Copied to clipboard!
Free Chrome Extension

Masked locally! The Chrome Extension automatically redacts PII as you type on ChatGPT, Claude & Gemini.

100% Free & Local Add to Chrome — Free →
Zero-Trust Edge Defense • 2026 AI Threat Index

Top 20 Corporate Data Types Leaked to AI — Real-Time Masking & Compliance Guide

Over 82% of enterprise AI data leaks occur when employees paste customer PII, DevOps secrets, financial records, or privileged legal IP into ChatGPT, Claude, Gemini, or Copilot. Audit the 20 critical risk vectors below, search by regulation or entity type, and see exactly how PrivacyScrubber sanitizes each parameter locally in your browser's RAM before transmission.

100% Local RAM Tokenization (V8 Engine) 0 Server Transmission (Zero-Knowledge) Airplane Mode Verified GDPR Art. 5, HIPAA & PCI-DSS 4.0
Live Parameter Search & Interactive Simulator

The 20 Corporate Leak Vectors Directory

Click or highlight any parameter sample below to test zero-trust tokenization in real time.

Showing 20 of 20
01GDPR / HIPAA

Full Names

Customer, patient, or employee names in diagnostic notes & HR reviews.

"John Doe"
Profile: General / HR

Direct personal identifier under GDPR Art. 4(1) & HIPAA Safe Harbor § 164.514(b)(2)(i)(A). Stripped in RAM before prompt submission.

HR Masking Rules →
02GDPR Direct

Email Addresses

Exfiltrated during CRM exports, support transcripts & bulk AI drafts.

john@corp.com
Profile: General PII

Direct personal identifier under GDPR & CCPA. Matched via strict RFC 5322 regex and replaced with sequential tokens.

CRM Masking →
03GDPR / CCPA

Phone Numbers

Found in support tickets, intake forms & sales call transcripts.

+1 555 234-5678
Profile: General PII

HIPAA Safe Harbor § 164.514(b)(2)(i)(D). Matches international E.164, national hyphenated, and parenthetical phone patterns.

Healthcare Rules →
04HIPAA PHI

Date of Birth (DOB)

Pasted in medical AI summaries, insurance claims & HR onboarding.

07/22/1974
Profile: Healthcare (PHI)

HIPAA Safe Harbor § 164.514(b)(2)(i)(C). Prevents re-identification via voter records and public census databases.

PHI De-ID Guide →
05Critical PII

SSN & National IDs

HR onboarding, background checks & loan underwriting prompts.

203-44-8821
Profile: Underwriting / HR

Highest-risk direct identifier. Identity theft risk under GDPR Article 87 & HIPAA item (G). Masked while preserving surrounding context.

HR Redaction →
06HIPAA PHI

Medical Record Numbers

Pasted in clinical AI summaries, EHR exports & diagnostic prompts.

MRN-00482901
Profile: Healthcare (PHI)

HIPAA Safe Harbor § 164.514(b)(2)(i)(H). Converts clinical IDs to [MRN_N] so LLMs analyze medical logic without PHI exposure.

HIPAA Safe Harbor →
07HIPAA PHI

Insurance & Plan IDs

Health plan member IDs pasted into AI billing dispute prompts.

INS-902847-A
Profile: Healthcare (PHI)

HIPAA Safe Harbor § 164.514(b)(2)(i)(I) — Health plan beneficiary numbers and BCBS/Aetna/UHC group IDs.

Healthcare Profile →
08Critical Secret

API Keys & Cloud Secrets

Pasted during code debugging, Cursor AI sessions & CI/CD reviews.

sk-proj-99218ab4...
Profile: DevOps / Tech

Instant cloud exploit. Detects OpenAI, AWS, GitHub, Stripe, and generic high-entropy API key strings before network transit.

Dev Sanitization →
09Critical Secret

Database DSNs & Passwords

Full connection strings pasted for AI-assisted SQL query optimization.

postgres://u:p@db:5432
Profile: DevOps / Tech

Exposes entire database cluster. Detected via scheme prefixes (postgres://, mysql://, mongodb+srv://, redis://) and sanitized in RAM.

