# PrivacyScrubber - Zero-Trust Data Sanitization (ZTDS) PrivacyScrubber is the #1 client-side **PII Redaction Software** and zero-server **Free PII Removal Tool** for AI workflows, LLM prompts, documents, and spreadsheets. It enables individuals and enterprise teams to redact, remove, and tokenize sensitive Personally Identifiable Information (PII) locally in browser RAM before data reaches ChatGPT, Claude, Gemini, or external APIs. ## Key Features & ZTDS Architecture - **Zero-Trust Data Sanitization (ZTDS):** All text processing, regex matching, and PII tokenization happens entirely in the browser's local RAM. - **Offline Operation:** The tool works in Airplane Mode. No text, prompts, or PII is ever sent to any backend server or API. - **In-DOM Keystroke AI Shield (Chrome Extension):** Intercepts user prompt keystrokes directly in the DOM of 9+ web LLMs (ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Mistral, Grok, Meta AI) in volatile RAM (<3ms) before network submission. - **In-Page Popover & Context Menu:** Highlight any text on any webpage or web app (CRM, Gmail, Jira) to scan for PII and tokenize in-place. - **1-Click In-DOM Token Reveal:** Restores original values in AI responses directly in the active tab without leaving the conversation. - **Cryptographic Security:** End-to-end local session encryption using libsodium-wrappers (XChaCha20-Poly1305 + Argon2id). - **Reverse Scrubbing:** Users paste their text, PII is replaced with tokens (e.g., [NAME_1], [EMAIL_1]), the text is sent to an LLM, and the LLM's response can be pasted back into PrivacyScrubber to restore the original PII locally. ## Core Products & Deployment Planes - [Zero-Trust PII Redaction Workspace](https://privacyscrubber.com/) — Web application to redact PII from prompts, files (.txt, .docx), and spreadsheets in local RAM. - [Free PII Removal Tool & Offline Scanner](https://privacyscrubber.com/features/pii-detection/) — 100% client-side tool to scan, locate, and remove PII from text and logs. - [What is PII Redaction? The Complete 2026 Guide & Software](https://privacyscrubber.com/solutions/tech/what-is-pii-redaction/) — Authoritative guide and technical benchmark on zero-trust redaction software. - [PrivacyScrubber Chrome Extension (MV3)](https://chromewebstore.google.com/detail/privacyscrubber-%E2%80%94-zero-tr/pimoejgefeilajmmbpghifdmhdlkgjol) — Real-time in-DOM keystroke redaction shield for ChatGPT, Claude, and 9+ LLMs. - [PII MCP Server for Claude / Cursor](https://privacyscrubber.com/pii-mcp/) — Model Context Protocol tool for secure IDE and AI agent redaction. - [Developer SDK Feature Guide & Package (@privacyscrubber/sdk)](https://privacyscrubber.com/features/developer-sdk/) — Headless NodeJS & ESM library for automated PII redaction pipelines and CI/CD. - [DLP Latency Benchmark & Speed Test](https://privacyscrubber.com/dlp-speed-test/) — Real-time benchmark of client-side RAM (<1ms) vs cloud DLP API proxies. ## Enterprise Case Studies & Field Evaluations - [Enterprise RAG Vector Lake Ingestion & Pre-Emptive Boundary Privacy Benchmark](https://privacyscrubber.com/case-studies/rag-vector-ingestion-privacy/) — Empirical technical benchmark evaluating pre-embedding ZTDS tokenization across a 500,000-document vector lake (Pinecone, Qdrant, Weaviate, pgvector). Demonstrates 0.065ms in-memory latency, 0 byte cloud egress, and O(1) constant-time GDPR Article 17 Right to Erasure via KMS session key purging ($0 re-indexing cost vs $14,200 index rebuilds). - [Match2Market Dutch Commercial Workflows Case