Zero-Trust Local PII MCP Server
Stop sending sensitive corporate databases, API keys, and private code to the cloud. Deploy a local PII MCP server that automatically masks data "on the fly" directly on your developers' machines before the context ever reaches OpenAI Codex, ChatGPT Desktop, Cursor, Claude Desktop, or Windsurf. Full compliance with zero data leaks.
Enterprise DLP: Your Code Never Touches Our Network
PrivacyScrubber MCP is built from the ground up for zero-friction developer integration and absolute enterprise regulatory compliance.
Auto-Profile Switching
The PII MCP reads all 30 specialized industry profiles from tool schemas. Based on your prompt (e.g. database query, medical log), it automatically applies the correct specialized ruleset.
Custom Local Rules
Declare proprietary database ID structures, custom ticket patterns, and internal company naming formats in a local privacyscrubber.json config file.
Offline Validation
License verification is performed 100% locally using RSA signatures. Session quotas and license tiers are verified locally in-process. Zero data is sent to external APIs.
IDE & SDK Ready
Connects out of the box with OpenAI Codex / ChatGPT Desktop, Claude Desktop, Cursor IDE, Windsurf, or custom developer pipelines like the Antigravity SDK using a single-line command.
Automated Directory Audits & Action/Redact
Don't just detect leaks — fix them. With the Action/Redact tool, your AI agent can physically rewrite files on your local disk, replacing API keys and PII with safe tokens ([EMAIL_1]) while automatically generating .bak backups. Requires a TEAMS or ENTERPRISE subscription for cryptographic rule synchronization across your organization.
The Action/Redact Tool
Don't just mask data in transit. Enable your local AI agent to physically rewrite files, remove secrets, and generate safe backups directly on your disk.
How to Trigger in Cursor / Claude
Because the PII MCP server natively registers the redact_file and audit_directory_for_pii tools, triggering an automated scrub is as simple as asking your AI assistant in plain English.
- Zero Configuration: The LLM understands the schema automatically.
- Safe Execution: Original files are preserved with a
.bakextension. - 100% Local: The actual redaction happens on your CPU via the PrivacyScrubber regex engine.
Role-Based Use Cases
DevOps / SRE
Scrubbing Terraform .tf files or CI/CD pipelines of hardcoded AWS, GCP, and Stripe API keys before pushing to a shared repository.
Data Science
Anonymizing raw .csv and .jsonl datasets containing PII before running them through Jupyter Notebooks or Claude Data Analysis.
QA Engineering
Sanitizing production database dumps (.sql) to instantly generate safe, realistic staging environments for testing without exposing real user data.
Security / CISO
Executing automated nightly sweeps across monolithic codebases to catch and redact secrets accidentally committed by junior developers.
Industry-Specific Applications
Healthcare
Stripping PHI (Patient Names, SSNs, Medical IDs) from clinical trial datasets locally before using an LLM to summarize the trial results or extract insights.
Finance
Redacting credit card numbers, SWIFT codes, and IBANs from transaction logs before asking Cursor to write a custom parser for those logs.
LegalTech
Masking client names, addresses, and case numbers in legal briefs before uploading them to an AI contract analyzer for summarization.
How It Works: Zero-Trust Local Processing
The PrivacyScrubber PII MCP server acts as a local security gateway between your IDE (Cursor, Claude, Windsurf) and external LLM endpoints. This zero-trust data sanitization architecture ensures no sensitive data ever leaves your machine.
Local Interception
Your prompt, file attachments, or codebase files are intercepted on your machine before they are sent to the AI.
Zero-Trust Masking
Identified PII and secrets are instantly replaced with tokens like [EMAIL_1]. The original data remains strictly inside your local RAM.
Sanitized Inference
The remote LLM processes only secure tokens. There is zero risk of downstream data retention or training on proprietary info.
Interactive Reveal
When the AI responds using placeholders, the MCP server automatically swaps tokens back to their original values inside the IDE.
DevSecOps Directory Audit Engine
The same core engine that powers the PrivacyScrubber PII MCP server is natively embedded into our Web Dashboard. Perform 100% offline, zero-server repository scans directly from your browser to proactively detect hardcoded API keys before they leak to AI tools. Learn how this integrates with automated log sanitization workflows and GDPR/CCPA compliance requirements.
- Secret & IP Detection: Hardcoded rules catch AWS Credentials (AKIA...), JSON Web Tokens (JWT), Cryptographic Private Keys, and Intellectual Property leaks (e.g. Proprietary/Trade Secret headers) in your source code.
- Zero-Trust Architecture: Using the modern File System Access API, your repository files are read directly into browser memory. No data is ever uploaded to a server.