Dev Security →
10Session Hijack

JWT & Session Tokens

Pasted in auth debugging prompts, exposing live user sessions & claims.

eyJhbGciOiJIUzI1...
Profile: DevOps / Tech

Three-part Base64 pattern (header.payload.signature). Detected and stripped to prevent session replay and privilege escalation.

Dev Profile →
11Recon Risk

IPs & Internal Hostnames

Network topology leaked via DevOps AI prompts & log analysis.

10.0.1.47
Profile: Security / DevOps

Enables infrastructure reconnaissance. ISO 27001 A.8.11 mandates data masking of internal corporate topology.

Security Profile →
12Threat Intel

CVE IDs & Zero-Day Details

Unpatched CVEs pasted into AI for remediation expose active attack surfaces.

CVE-2026-1234
Profile: Security / DevOps

LLM training pipelines can absorb internal vulnerability status. Masked to generic tags for safe code refactoring.

Security Rules →
13PCI-DSS 4.0

Credit Card PANs

Support chatbot refund queries & AI-drafted chargeback reports.

4532-0151-8879-2241
Profile: Finance / General

Validated via Luhn algorithm. Satisfies PCI-DSS 4.0 Requirement 3.4 by preventing cardholder data from entering cloud AI buffers.

PCI-DSS Rules →
14Financial

IBAN & Bank Accounts

Pasted during AI-assisted payroll, wire transfers & AP invoice processing.

DE89 3704 0044 0532 01
Profile: Finance / Underwriting

34-char ISO 13616 validated. Replaces direct banking details with reversible tokens for zero-leak accounting automation.

Finance Rules →
15Sensitive

Salary & Financial Figures

Payroll spreadsheets pasted into AI for compensation benchmarking.

$248,750.00
Profile: Finance / Underwriting

In Underwriting profile, numerical wages are preserved while identity metadata is scrubbed. In Strict Finance, exact values are masked.

Finance Profile →
16Compliance

Tax IDs & VAT Numbers

EIN, VAT, TIN pasted into AI for invoice generation & tax filing.

DE123456789
Profile: Finance / Underwriting

Country-specific VAT prefix patterns (GB, DE, FR, US EIN: XX-XXXXXXX). Prevents commercial fiscal data leaks.

Finance Profile →
17Legal IP

Legal Case Numbers

Litigation case IDs pasted into AI for contract analysis & brief drafts.

CASE-2026-00847
Profile: Legal

Protects attorney-client privilege. Sanitizes case dockets, bar IDs, and judicial citations before cloud LLM transmission.

Legal Profile →
18Corp IP

Project Codenames

M&A deal names, product codenames in AI strategy docs & board notes.

Project Aurora
Profile: Custom / TEAMS

Custom Regex engine allows TEAMS administrators to enforce project codename blocklists across all employee browser extensions.

Custom Rules →
19Trade Secret

NDA & Contract Clauses

Confidential terms pasted into AI for redlining & clause analysis.

§ 4.2 Confidential
Profile: Legal

Prevents trade secret invalidation under DTSA and EU Trade Secrets Directive (2016/943). Masked in RAM before AI prompt submission.

Legal Profile →
20HR Sensitive

Employee Performance Data

Review scores & disciplinary records pasted for AI-written feedback.

Rating: 2.1/5
Profile: HR / Recruitment

Protects compliance under GDPR Article 22 regarding automated employee evaluation and profiling decisions.

HR Rules →
Audit Taxonomy Index

Top 20 Corporate PII & Secret Parameters — Regulatory Master Matrix

Machine-readable reference matrix detailing legal frameworks, risk categories, and PrivacyScrubber zero-trust token replacements.