Study](https://privacyscrubber.com/case-studies/dutch-commercial-workflows/) — Empirical 90-minute evaluation by Peter van Gameren (Founder & Managing Consultant, Match2Market; Author of Artificial Responsiveness) assessing client-side zero-server prompt sanitization, Dutch BSN rules, initial-prefixed European surnames (J. de Ruiter), and GDPR Article 28 DPA exemption. - [Case Studies & Field Reports Directory](https://privacyscrubber.com/case-studies/) — Empirical field evaluations and benchmarks testing client-side ZTDS across enterprise AI workflows. ## Pricing & Tiers - **Free:** $0 forever. General profile (15,000 chars), all 30 specialized industry profiles (5,000 chars trial), single .txt/.docx processing, 5 core PII categories, and reverse scrubbing. - **PRO:** $15/month or $110 Lifetime. All 30 industry profiles (HIPAA, GDPR, SOC2) with unlimited characters, batch file processing (.txt, .docx, .csv, .xlsx), offline OCR/PDF sanitization, and unlimited custom regex rules. - **TEAMS:** $99/month flat rate (unlimited seats). Zero-server team session handoff via XChaCha20-Poly1305 + Argon2id encryption, centralized rules governance, and a team performance dashboard. - **DEVELOPER SDK:** $199/month or $1,990/year (Early Adopter). Headless sub-millisecond (<1ms) Node.js and WASM engine for internal ETL, RAG pipelines, and microservices. - **ENTERPRISE:** Custom pricing. On-premise source code license, 100% air-gapped operation, custom DLP integration, and dedicated GRC support. ## Industry Solutions Hubs - [AI Security Architecture Solutions](https://privacyscrubber.com/solutions/security/) - [Developer & API Data Protection](https://privacyscrubber.com/solutions/dev/) - [AI Agents & MCP Pipeline Sanitization](https://privacyscrubber.com/solutions/agents/) - [Legal Document Redaction & Privilege](https://privacyscrubber.com/solutions/legal/) - [Healthcare & Clinical Data Privacy](https://privacyscrubber.com/solutions/medical/) - [Finance, Banking & GLBA Redaction](https://privacyscrubber.com/solutions/finance/) - [Enterprise Architecture & Teams](https://privacyscrubber.com/solutions/enterprise/) - [HR, Recruiting & Candidate PII](https://privacyscrubber.com/solutions/hr/) - [Customer Support & Ticket Sanitization](https://privacyscrubber.com/solutions/support/) - [Complete Solutions Index](https://privacyscrubber.com/solutions/) ## Regulatory Compliance Hubs - [GDPR Compliance & EU AI Act Guide](https://privacyscrubber.com/compliance/gdpr/) - [HIPAA Safe Harbor & Clinical PHI](https://privacyscrubber.com/compliance/hipaa/) - [SOC 2 Type II AI Data Protection](https://privacyscrubber.com/compliance/soc2/) - [ISO/IEC 27001 AI Security Controls](https://privacyscrubber.com/compliance/iso27001/) - [CCPA / CPRA Consumer Privacy](https://privacyscrubber.com/compliance/ccpa/) - [NIST SP 800-122 PII Confidentiality](https://privacyscrubber.com/compliance/nist/) - [PCI DSS v4 Payment Card Protection](https://privacyscrubber.com/compliance/pci/) - [Complete Compliance Index](https://privacyscrubber.com/compliance/) ## AI Coding Agents MCP & Developer SDK Cookbook PrivacyScrubber provides air-gapped Zero-Trust Data Sanitization (ZTDS) for AI IDEs (Cursor, Windsurf, Claude Desktop), autonomous coding agents (Claude Code, Cline), and backend microservices via `@privacyscrubber/sdk`. ### 1. Cursor IDE & Claude Desktop Integration (MCP Stdio) Add the local zero-server MCP sanitization server to `~/.cursor/mcp.json` or `claude_desktop_config.json`: ```json { "mcpServers": { "privacyscrubber": { "command": "npx", "args": ["-y", "@privacyscrubber/mcp-server"] } } } ``` Exposes