Cryptographic Operations & Primitives

Zero-Trust Cryptographic Blueprint

PrivacyScrubber secures sensitive data not by policy or trust, but by mathematics. Our Zero-Trust Data Sanitization (ZTDS) model executes 100% in local browser memory, utilizing military-grade cryptography to mask and reconstruct sensitive records with zero server transit.

WebAssembly Libsodium 0-Byte Network Egress Argon2id Key Derivation XChaCha20-Poly1305 AEAD

The Client-Side Cryptographic Pipeline

1

Local In-DOM Detection & TokenizationClient V8

Sensitive PII and regulatory entities are scanned natively inside the client DOM using our compiled JS regex engine. Raw strings are replaced with contextual, format-preserving semantic tokens (e.g., [NAME_1], [IBAN_1]).

Execution: <1.2ms · Network egress: 0 bytes · Heap footprint: ephemeral
2

In-Memory Volatile SessionMap (Tab-Isolated)RAM Only

The bi-directional token-to-PII dictionary is stored exclusively in the browser's volatile heap memory (sessionMap). Each session is cryptographically bound to the active tabId, ensuring strict cross-tab isolation. No plain text ever touches localStorage, cookies, or IndexedDB.

Persistence: 0 bytes on disk · Destruction: instant on tab close or reload
3

Teams Session Cryptography (Argon2id + XChaCha20-Poly1305)WASM Libsodium

For cross-workstation team handoffs, sessions are encrypted end-to-end via WebAssembly Libsodium. Decryption keys are derived locally using Argon2id (64MB memory cost, 3 passes). Payloads are authenticated and encrypted with XChaCha20-Poly1305 (256-bit key, 192-bit nonce). Servers merely broker encrypted ciphertext blobs and never possess decryption keys.

Cipher: XChaCha20-Poly1305 AEAD · KDF: Argon2id v1.3 · Server visibility: 0%

Cryptographic Standards & Primitives

PrivacyScrubber does not invent proprietary cryptography. We exclusively implement industry-standard algorithms compiled to WebAssembly via Libsodium to prevent timing attacks, cache-bleed vulnerabilities, and side-channel leakage.

Key Derivation: Argon2id
RFC 9106

We derive 256-bit symmetric keys from local Team Magic Link parameters using Argon2id. This prevents brute-force key retrieval from intercepted links and ensures keys are generated dynamically inside the client DOM with high memory-hardness parameters.

64MB memory cost · 3 iterations · 1 lane
Authenticated Encryption: XChaCha20-Poly1305
AEAD

Encrypted session blobs are constructed using XChaCha20-Poly1305 (AEAD). This ensures confidentiality and cryptographic integrity—if an encrypted session is modified or tampered with in-transit, decryption fails instantly before memory ingestion.

256-bit symmetric key · 192-bit extended nonce

Two-Tier Fleet Governance Architecture

PrivacyScrubber delivers unified corporate AI governance without restricting individual worker velocity. Our architecture cleanly decouples global compliance controls from worker-level agility:

Central CISO Hard Lock

Security leads configure company-wide regex rules and select industry profiles in the Team Hub. Activating the Hard Lock makes the base policy read-only and locks the extension protection toggle permanently ON across managed endpoints.

Instant Zero-Proxy Rollout

Blueprints are distributed instantly via 1-click encrypted URLs, config files, or Google Workspace/Microsoft Intune MDM policies. There are zero proxy servers to configure, zero network hops, and zero latency overhead.

Local Worker Flexibility (Additive Overlay)

Employees can add temporary [LOCAL] rules for active client codenames directly from the extension popover without filing IT tickets. These local rules overlay on top of the locked corporate baseline additively without degrading compliance.

Zero Storage & Memory Lifecycle

PrivacyScrubber enforces a strict zero-data-at-rest architecture. Understanding our memory lifecycle is crucial for compliance officers and AppSec teams:

  • No Local Disk Storage: We do not write raw PII to localStorage, cookies, IndexedDB, or the client file system. All original PII mappings exist solely as temporary variables in the JS garbage-collector scope.
  • Tab Isolation Shield: To prevent session leakage across browser tabs, all memory maps are scoped using the active tabId provided by the extension service worker. Tab A cannot access the PII mapping of Tab B.
  • Volatile Termination: The moment you close the active browser tab or refresh the page, the volatile RAM is flushed. The keys mapping the tokens back to PII are permanently destroyed.

How to Verify Our Zero-Server Claim

We do not ask you to trust our promises. We invite you to perform an independent local network audit using standard Google Chrome Developer Tools.

  1. Open the PrivacyScrubber utility on your browser.
  2. Press F12 or right-click the page and select Inspect to open Developer Tools.
  3. Select the Network tab and select the "Fetch/XHR" filter.
  4. Type sensitive names or credit card numbers into the input field and click Protect Now.
  5. Observe the Network console. You will see zero outbound requests containing your raw text or token mappings. The only network calls permitted are asynchronous team subscription verification checks (excluding any prompt data).

Airplane Mode Verification: Disconnect your Wi-Fi or unplug your ethernet cable. PrivacyScrubber remains 100% functional, proving that all tokenization and text reconstruction run natively on your local hardware.

Regulatory Compliance Mapping

StandardRequirementPrivacyScrubber Cryptographic Alignment
GDPR Art. 32 & 25Pseudonymization and encryption of personal data to ensure ongoing confidentiality.PII is replaced with generic semantic tokens locally in the browser DOM before hitting cloud API endpoints, preventing exposure to LLM training logs and ensuring 0 cross-border data transfer.
SOC 2 Type II CC9.1Maintains confidentiality of system data in transit and at rest.Uses in-memory RAM-only SessionMap to store de-identification keys. Original mappings are destroyed upon closing the active browser tab. Zero persistent disk storage.
HIPAA Safe HarborDe-identification of 18 specific health identifiers (45 CFR § 164.514(b)).Client-side detection and redaction of names, dates, MRNs, geographic data, and medical record numbers prior to LLM submission, removing BAA liability for public AI tools.
ISO 27001 A.8.11Data masking controls in accordance with organizational access control policy.Deterministic pseudonymization masking sensitive fields at the application endpoint layer, satisfying ISO/IEC 27001:2022 Annex A.8.11 without middleman proxy servers.
NIST AI RMF 1.0Manage security and privacy risks of third-party Generative AI integrations.Intercepts prompts and sanitizes files (.txt, .docx, .pdf) natively on the endpoint, eliminating the risk of corporate IP and PII leakage to external models.