Local AI Security

Zero-Trust Local PII MCP Server

Stop sending sensitive corporate databases, API keys, and private code to the cloud. Deploy a local PII MCP server that automatically masks data "on the fly" directly on your developers' machines before the context ever reaches OpenAI Codex, ChatGPT Desktop, Cursor, Claude Desktop, or Windsurf. Full compliance with zero data leaks.

Free with Quota · Test in 30s · Zero Config · 100% Local stdio

Enterprise DLP: Your Code Never Touches Our Network

PrivacyScrubber MCP is built from the ground up for zero-friction developer integration and absolute enterprise regulatory compliance.

Auto-Profile Switching

The PII MCP reads all 30 specialized industry profiles from tool schemas. Based on your prompt (e.g. database query, medical log), it automatically applies the correct specialized ruleset.

Custom Local Rules

Declare proprietary database ID structures, custom ticket patterns, and internal company naming formats in a local privacyscrubber.json config file.

Offline Validation

License verification is performed 100% locally using RSA signatures. Session quotas and license tiers are verified locally in-process. Zero data is sent to external APIs.

IDE & SDK Ready

Connects out of the box with OpenAI Codex / ChatGPT Desktop, Claude Desktop, Cursor IDE, Windsurf, or custom developer pipelines like the Antigravity SDK using a single-line command.

TEAMSENTERPRISE

Automated Directory Audits & Action/Redact

Don't just detect leaks — fix them. With the Action/Redact tool, your AI agent can physically rewrite files on your local disk, replacing API keys and PII with safe tokens ([EMAIL_1]) while automatically generating .bak backups. Requires a TEAMS or ENTERPRISE subscription for cryptographic rule synchronization across your organization.

Deep Dive

The Action/Redact Tool

Don't just mask data in transit. Enable your local AI agent to physically rewrite files, remove secrets, and generate safe backups directly on your disk.

How to Trigger in Cursor / Claude

Because the PII MCP server natively registers the redact_file and audit_directory_for_pii tools, triggering an automated scrub is as simple as asking your AI assistant in plain English.

  • Zero Configuration: The LLM understands the schema automatically.
  • Safe Execution: Original files are preserved with a .bak extension.
  • 100% Local: The actual redaction happens on your CPU via the PrivacyScrubber regex engine.
"Audit my `./config/` directory and redact any hardcoded AWS keys or database passwords."
Tool Used: audit_directory_for_pii
Found 3 files with secrets. Replaced with [SECRET_KEY_1]. Original files backed up as .bak.

Role-Based Use Cases

DevOps / SRE

Scrubbing Terraform .tf files or CI/CD pipelines of hardcoded AWS, GCP, and Stripe API keys before pushing to a shared repository.

Data Science

Anonymizing raw .csv and .jsonl datasets containing PII before running them through Jupyter Notebooks or Claude Data Analysis.

QA Engineering

Sanitizing production database dumps (.sql) to instantly generate safe, realistic staging environments for testing without exposing real user data.

Security / CISO

Executing automated nightly sweeps across monolithic codebases to catch and redact secrets accidentally committed by junior developers.

Industry-Specific Applications

HIPAA Compliance

Healthcare

Stripping PHI (Patient Names, SSNs, Medical IDs) from clinical trial datasets locally before using an LLM to summarize the trial results or extract insights.

PCI-DSS Standard

Finance

Redacting credit card numbers, SWIFT codes, and IBANs from transaction logs before asking Cursor to write a custom parser for those logs.

Client Confidentiality

LegalTech

Masking client names, addresses, and case numbers in legal briefs before uploading them to an AI contract analyzer for summarization.

How It Works: Zero-Trust Local Processing

The PrivacyScrubber PII MCP server acts as a local security gateway between your IDE (Cursor, Claude, Windsurf) and external LLM endpoints. This zero-trust data sanitization architecture ensures no sensitive data ever leaves your machine.

1

Local Interception

Your prompt, file attachments, or codebase files are intercepted on your machine before they are sent to the AI.

2

Zero-Trust Masking

Identified PII and secrets are instantly replaced with tokens like [EMAIL_1]. The original data remains strictly inside your local RAM.

3

Sanitized Inference

The remote LLM processes only secure tokens. There is zero risk of downstream data retention or training on proprietary info.

4

Interactive Reveal

When the AI responds using placeholders, the MCP server automatically swaps tokens back to their original values inside the IDE.

Secure Workspace Integration

DevSecOps Directory Audit Engine

The same core engine that powers the PrivacyScrubber PII MCP server is natively embedded into our Web Dashboard. Perform 100% offline, zero-server repository scans directly from your browser to proactively detect hardcoded API keys before they leak to AI tools. Learn how this integrates with automated log sanitization workflows and GDPR/CCPA compliance requirements.