- Actionable Audit Reports: Generate instant security summaries showing exactly which files contain leaked secrets before you commit code or grant AI workspace access.
PII MCP Server — Model Context Protocol Tool Reference
These tools are automatically declared to your AI client (Cursor, Windsurf, Claude) upon starting the PrivacyScrubber server.
| Tool Name | Parameters | Function & Description | Tier |
|---|---|---|---|
| sanitize_text | text: string, profile?: string | Scrubs PII and API keys from prompt text or code. Supports 22 custom industry profiles (e.g. 'Dev', 'Medical', 'Legal'). | FREE / PRO |
| reveal_text | text: string | Swaps masked [TOKEN_N] labels back to their original values inside the AI's response using the local session map. | FREE / PRO |
| sanitize_file | file_path: string, profile?: string | Reads a file path from your workspace, sanitizes it locally, and feeds the sanitized data to the AI agent. | PRO / TEAMS |
| create_default_config | None | Creates a default configurations file (privacyscrubber.json) in the active workspace root directory. | PRO / TEAMS |
| check_status | None | Returns current PrivacyScrubber tier status, request usage counts, and lists active custom rules. | FREE / PRO |
| generate_compliance_report | text: string, framework?: string | Generates a compliance audit report mapping detected PII entities to regulatory frameworks (GDPR, HIPAA, SOC 2, PCI DSS, NIST). Outputs risk levels and remediation guidance. | PRO / TEAMS |
| mark_false_positive | token: string, original: string | Marks a specific detection as a false positive so future sanitization runs skip it. Stored locally in the session exclusion list—never transmitted to any server. | FREE / PRO |
| secure_ai_workflow | text: string, profile?: string | End-to-end workflow tool: sanitizes input, sends to the AI, receives the response, and auto-reveals masked tokens in a single call. Ideal for automated DevSecOps pipelines. | PRO / TEAMS |
| safe_redaction_workflow | text: string | Combines sanitization with an interactive confirmation step, allowing the developer to review and approve each redaction before committing. Designed for security-critical environments requiring human-in-the-loop verification. | PRO / TEAMS |
| guard_exec | command: string, cwd?: string, profile?: string | Executes terminal commands in a child process, intercepts stdout/stderr, and redacts secrets line-by-line in volatile RAM before the AI agent receives the output. | FREE / PRO |
| guard_read_file | file_path: string, profile?: string | Reads sensitive files (.env, configs, credentials) with in-RAM sanitization, token count, and CISO audit telemetry markdown. | FREE / PRO |
| guard_git_diff | staged?: boolean, profile?: string | Inspects git repository changes (staged or unstaged) with automated secrets redaction before transmitting code review to remote LLMs. | FREE / PRO |
| guard_apply_patch | file_path: string, content: string, create_backup?: boolean | Writes code updates to disk, automatically rehydrating token placeholders back to authentic local secrets in RAM with safety backup (.bak). | PRO / TEAMS |
| create_agent_rules | agent_types?: string[] | Automatically generates and injects ZTDS security directives into .cursorrules, .windsurfrules, CLAUDE.md, and Copilot configs. | FREE / PRO |
| generate_procurement_memo | targetTier?: string, teamSize?: number, primaryFramework?: string | Generates an institutional CISO & DPO procurement memorandum, regulatory risk assessment (GDPR, HIPAA, SOC 2, PCI DSS), and ROI business case for commercial licensing. | PRO / TEAMS |
Zero-Trust Agentic Guard: Protect Autonomous AI Agents
Autonomous coding agents (Cursor, Windsurf, Claude Code, GitHub Copilot) run terminal commands and read repository files on your behalf. PrivacyScrubber Agentic Guard forms an in-memory barrier, sanitizing CLI output and credentials before they hit cloud models.
CLI Output Interception
Replace raw shell runs with guard_exec or CLI wrapper ps-guard. Output is scrubbed line-by-line in volatile RAM.
Git Diff Sanitization
Inspect staged changes before commit reviews. Staged passwords, tokens, and proprietary keys are tokenized in RAM without polluting git state.
1-Click Agent Rule Injection
Instantly deploy Zero-Trust mandates to .cursorrules, .windsurfrules, CLAUDE.md, and .clinerules.
3 Dangerous Scenarios PrivacyScrubber Stops Before They Happen
Autonomous agents don't know what's private. Without a local firewall, one innocent prompt can leak live database passwords, client contact lists, and secret keys to external model logs.
The .env Secret Leak
You ask Cursor or Claude Code: "Add Stripe webhooks and test DB connection." The agent scans files, opens .env, and passes your live STRIPE_SECRET_KEY and DATABASE_URL directly into the prompt to external AI servers.