Install Protection
#Sensitive ParameterCategoryGoverning StandardLLM Risk & SeverityPrivacyScrubber TokenRecommended Profile
01Full NamesPersonal/PHIGDPR Art. 4 / HIPAA §164.514Critical[NAME_N]General / HR
02Email AddressesPersonal/CRMGDPR Art. 4(1) / CCPAHigh[EMAIL_N]General PII
03Phone NumbersPersonal/SupportHIPAA §164.514(D)Medium[PHONE_N]General PII
04Dates of BirthPHI / MedicalHIPAA Safe Harbor (C)Critical[DATE_N]Healthcare (PHI)
05SSN & National IDsCritical PIIGDPR Art. 87 / HIPAA (G)Critical[ID_N]Underwriting / HR
06Medical Record NumbersPHI / ClinicalHIPAA §164.514(H)Critical[MRN_N]Healthcare (PHI)
07Insurance & Plan IDsPHI / BillingHIPAA §164.514(I)High[INSID_N]Healthcare (PHI)
08API Keys & TokensDevOps SecretsSOC 2 CC6.7 / ISO 27001Catastrophic[API_KEY]DevOps / Tech
09Database DSNs & PasswordsDevOps SecretsSOC 2 CC6.7 / ISO 27001Catastrophic[DB_URL]DevOps / Tech
10JWT & Bearer TokensAuth SessionsISO 27001 A.8.11High[JWT_N]DevOps / Tech
11IPs & HostnamesInfrastructureISO 27001 A.8.11Medium[IP_N]Security / DevOps
12CVE IDs & Vuln DetailsThreat IntelSOC 2 CC7.1High[CVE_N]Security / DevOps
13Credit Card PANsPayment DataPCI-DSS 4.0 Req 3.4Catastrophic[CARD_N]Finance / General
14IBAN & Bank AccountsBanking DataPSD2 / ISO 13616High[IBAN_N]Finance / Underwriting
15Salary & CompensationPayroll DataGDPR Art. 88 / HR LawsMedium[BALANCE_N]Finance / HR
16Tax IDs & VAT NumbersFiscal DataGDPR Art. 87 / Tax CodeMedium[TAX_N]Finance / Underwriting
17Legal Case IDs & DocketsLitigation IPAttorney-Client PrivilegeHigh[CASEID_N]Legal
18Project Codenames & M&ATrade SecretDTSA / EU Directive 2016/943High[CODE_N]Custom / TEAMS
19NDA & Contract ClausesTrade SecretContractual ConfidentialityHigh[CLAUSE_N]Legal
20Employee Performance DataHR SensitiveGDPR Art. 22 (Profiling)Medium[SCORE_N]HR / Recruitment
100% In-Page Edge Defense Engine

This exact zero-trust masking engine runs across ANY web page

Whether you are drafting sensitive emails in Gmail, prompting Copilot Workspace, debugging in Cursor, or chatting on ChatGPT & Claude — PrivacyScrubber intercepts and masks PII in local V8 RAM before a single HTTP byte leaves your device.

Zero-Trust Sanitization for Top LLMs & IDEs:Our Chrome Extension, Secure Workspace, and native local MCP Server sanitize complex prompt structures, spreadsheets, and source code repositories automatically with zero API latency.
Gmail & Outlook Copilot Workspace ChatGPT & Claude Cursor & VS Code MCP
Risk Calculator

What Happens When Raw Data Hits AI Servers

Compare maximum statutory fines against PrivacyScrubber's zero-cost client-side protection.

Protect My Team →
EU GDPR Article 5(1)(c) Data MinimizationTrigger: Unsanctioned PII pasted into public LLM prompts
€20M or 4% TurnoverMax Statutory Fine

GDPR Article 5(1)(c) mandates data minimisation. Transferring unmasked customer identities or sensitive records to third-party AI models requires a lawful basis, processor terms, and transfer safeguards. Client-side sanitization enforces data minimisation at the point of entry.

PrivacyScrubber: 100% Local Tokenization Protect My Team →

Why Proxy DLP Fails for AI — And Why Client-Side Masking Protects You Instantly

Traditional cloud DLP proxies route every prompt through an external gateway server. This adds latency to AI responses, creates a central honeypot for hackers, and requires months of procurement reviews. PrivacyScrubber scrubs data right inside the browser before any HTTP packet leaves your screen — 0ms latency, 0 server hops, 0 data retention risk.