  • Secret & IP Detection: Hardcoded rules catch AWS Credentials (AKIA...), JSON Web Tokens (JWT), Cryptographic Private Keys, and Intellectual Property leaks (e.g. Proprietary/Trade Secret headers) in your source code.
  • Zero-Trust Architecture: Using the modern File System Access API, your repository files are read directly into browser memory. No data is ever uploaded to a server.
  • Actionable Audit Reports: Generate instant security summaries showing exactly which files contain leaked secrets before you commit code or grant AI workspace access.
Audit Results Preview
src/config/.env.local1 Leak
AWS Credentials Detected
api/middleware/auth.ts2 Leaks
JSON Web Token (JWT) Detected

PII MCP Server — Model Context Protocol Tool Reference

These tools are automatically declared to your AI client (Cursor, Windsurf, Claude) upon starting the PrivacyScrubber server.

Tool NameParametersFunction & DescriptionTier
sanitize_texttext: string,
profile?: string
Scrubs PII and API keys from prompt text or code. Supports 22 custom industry profiles (e.g. 'Dev', 'Medical', 'Legal').FREE / PRO
reveal_texttext: stringSwaps masked [TOKEN_N] labels back to their original values inside the AI's response using the local session map.FREE / PRO
sanitize_filefile_path: string,
profile?: string
Reads a file path from your workspace, sanitizes it locally, and feeds the sanitized data to the AI agent.PRO / TEAMS
create_default_configNoneCreates a default configurations file (privacyscrubber.json) in the active workspace root directory.PRO / TEAMS
check_statusNoneReturns current PrivacyScrubber tier status, request usage counts, and lists active custom rules.FREE / PRO
generate_compliance_reporttext: string,
framework?: string
Generates a compliance audit report mapping detected PII entities to regulatory frameworks (GDPR, HIPAA, SOC 2, PCI DSS, NIST). Outputs risk levels and remediation guidance.PRO / TEAMS
mark_false_positivetoken: string,
original: string
Marks a specific detection as a false positive so future sanitization runs skip it. Stored locally in the session exclusion list—never transmitted to any server.FREE / PRO
secure_ai_workflowtext: string,
profile?: string
End-to-end workflow tool: sanitizes input, sends to the AI, receives the response, and auto-reveals masked tokens in a single call. Ideal for automated DevSecOps pipelines.PRO / TEAMS
safe_redaction_workflowtext: stringCombines sanitization with an interactive confirmation step, allowing the developer to review and approve each redaction before committing. Designed for security-critical environments requiring human-in-the-loop verification.PRO / TEAMS
guard_execcommand: string,
cwd?: string,
profile?: string
Executes terminal commands in a child process, intercepts stdout/stderr, and redacts secrets line-by-line in volatile RAM before the AI agent receives the output.FREE / PRO
guard_read_filefile_path: string,
profile?: string
Reads sensitive files (.env, configs, credentials) with in-RAM sanitization, token count, and CISO audit telemetry markdown.FREE / PRO
guard_git_diffstaged?: boolean,
profile?: string
Inspects git repository changes (staged or unstaged) with automated secrets redaction before transmitting code review to remote LLMs.FREE / PRO
guard_apply_patchfile_path: string,
content: string,
create_backup?: boolean
Writes code updates to disk, automatically rehydrating token placeholders back to authentic local secrets in RAM with safety backup (.bak).PRO / TEAMS
create_agent_rulesagent_types?: string[]Automatically generates and injects ZTDS security directives into .cursorrules, .windsurfrules, CLAUDE.md, and Copilot configs.FREE / PRO
generate_procurement_memotargetTier?: string,
teamSize?: number,
primaryFramework?: string
Generates an institutional CISO & DPO procurement memorandum, regulatory risk assessment (GDPR, HIPAA, SOC 2, PCI DSS), and ROI business case for commercial licensing.PRO / TEAMS
Autonomous Agent Firewall

Zero-Trust Agentic Guard: Protect Autonomous AI Agents

Autonomous coding agents (Cursor, Windsurf, Claude Code, GitHub Copilot) run terminal commands and read repository files on your behalf. PrivacyScrubber Agentic Guard forms an in-memory barrier, sanitizing CLI output and credentials before they hit cloud models.

CLI Output Interception

Replace raw shell runs with guard_exec or CLI wrapper ps-guard. Output is scrubbed line-by-line in volatile RAM.

cat .env | npx -y -p @privacyscrubber/mcp-server ps-guard --profile dev

Git Diff Sanitization

Inspect staged changes before commit reviews. Staged passwords, tokens, and proprietary keys are tokenized in RAM without polluting git state.

npx -y -p @privacyscrubber/mcp-server ps-guard --diff --staged

1-Click Agent Rule Injection

Instantly deploy Zero-Trust mandates to .cursorrules, .windsurfrules, CLAUDE.md, and .clinerules.

npx -y -p @privacyscrubber/mcp-server ps-guard --rules
Real-World AI Disasters

3 Dangerous Scenarios PrivacyScrubber Stops Before They Happen

Autonomous agents don't know what's private. Without a local firewall, one innocent prompt can leak live database passwords, client contact lists, and secret keys to external model logs.

Scenario 1 File Inspection

The .env Secret Leak

What Goes Wrong

You ask Cursor or Claude Code: "Add Stripe webhooks and test DB connection." The agent scans files, opens .env, and passes your live STRIPE_SECRET_KEY and DATABASE_URL directly into the prompt to external AI servers.

