
VM-01AppSec & SDLC
100% Auditable Source

Can the client-side code be inspected and audited by customer AppSec teams?

YES. The codebase consists of open, unminified or source-mapped client JavaScript, CSS, and WebAssembly directly inspectable in browser developer tools.

Reference: Transparent Client-Side Architecture
VM-02AppSec & SDLC
Zero Remote Code Execution

Does the application execute dynamic remote code (eval or remote script injection)?

NO. Strictly forbidden by Manifest V3 and CSP. All execution logic is pre-compiled and bundled within the extension package with zero dynamic remote eval.

Reference: Manifest V3 Security Mandate
VM-03AppSec & SDLC
24-Hour Critical SLA

What is the vulnerability disclosure and patching SLA?

Documented policy at /vulnerability-disclosure/. Critical security patches are deployed within 24 hours to the public registry.

Reference: Vulnerability Disclosure Policy
VM-04AppSec & SDLC
Automated CI/CD Gating

Does PrivacyScrubber perform automated Dependency Scanning and SAST?

YES. Automated CI/CD pipelines run pre-commit dependency audits, IP guards, single-source checks, and socket egress listeners before every release.

Reference: Husky Pre-Commit & Pre-Push Pipeline
VM-05AppSec & SDLC
Strict SRI & Lockfile Pinning

Are software dependencies pinned with cryptographic hash integrity?

YES. All npm packages and WASM binaries enforce Subresource Integrity (SRI) hashes and locked package-lock.json version pinning.

Reference: Supply Chain Security Standard
BC-01Disaster Recovery
Zero Operational Impact

What happens to employee AI sanitization if PrivacyScrubber servers experience an outage?

Zero Impact. Because execution is 100% local, the extension and SDK continue sanitizing prompts normally even during a total vendor network outage.

Reference: Autonomous Local Runtime
BC-02Disaster Recovery
RPO = 0s / RTO = 0s

What is the recovery point objective (RPO) and recovery time objective (RTO) for customer data?

RPO = 0s / RTO = 0s. Because customer data is never stored on vendor servers, disaster recovery of vendor servers never impacts customer data integrity.

Reference: Zero Server Data Liability
BC-03Disaster Recovery
On-Premise Source License

Can the organization maintain an air-gapped or on-premise source code escrow?

YES. Enterprise licenses include an on-premise source code license and local private build pipeline support.

Reference: Enterprise Air-Gapped Licensing
BC-04Disaster Recovery
99.9% CDN Availability

What uptime SLA is provided for hosted endpoints?

99.9% for static CDN delivery and license validation endpoints. Local runtime uptime is 100% bound to the host workstation.

Reference: Commercial Service Level Agreement
CC-01Regulatory & IP
Automated Data Minimization

How does PrivacyScrubber address GDPR Article 25 ('Data Protection by Design and Default')?

By enforcing point-of-prompt de-identification at the client boundary before network transmission, data minimization is automated by default.

Reference: GDPR Art. 25 Statutory Compliance
CC-02Regulatory & IP
18 Safe Harbor Identifiers Stripped

How does PrivacyScrubber address HIPAA Safe Harbor (45 CFR § 164.514)?

Built-in HIPAA detection profile strips all 18 PHI identifiers (names, dates, geographic data, MRNs, SSNs, phone numbers) in local memory prior to AI ingestion.

Reference: HIPAA Safe Harbor De-Identification Standard
CC-03Regulatory & IP
CC6.1 / CC6.6 / CC6.7 Satisfied

How does PrivacyScrubber satisfy SOC 2 Type II controls?

Directly satisfies CC6.1, CC6.6, and CC6.7 (Boundary Protection and Data Exfiltration Prevention) by ensuring sensitive data never leaves endpoint control.

Reference: SOC 2 Type II Trust Services Criteria
CC-04Regulatory & IP
Pre-Emptive Edge Compliance

How does PrivacyScrubber comply with the EU AI Act (Article 50)?

Prevents unredacted corporate records and personal profiles from being processed by high-risk or general-purpose AI models without data minimization.

Reference: EU AI Act Article 50 Governance
IP-01Regulatory & IP
IL 331905 (Tracking ID: 94221)

What patent protection governs the Zero-Trust Data Sanitization architecture?

Protected under Israel Patent Office (ILPO) Patent Application No. 331905 (filed 14/09/2026), titled 'SYSTEM AND METHOD FOR CLIENT-SIDE ZERO-TRUST DATA SANITIZATION AND CRYPTOGRAPHIC SESSION HANDOFF IN ARTIFICIAL INTELLIGENCE WORKFLOWS'. Paris Convention & 35 U.S.C. § 119 priority locked through 14/09/2027.

Reference: Israel Patent Office Official Filing
IP-02Regulatory & IP
WIPO DAS Code: B17B

What is the WIPO DAS Access Control Code for automated electronic priority document retrieval?

WIPO DAS Access Control Code: B17B (Office: IL, Application: 331905). Enables automated zero-paper electronic priority document retrieval by USPTO, EPO, JPO, CNIPA, UK IPO, and PCT receiving offices.

Reference: WIPO Digital Access Service (DAS)
IP-03Regulatory & IP
ILPO Registered Word Mark

Is the trademark ZTDS legally registered?