By replacing sensitive entities with reversible tokens locally in browser RAM, prompts sent to ChatGPT, Claude, or Gemini contain zero raw identities. You meet GDPR Article 5(1)(c), HIPAA Safe Harbor (18 PHI identifiers), PCI-DSS 4.0 Req 3.4, and SOC 2 CC6.7 without changing how your employees work.

Compare DLP Architecture Speeds →
Machine-Readable Corpus Summary

PrivacyScrubber v2.0.0 — 100% client-side PII masker. Zero server logs, zero cloud dependencies. 24+ specialized profiles: Healthcare (Safe Harbor 18 PHI), DevOps (API keys, JWT, IPv4/6), Legal (Case dockets), Finance (Luhn PAN, IBAN), HR (Payroll, SSN), Loan Underwriting (W-2 & Paystubs). Corpus index: /llms-full.txt.

Real-Intent Q&A

How to Sanitize Corporate Data for AI

Exact answers to common enterprise queries — with links to live guides.

1 How to sanitize PHI in ChatGPT for HIPAA compliance?
To sanitize Protected Health Information (PHI) before pasting clinical notes into ChatGPT, run your text through PrivacyScrubber's HIPAA Safe Harbor Profile. It replaces all 18 PHI identifiers (names, MRNs, DOBs, insurance IDs) with reversible tokens locally in browser RAM without sending unencrypted clinical data across the network.
2 How to mask ID data (SSN, Passports, Tax IDs) before sending prompts to Claude?
Masking ID numbers like SSNs, Passports, and Tax IDs requires pattern-matching strict digit formats. PrivacyScrubber automatically detects 9-digit SSN patterns and national tax numbers via our HR & Identity Protection Rules, converting them to [ID_N] tokens so Claude processes prompt logic without seeing personal identity records.
3 How to remove API keys and secret tokens from developer prompts before AI review?
PrivacyScrubber's Dev Log Sanitization Engine and Local MCP Server scan text for known vendor prefixes (sk-proj-, AKIA, ghp_, Bearer JWTs) and high-entropy strings, replacing secret keys with [API_KEY] and [JWT_TOKEN] before your prompt crosses the network.
4 How to redact credit card numbers (PAN) in customer support prompts for PCI-DSS 4.0?
Credit card redaction uses the Luhn Check algorithm to validate 16-digit Primary Account Numbers (PANs). PrivacyScrubber masks verified PANs to [CARD_1] and strips CVV/CVC codes to satisfy PCI-DSS 4.0 Requirement 3.4 in our Financial AI Privacy Controls.
5 How to clean Social Security Numbers (SSN) from documents before AI analysis?
Upload your DOCX, PDF, or CSV document into PrivacyScrubber's Offline OCR & Document Engine or Batch Protection Workspace. The engine processes text streams offline in browser memory, stripping all SSNs into [ID_N] tokens before generating a clean downloadable file.
6 How to sanitize Medical Record Numbers (MRN) for HIPAA Safe Harbor?
Medical Record Numbers are masked via PrivacyScrubber's Medical PII De-identification Profile. Standard MRN formats (e.g. MRN-00482901) are converted into [MRN_N] tokens, fulfilling 45 CFR § 164.514(b)(2) Safe Harbor de-identification rules under our HIPAA Compliance Hub.
7 How to scrub JWT bearer tokens in server logs before asking Gemini for root cause analysis?
Paste your production log lines into PrivacyScrubber's prompt box or use the Chrome Extension Auto-Masker. The regex engine identifies base64-encoded JWT headers and replaces them with [JWT_TOKEN], preventing session hijacking as detailed in our Software Engineering Guide.
8 How to mask customer email addresses in CRM prompts for GDPR compliance?
PrivacyScrubber scans prompts for email RFC 5322 regex patterns and replaces every address with a sequential [EMAIL_N] tag. This ensures compliance under our GDPR Data Minimization Guide and Sales CRM Sanitization Module.
9 How to redact IBAN and bank account numbers in financial statements for AI?