How PrivacyScrubber Saves You

The agent reads configs via guard_read_file. All live secrets turn into [API_KEY_1] in local RAM. When the agent saves code changes, guard_apply_patch puts real keys back on disk. Remote LLMs never see them.

Scenario 2 Shell Execution

The Dirty Error Log Dump

What Goes Wrong

A migration or test fails. You ask the agent: "Fix this error." The agent runs the command in terminal, and the output dumps an unhandled SQL error containing customer emails, phone numbers, or session tokens right into the AI's context window.

How PrivacyScrubber Saves You

Commands execute through guard_exec (or cat file | ps-guard). All terminal output is filtered in RAM in <1ms. The AI sees the stack trace to fix the bug, but every email and phone number is safely tokenized.

Scenario 3 Version Control

The Unchecked git diff Leak

What Goes Wrong

During rapid debugging, you temporarily pasted an API key into a test file. You ask the agent: "Generate a commit message from git diff." The agent sends the raw diff to the cloud model, exposing the temporary secret before you even commit.

How PrivacyScrubber Saves You

The agent reviews changes through guard_git_diff (or ps-guard --diff). Any staged or unstaged secrets are instantly masked in memory. The agent writes a clean commit message and alerts you to the leaked token.

Workspace Custom Rules

Declare proprietary database structures, internal project identifiers, or custom security profiles locally. Create a privacyscrubber.json file at the root of your project or home folder. The local server automatically loads and merges these rules.

Regex Collision Prevention

Rules are sorted by length descending automatically to prevent token collision.

Exclusion Lists

Define safe terms (e.g. localhost, system keywords) that must never be redacted.

// privacyscrubber.json example
{
  "customRules": [
    {
      "pattern": "\\\\b[A-Z]{3}-\\\\d{4}-\\\\d{2}\\\\b",
      "label": "INTERNAL_DB_ID",
      "enabled": true
    }
  ],
  "exclusions": [
    "localhost",
    "main_production_db",
    "PrivacyScrubber"
  ]
}

Hardening AI Coding Workflows

Address data leakage risks in Cursor IDE, Claude Desktop, and terminal agents without breaking code syntax or development velocity.

Automated Token Rehydration

Instruct the AI client to automatically run the reveal_text tool as its last step. Add this instruction to your system prompt presets so original values (e.g. database keys, emails) are automatically restored in the editor viewport:

"At the end of your response, if you used any masked placeholders like [EMAIL_1], you must call the reveal_text tool to restore them before displaying the code."

Zero-Frustration Code Auditing

Security regexes can sometimes redact programming syntax, breaking build compiles. PrivacyScrubber's default template automatically excludes standard developer keywords from sanitization, keeping code fully functional:

  • process.env.* and environment hooks
  • localhost and 127.0.0.1 addresses
  • node_modules directory paths
  • Standard console methods (console.log)

Terminal Shell Sanitization

If an AI agent (Cursor Agent or Claude Code) executes terminal command lines directly, secrets or user data can leak through stderr/stdout. Wrap any command in our lightweight execution utility to sanitize logs and outputs locally before they display or egress:

npx pii-masking-run -- npm run dev
Terminal — Run 100% Offline
# 1-Click auto-detect & configure all installed AI IDEs (Cursor, Claude, VS Code, Zed)
$npx -y @privacyscrubber/mcp-server install --all
> [Auto-Detect] Scanning for Cursor, Claude Desktop, Claude Code, VS Code, Zed, Windsurf...
> [Configured] Injected zero-egress privacyscrubber MCP server safely into client configs
> [Done] Ready! Restart your IDE to start scrubbing prompts in local RAM
Air-Gapped Local Stdio • 0 Phone-Home Pings • Safe Non-Destructive Config Merge

Quick Integration Guides

Universal 1-Click Auto-Installer

Automatically discovers installed AI IDEs on your machine (Cursor, Claude Desktop, Claude Code, VS Code, Zed, Windsurf, Cline) and injects the Zero-Trust MCP configuration without overwriting or corrupting existing tools.

$npx -y @privacyscrubber/mcp-server install --all
Target Claude Code:install --claude-code
Target VS Code:install --vscode
Target Zed:install --zed
Target Cursor:install --cursor
Pro Tip: Pass your commercial key as an env var: PRIVACYSCRUBBER_KEY=your_key npx ...

Frequently Asked Questions

Find quick answers to common questions about the PrivacyScrubber MCP Server deployment, features, and security architecture.

$299/mo · $2,990/yr

Headless Developer SDK

Sanitize prompts, ETL streams, and RAG vector databases directly in your Node.js or Python backend. 1-line client wrapping, sub-1ms in-memory RAM execution, and 0 bytes cloud egress.

100% Free · In-Browser RAM

In-Browser Chrome Extension

Not using an IDE? Intercept and sanitize sensitive prompts as you type directly inside ChatGPT, Claude, and Gemini web interfaces with zero configuration.