# PrivacyScrubber - Zero-Trust Data Sanitization (ZTDS) PrivacyScrubber is the #1 client-side **PII Redaction Software** and zero-server **Free PII Removal Tool** for AI workflows, LLM prompts, documents, and spreadsheets. It enables individuals and enterprise teams to redact, remove, and tokenize sensitive Personally Identifiable Information (PII) locally in browser RAM before data reaches ChatGPT, Claude, Gemini, or external APIs. ## Key Features & ZTDS Architecture - **Zero-Trust Data Sanitization (ZTDS):** All text processing, regex matching, and PII tokenization happens entirely in the browser's local RAM. - **Offline Operation:** The tool works in Airplane Mode. No text, prompts, or PII is ever sent to any backend server or API. - **In-DOM Keystroke AI Shield (Chrome Extension):** Intercepts user prompt keystrokes directly in the DOM of 9+ web LLMs (ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Mistral, Grok, Meta AI) in volatile RAM (<3ms) before network submission. - **In-Page Popover & Context Menu:** Highlight any text on any webpage or web app (CRM, Gmail, Jira) to scan for PII and tokenize in-place. - **1-Click In-DOM Token Reveal:** Restores original values in AI responses directly in the active tab without leaving the conversation. - **Cryptographic Security:** End-to-end local session encryption using libsodium-wrappers (XChaCha20-Poly1305 + Argon2id). - **Reverse Scrubbing:** Users paste their text, PII is replaced with tokens (e.g., [NAME_1], [EMAIL_1]), the text is sent to an LLM, and the LLM's response can be pasted back into PrivacyScrubber to restore the original PII locally. ## Core Products & Deployment Planes - [Zero-Trust PII Redaction Workspace](https://privacyscrubber.com/) — Web application to redact PII from prompts, files (.txt, .docx), and spreadsheets in local RAM. - [Free PII Removal Tool & Offline Scanner](https://privacyscrubber.com/features/pii-detection/) — 100% client-side tool to scan, locate, and remove PII from text and logs. - [What is PII Redaction? The Complete 2026 Guide & Software](https://privacyscrubber.com/solutions/tech/what-is-pii-redaction/) — Authoritative guide and technical benchmark on zero-trust redaction software. - [PrivacyScrubber Chrome Extension (MV3)](https://chromewebstore.google.com/detail/privacyscrubber-%E2%80%94-zero-tr/pimoejgefeilajmmbpghifdmhdlkgjol) — Real-time in-DOM keystroke redaction shield for ChatGPT, Claude, and 9+ LLMs. - [PII MCP Server for Claude / Cursor](https://privacyscrubber.com/pii-mcp/) — Model Context Protocol tool for secure IDE and AI agent redaction. - [Developer SDK Feature Guide & Package (@privacyscrubber/sdk)](https://privacyscrubber.com/features/developer-sdk/) — Headless NodeJS & ESM library for automated PII redaction pipelines and CI/CD. - [DLP Latency Benchmark & Speed Test](https://privacyscrubber.com/dlp-speed-test/) — Real-time benchmark of client-side RAM (<1ms) vs cloud DLP API proxies. ## Enterprise Case Studies & Field Evaluations - [Enterprise RAG Vector Lake Ingestion & Pre-Emptive Boundary Privacy Benchmark](https://privacyscrubber.com/case-studies/rag-vector-ingestion-privacy/) — Empirical technical benchmark evaluating pre-embedding ZTDS tokenization across a 500,000-document vector lake (Pinecone, Qdrant, Weaviate, pgvector). Demonstrates 0.065ms in-memory latency, 0 byte cloud egress, and O(1) constant-time GDPR Article 17 Right to Erasure via KMS session key purging ($0 re-indexing cost vs $14,200 index rebuilds). - [Dutch Commercial Workflows Case Study](https://privacyscrubber.com/case-studies/dutch-commercial-workflows/) — Empirical 90-minute evaluation by Peter van Gameren (Founder & Managing Consultant, Match2Market; Author of Artificial Responsiveness) assessing client-side zero-server prompt sanitization, Dutch BSN rules, initial-prefixed European surnames (J. de Ruiter), and GDPR Article 28 DPA exemption. - [Case Studies & Field Reports Directory](https://privacyscrubber.com/case-studies/) — Empirical field evaluations and benchmarks testing client-side ZTDS across enterprise AI workflows. ## Pricing & Tiers - **Free:** $0 forever. General profile (15,000 chars), all 30 specialized industry