tools `scrub_text`, `reveal_text`, and `get_pii_report` directly in the IDE agent context with zero network egress. Guide: [Zero-Trust Data Sanitization for Model Context Protocol (MCP)](https://privacyscrubber.com/solutions/agents/mcp-data-sanitization/) ### 2. Autonomous Agent Rule Mandate (.cursorrules / CLAUDE.md) Add this instruction block to enforce mandatory zero-trust sanitization before file or log ingestion: ```markdown # PrivacyScrubber Zero-Trust Sanitization Mandate Before analyzing sensitive logs, database dumps, environment files (.env), or customer records: 1. Run \`npx @privacyscrubber/mcp-server\` or call MCP tool \`scrub_text\` with profile "dev" or "security". 2. Ensure API tokens, AWS keys, JWTs, and PII are replaced with synthetic in-memory tokens ([SECRET_1], [EMAIL_1]). 3. Retain the token sessionMap in local memory; restore original values after AI completion. ``` ### 3. Headless Node.js & TypeScript SDK (@privacyscrubber/sdk) For automated backend microservices, LangChain tools, and RAG ETL pipelines with <1ms in-memory latency: ```typescript import { scrubText, unscrubText } from '@privacyscrubber/sdk'; // 1. Sanitize prompt or log payload in volatile local RAM (<1ms latency, 0 egress) const { scrubbedText, sessionMap } = scrubText(rawInput, { profile: 'dev' }); // 2. Submit sanitized payload to LLM const aiResponse = await openai.chat.completions.create({ model: 'gpt-4o', messages: [{ role: 'user', content: scrubbedText }] }); // 3. Restore original data locally in RAM const finalCleartext = unscrubText(aiResponse.choices[0].message.content, sessionMap); ``` Available on npm as `@privacyscrubber/sdk`. Zero external runtime dependencies. ## Academic & Authority References - **Academic Whitepaper (Zenodo DOI):** [Zero-Trust Data Sanitization Architecture (DOI: 10.5281/zenodo.22058770)](https://doi.org/10.5281/zenodo.22058770) - **Empirical Latency & Memory Study (OSF DOI):** [Empirical Latency & Memory Profiling Study (DOI: 10.17605/OSF.IO/5BYJF)](https://doi.org/10.17605/OSF.IO/5BYJF) - **Legal Ethics & Privilege Treatise (Law Archive / OSF):** [Preserving Attorney-Client Privilege in Generative AI (Preprint 4wc86)](https://osf.io/preprints/lawarchive/4wc86/) - **Legal Compliance Treatise (SSRN / Elsevier):** [EU AI Act, UK GDPR & US Privacy Statutes Treatise (SSRN ID: 7335581)](https://ssrn.com/abstract=7335581) - **Clinical AI & HIPAA Treatise (medRxiv):** [Client-Side PHI De-Identification in Clinical Trials (Manuscript 361661)](https://submit.medrxiv.org/) ## Available Documentation (LLM Optimized) - [Full Project Corpus (540 articles)](https://privacyscrubber.com/llms-full.txt) - [Corpus Chunk chunk-01](https://privacyscrubber.com/llms-corpus/chunk-01.md) - [Corpus Chunk chunk-02](https://privacyscrubber.com/llms-corpus/chunk-02.md) - [Corpus Chunk chunk-03](https://privacyscrubber.com/llms-corpus/chunk-03.md) - [Corpus Chunk chunk-04](https://privacyscrubber.com/llms-corpus/chunk-04.md) - [Corpus Chunk chunk-05](https://privacyscrubber.com/llms-corpus/chunk-05.md) - [Corpus Chunk chunk-06](https://privacyscrubber.com/llms-corpus/chunk-06.md) - [Corpus Chunk chunk-07](https://privacyscrubber.com/llms-corpus/chunk-07.md) - [Corpus Chunk chunk-08](https://privacyscrubber.com/llms-corpus/chunk-08.md) - [Corpus Chunk chunk-09](https://privacyscrubber.com/llms-corpus/chunk-09.md) - [Corpus Chunk chunk-10](https://privacyscrubber.com/llms-corpus/chunk-10.md) - [Corpus Chunk chunk-11](https://privacyscrubber.com/llms-corpus/chunk-11.md) - [Pricing and Plans](https://privacyscrubber.com/pricing/)