YES. Registered word mark ZTDS (Zero-Trust Data Sanitization) with the Israel Patent Office (Order #182655957, Nice Classes 9 & 42), with Paris Convention international priority through 20/03/2027.

Reference: Israel Patent Office Order #182655957
IP-04Regulatory & IP
IETF Track & 4 DOIs

Is the technical architecture published on international standards bodies and peer-reviewed repositories?

YES. Published on the official IETF standards track (draft-sibiryakov-ztds-protocol-00), CERN Zenodo (DOI 10.5281/zenodo.22058770), Center for Open Science OSF (DOI 10.17605/OSF.IO/5BYJF), and SSRN Elsevier (Abstract 7335581).

Reference: IETF & Open-Science Corpus
Statutory Non-Applicability Determination

DPA Subprocessor Waiver & Legal Exemption Certificate

Standard legal determination for General Counsel, Data Protection Officers (DPO), and Vendor Procurement Committees.

LEGAL CERTIFICATE // STATUTORY EXEMPTION FROM DATA PROCESSING ADDENDUM (DPA)

TO: Office of General Counsel · Data Protection Officer (DPO) · Enterprise Procurement Board

SUBJECT: Determination of Non-Applicability of Third-Party DPA / BAA for PrivacyScrubber (ZTDS Architecture)

1. STATUTORY CONTROLLER-TO-PROCESSOR ANALYSIS:
Under European Union General Data Protection Regulation (GDPR) Article 4(8) and UK GDPR, a "Processor" is defined as a natural or legal person that processes personal data on behalf of the controller. Because PrivacyScrubber operates strictly as an in-memory client-side software utility executing within endpoint host memory (V8 heap / local stdio), PrivacyScrubber never takes custody, possession, transmission, or storage of customer data. Consequently, the statutory relationship of Controller-to-Processor does not arise, rendering standard 30-page Data Processing Agreements legally non-applicable.

2. HIPAA SAFE HARBOR & BUSINESS ASSOCIATE EXEMPTION:
Under 45 CFR § 160.103 and § 164.502(e), a Business Associate Agreement (BAA) is required only when a vendor receives Protected Health Information (PHI) from a covered entity. Because all 18 HIPAA Safe Harbor identifiers are stripped in local memory before prompt transmission, 0 bytes of PHI ever reach vendor infrastructure, eliminating statutory BAA obligations.

3. SUBPROCESSOR CHAIN LIABILITY (GDPR ART. 28):
Exactly ZERO (0) third-party subprocessors participate in the prompt data processing path. Administrative CDNs (Vercel) deliver static public JavaScript code, and payment gateways (PayPal/Paddle) process invoice transactions strictly decoupled from customer prompt payloads.

4. INTELLECTUAL PROPERTY & GOVERNMENT PRIORITY VERIFICATION:
The Zero-Trust Data Sanitization (ZTDS) architecture is protected under Israel Patent Office Patent Application No. 331905 (Tracking ID: 94221, filed 14/09/2026). International priority is electronically certifiable via WIPO DAS Access Control Code: B17B (Office: IL, priority locked through 14/09/2027 under Paris Convention and 35 U.S.C. § 119). Word mark ZTDS is registered under Order #182655957 (Classes 9 & 42).

5. FINAL PROCUREMENT DETERMINATION:
PrivacyScrubber is approved for rapid enterprise onboarding under standard commercial software license terms across TEAMS ($99/mo flat rate) and Developer SDK ($199/mo or $1,990/yr) with zero vendor security review delays.

Restricted Access

Download the Printable CISO AI Security Guide

Join 3,000+ security engineering leaders. Instantly access the mathematical proofs, local execution benchmarks, and our SOC 2 compliance checklist.

  • VDI & Air-gapped Deployment Protocol
  • Pre-filled Vendor Risk Questionnaire (VRQ)

Unlock Enterprise Benchmarks

Enter your work email to download the CISO Whitepaper and receive a 14-day TEAMS trial key.

By authenticating, you agree to our Zero-Trust data policy.

CISO Knowledge Base

Technical Governance FAQ

How does PrivacyScrubber prevent "Model Learning" from sensitive data?

By tokenizing PII at the semantic boundary (the prompt input) prior to network transmission, foundational models (ChatGPT, Claude, Gemini) never receive the original data. This eliminates sensitive company data from ever entering training datasets or short-term context cache.

Is ZTDS auditable for SOC 2 Type II compliance?

Yes. Because data sanitization is independently verifiable in the browser's Network tab with zero network egress, CISOs provide forensic proof that customer PII never leaves the corporate endpoint, satisfying SOC 2 CC6.1 and CC6.6 Trust Services Criteria without complex third-party vendor audits.

How does SIEM & Webhook logging work without collecting sensitive data?

PrivacyScrubber emits structured telemetry heartbeats containing timestamp, fleet node identifier, and sanitized entity categories. Prompt content and raw PII values are mathematically excluded from the payload, providing 100% SIEM compliance visibility with zero toxic data custody.

Does this work in air-gapped and offline VDI environments?

PrivacyScrubber operates 100% offline once the client bundle is loaded. For secure enterprise enclaves and SCIF/VDI environments, we provide pre-packaged self-contained deployments with zero remote dependencies.