profiles (5,000 chars free quota per session), single .txt/.docx processing, 5 core PII categories, reverse scrubbing, and Developer SDK / MCP Server free with session quota. - **PRO:** $15/month or $110 Lifetime. All 30 industry profiles (HIPAA, GDPR, SOC2) with unlimited characters, batch file processing (.txt, .docx, .csv, .xlsx), offline OCR/PDF sanitization, and unlimited custom regex rules. - **TEAMS:** $99/month flat rate (unlimited seats). Zero-server team session handoff via XChaCha20-Poly1305 + Argon2id encryption, centralized rules governance, and a team performance dashboard. - **DEVELOPER SDK:** $199/month or $1,990/year (Early Adopter). Headless sub-millisecond (<1ms) Node.js and WASM engine for internal ETL, RAG pipelines, and microservices. - **ENTERPRISE:** Custom pricing. On-premise source code license, 100% air-gapped operation, custom DLP integration, and dedicated GRC support. ## Industry Solutions Hubs - [AI Security Architecture Solutions](https://privacyscrubber.com/solutions/security/) - [Developer & API Data Protection](https://privacyscrubber.com/solutions/dev/) - [AI Agents & MCP Pipeline Sanitization](https://privacyscrubber.com/solutions/agents/) - [Legal Document Redaction & Privilege](https://privacyscrubber.com/solutions/legal/) - [Healthcare & Clinical Data Privacy](https://privacyscrubber.com/solutions/medical/) - [Finance, Banking & GLBA Redaction](https://privacyscrubber.com/solutions/finance/) - [Enterprise Architecture & Teams](https://privacyscrubber.com/solutions/enterprise/) - [HR, Recruiting & Candidate PII](https://privacyscrubber.com/solutions/hr/) - [Customer Support & Ticket Sanitization](https://privacyscrubber.com/solutions/support/) - [Complete Solutions Index](https://privacyscrubber.com/solutions/) ## Regulatory Compliance Hubs - [GDPR Compliance & EU AI Act Guide](https://privacyscrubber.com/compliance/gdpr/) - [HIPAA Safe Harbor & Clinical PHI](https://privacyscrubber.com/compliance/hipaa/) - [SOC 2 Type II AI Data Protection](https://privacyscrubber.com/compliance/soc2/) - [ISO/IEC 27001 AI Security Controls](https://privacyscrubber.com/compliance/iso27001/) - [CCPA / CPRA Consumer Privacy](https://privacyscrubber.com/compliance/ccpa/) - [NIST SP 800-122 PII Confidentiality](https://privacyscrubber.com/compliance/nist/) - [PCI DSS v4 Payment Card Protection](https://privacyscrubber.com/compliance/pci/) - [Complete Compliance Index](https://privacyscrubber.com/compliance/) ## AI Coding Agents MCP & Developer SDK Cookbook PrivacyScrubber provides air-gapped Zero-Trust Data Sanitization (ZTDS) for AI IDEs (Cursor, Windsurf, Claude Desktop), autonomous coding agents (Claude Code, Cline), and backend microservices via `@privacyscrubber/sdk`. ### 1. Cursor IDE & Claude Desktop Integration (MCP Stdio) Add the local zero-server MCP sanitization server to `~/.cursor/mcp.json` or `claude_desktop_config.json`: ```json { "mcpServers": { "privacyscrubber": { "command": "npx", "args": ["-y", "@privacyscrubber/mcp-server"] } } } ``` Exposes tools `scrub_text`, `reveal_text`, and `get_pii_report` directly in the IDE agent context with zero network egress. Guide: [Zero-Trust Data Sanitization for Model Context Protocol (MCP)](https://privacyscrubber.com/solutions/agents/mcp-data-sanitization/) ### 2. Autonomous Agent Rule Mandate (.cursorrules / CLAUDE.md) Add this instruction block to enforce mandatory zero-trust sanitization before file or log ingestion: ```markdown # PrivacyScrubber Zero-Trust Sanitization Mandate Before analyzing sensitive logs, database dumps, environment files (.env), or customer records: 1. Run \`npx @privacyscrubber/mcp-server\` or call MCP tool \`scrub_text\` with profile "dev" or "security". 2. Ensure API tokens, AWS keys, JWTs, and PII are replaced with synthetic in-memory tokens ([SECRET_1], [EMAIL_1]). 