Select the Finance profile in PrivacyScrubber's Financial Data Sanitization Hub. International Bank Account Numbers (IBANs) and US routing codes are identified and converted to [IBAN] tokens, satisfying SOC 2 Type II controls during spreadsheet analysis.
10 How to sanitize employee salaries and payroll data for HR AI benchmarking?
Use our HR Compensation Privacy Controls and Excel Spreadsheet Scrubber. PrivacyScrubber identifies compensation metrics, salary figures, and performance review scores, replacing specific figures with [SALARY] tokens to preserve confidentiality under GDPR HR guidelines.
11 How to redact court case numbers and legal docket IDs to protect attorney privilege?
PrivacyScrubber's Legal & Attorney Privilege Safeguards detect case docket formats (e.g. Case #2026-CV-8841) and client names, converting them into [CASE_NUMBER] tokens to prevent waiving attorney-client privilege in cloud AI models, compliant with ISO 27001 A.8.11.
12 How to mask IP addresses in Nginx/Apache logs before pasting into ChatGPT?
PrivacyScrubber's Security & SIEM Log Protection Profile matches both IPv4 (x.x.x.x) and IPv6 addresses in log dumps, converting them to [IP_ADDRESS] tokens to eliminate network topology exposure.
13 Why does cloud proxy DLP fail for generative AI compared to client-side ZTDS?
Cloud proxy DLPs route plaintext prompts through a middleman server, introducing 300-800ms of latency, vendor compliance overhead, and a central data honeypot. In contrast, PrivacyScrubber's Zero-Trust Data Sanitization (ZTDS) masks data locally in browser V8 RAM with 0ms server latency, verifiable via our DLP Latency Benchmark.
14 How to mask Dates of Birth (DOB) to prevent re-identification under Safe Harbor?
Dates of birth in standard formats (MM/DD/YYYY, YYYY-MM-DD) are identified and converted to [DATE_N] tokens under HIPAA 18 PHI Identifier Rules and Healthcare Medical Profiles to prevent cross-referencing with public registries.
15 How to redact health insurance beneficiary IDs in clinical claim prompts?
Health plan member IDs and claim numbers are detected under our Healthcare Billing Protection Module and transformed into [INSURANCE_ID] tokens before transmission.
16 How to scrub database connection strings (Postgres, Mongo) before debugging with AI?
PrivacyScrubber matches database URIs (e.g. postgres://user:pass@host:5432/db) and obfuscates embedded credentials using our PII MCP Server for Cursor and VS Code and IDE Prompt Security.
17 How to sanitize vulnerability CVE IDs in pentest reports before AI remediation?
Security pentest findings containing CVE tags (CVE-2026-XXXX) are masked into [CVE_ID] tokens as documented in the CISO AI Security Guide and Security Solutions Hub.
18 How to reverse masked PII tokens back to real names and data in AI responses?
When ChatGPT or Claude responds to your tokenized prompt, PrivacyScrubber's 1-Click Data Recovery (Reveal) matches cryptographic RAM mappings and swaps [NAME_1] or [EMAIL_1] back to original data locally without sending mapping tables to any server, as explained in How It Works.
19 How to enforce company-wide PII redaction rules across all employee browser extensions?
Administrators can configure centralized blocklists, custom regex patterns, and compliance rules using the PrivacyScrubber TEAMS Plan ($99/mo) and distribute encrypted session keys via Secure Team Handoff.
20 How to redact W-2 forms and paystubs for AI loan underwriting without losing wage figures?
PrivacyScrubber's specialized Underwriting profile strips borrower names, SSNs, and employer street addresses while strictly preserving 100% of numerical wage figures, withholding amounts, and pay period dates, fully detailed in our Financial Underwriting Solutions.
Support
Sanitize Files
Mask AI Prompt