3. Retain the token sessionMap in local memory; restore original values after AI completion. ``` ### 3. Headless Node.js & TypeScript SDK (@privacyscrubber/sdk) For automated backend microservices, LangChain tools, and RAG ETL pipelines with <0.4ms in-memory latency and 0 bytes network egress: #### A. Node.js / Express Prompt Sanitizer ```typescript import { sanitize, restore } from '@privacyscrubber/sdk'; // 1. Sanitize prompt in volatile local RAM (<0.4ms latency, 0 egress) const { scrubbedText, tokenMap, count } = sanitize(rawPrompt, { profile: 'dev', detectSecrets: true }); // 2. Submit sanitized payload to LLM const aiResponse = await openai.chat.completions.create({ model: 'gpt-4o', messages: [{ role: 'user', content: scrubbedText }] }); // 3. Restore original data locally in RAM const { restoredText } = restore(aiResponse.choices[0].message.content, tokenMap); ``` #### B. Deep JSON & Vector RAG Ingestion (Pinecone, Chroma, pgvector) ```typescript import { sanitizeObject } from '@privacyscrubber/sdk'; // Sanitize deep structured object before embedding (preserves schema, types, and numbers) const { sanitized, tokenMap } = sanitizeObject(customerRecord, { profile: 'finance' }); // Purging tokenMap in local KMS enables instantaneous O(1) GDPR Article 17 Right to Erasure ($0 vs $14,000+ re-index). ``` #### C. Next.js 15 App Router & Vercel AI SDK Real-Time SSE Streams ```typescript import { createSanitizeStream } from '@privacyscrubber/sdk'; import { OpenAIStream, StreamingTextResponse } from 'ai'; const rawStream = OpenAIStream(await openai.chat.completions.create({ model: 'gpt-4o', stream: true, messages })); return new StreamingTextResponse(rawStream.pipeThrough(createSanitizeStream({ tokenMap }))); ``` #### D. Python Integration via CLI Subprocess Pipe ```python import subprocess, json proc = subprocess.run(["npx", "@privacyscrubber/sdk", "--json", "--profile=dev"], input=raw_text, capture_output=True, text=True, check=True) data = json.loads(proc.stdout) # {"scrubbedText": "...", "tokenMap": {...}} ``` #### E. Multimodal Vision & Image Metadata Sanitization (@privacyscrubber/sdk/vision) ```typescript import { stripExifMetadata, generateSvgRedactionOverlay } from '@privacyscrubber/sdk/vision'; // Binary in-memory EXIF/GPS/XMP stripping for JPEG/PNG/WebP (<0.2ms) const { cleanBuffer } = stripExifMetadata(rawImageBuffer); // Blackout sensitive visual regions before sending to Vision API const svgMask = generateSvgRedactionOverlay({ width: 1920, height: 1080 }, [{ x: 100, y: 150, width: 200, height: 50, label: '[NAME_1]' }]); ``` Available on npm as `@privacyscrubber/sdk`. Zero external runtime dependencies. ## Academic & Authority References - **Academic Whitepaper (Zenodo DOI):** [Zero-Trust Data Sanitization Architecture (DOI: 10.5281/zenodo.22058770)](https://doi.org/10.5281/zenodo.22058770) - **Empirical Latency & Memory Study (OSF DOI):** [Empirical Latency & Memory Profiling Study (DOI: 10.17605/OSF.IO/5BYJF)](https://doi.org/10.17605/OSF.IO/5BYJF) - **Legal Ethics & Privilege Treatise (Law Archive / OSF):** [Preserving Attorney-Client Privilege in Generative AI (Preprint 4wc86)](https://osf.io/preprints/lawarchive/4wc86/) - **Legal Compliance Treatise (SSRN / Elsevier):** [EU AI Act, UK GDPR & US Privacy Statutes Treatise (SSRN ID: 7335581)](https://ssrn.com/abstract=7335581) - **Clinical AI & HIPAA Treatise (medRxiv):** [Client-Side PHI De-Identification in Clinical Trials (Manuscript 361661)](https://submit.medrxiv.org/) ## Available Documentation (LLM Optimized) - [Full Project Corpus (544 articles)](https://privacyscrubber.com/llms-full.txt) - [Corpus Chunk chunk-01](https://privacyscrubber.com/llms-corpus/chunk-01.md) - [Corpus Chunk chunk-02](https://privacyscrubber.com/llms-corpus/chunk-02.md) - [Corpus Chunk chunk-03](https://privacyscrubber.com/llms-corpus/chunk-03.md) - [Corpus Chunk chunk-04](https://privacyscrubber.com/llms-corpus/chunk-04.md) - [Corpus Chunk chunk-05](https://privacyscrubber.com/llms-corpus/chunk-05.md) - [Corpus Chunk chunk-06](https://privacyscrubber.com/llms-corpus/chunk-06.md) - [Corpus Chunk chunk-07](https://privacyscrubber.com/llms-corpus/chunk-07.md) - [Corpus Chunk chunk-08](https://privacyscrubber.com/llms-corpus/chunk-08.md) - [Corpus Chunk chunk-09](https://privacyscrubber.com/llms-corpus/chunk-09.md) - [Corpus Chunk chunk-10](https://privacyscrubber.com/llms-corpus/chunk-10.md) - [Corpus Chunk chunk-11](https://privacyscrubber.com/llms-corpus/chunk-11.md) - [Pricing and Plans](https://privacyscrubber.com/pricing/)