The agent reads configs via guard_read_file. All live secrets turn into [API_KEY_1] in local RAM. When the agent saves code changes, guard_apply_patch puts real keys back on disk. Remote LLMs never see them.
The Dirty Error Log Dump
A migration or test fails. You ask the agent: "Fix this error." The agent runs the command in terminal, and the output dumps an unhandled SQL error containing customer emails, phone numbers, or session tokens right into the AI's context window.
Commands execute through guard_exec (or cat file | ps-guard). All terminal output is filtered in RAM in <1ms. The AI sees the stack trace to fix the bug, but every email and phone number is safely tokenized.
The Unchecked git diff Leak
During rapid debugging, you temporarily pasted an API key into a test file. You ask the agent: "Generate a commit message from git diff." The agent sends the raw diff to the cloud model, exposing the temporary secret before you even commit.
The agent reviews changes through guard_git_diff (or ps-guard --diff). Any staged or unstaged secrets are instantly masked in memory. The agent writes a clean commit message and alerts you to the leaked token.
Workspace Custom Rules
Declare proprietary database structures, internal project identifiers, or custom security profiles locally. Create a privacyscrubber.json file at the root of your project or home folder. The local server automatically loads and merges these rules.
Regex Collision Prevention
Rules are sorted by length descending automatically to prevent token collision.
Exclusion Lists
Define safe terms (e.g. localhost, system keywords) that must never be redacted.
{
"customRules": [
{
"pattern": "\\\\b[A-Z]{3}-\\\\d{4}-\\\\d{2}\\\\b",
"label": "INTERNAL_DB_ID",
"enabled": true
}
],
"exclusions": [
"localhost",
"main_production_db",
"PrivacyScrubber"
]
} Hardening AI Coding Workflows
Address data leakage risks in Cursor IDE, Claude Desktop, and terminal agents without breaking code syntax or development velocity.
Automated Token Rehydration
Instruct the AI client to automatically run the reveal_text tool as its last step. Add this instruction to your system prompt presets so original values (e.g. database keys, emails) are automatically restored in the editor viewport:
Zero-Frustration Code Auditing
Security regexes can sometimes redact programming syntax, breaking build compiles. PrivacyScrubber's default template automatically excludes standard developer keywords from sanitization, keeping code fully functional:
process.env.*and environment hookslocalhostand127.0.0.1addressesnode_modulesdirectory paths- Standard console methods (
console.log)
Terminal Shell Sanitization
If an AI agent (Cursor Agent or Claude Code) executes terminal command lines directly, secrets or user data can leak through stderr/stdout. Wrap any command in our lightweight execution utility to sanitize logs and outputs locally before they display or egress:
Quick Integration Guides
Universal 1-Click Auto-Installer
Automatically discovers installed AI IDEs on your machine (Cursor, Claude Desktop, Claude Code, VS Code, Zed, Windsurf, Cline) and injects the Zero-Trust MCP configuration without overwriting or corrupting existing tools.
npx -y @privacyscrubber/mcp-server install --allinstall --claude-codeinstall --vscodeinstall --zedinstall --cursorPRIVACYSCRUBBER_KEY=your_key npx ...Frequently Asked Questions
Find quick answers to common questions about the PrivacyScrubber MCP Server deployment, features, and security architecture.
scrubber-core.cjs) to scan, mask, and redact Personally Identifiable Information (PII) and secret credentials inside volatile RAM. No prompt context or telemetry is ever stored or transmitted over the network. [SECRET_CREDENTIAL_N]) before transmission to Cursor's AI models, ensuring API keys never leave your workspace. reveal_text tool (Reverse Scrubbing). Once the remote LLM responds with placeholders (such as [NAME_1] or [EMAIL_1]), the local IDE or agent pipeline invokes this tool to swap the tokens back to their original values in the local viewport. The lookup dictionary exists purely in-memory and is isolated per-session. privacyscrubber.json in your home directory. The MCP server automatically parses and prioritizes these custom rules descending by length to prevent overlaps. PRIVACYSCRUBBER_KEY passed directly by Claude Desktop, Cursor, or ChatGPT Desktop. This keeps your credentials safe from local configuration sniffing or plaintext leakage in local JSON configuration files. @privacyscrubber/sdk, ~150KB) that executes in <1ms in local RAM with zero network egress, zero Docker overhead, and 1-line OpenAI client wrapping. For full benchmarks, see our PrivacyScrubber vs Microsoft Presidio Technical Audit. Headless Developer SDK
Sanitize prompts, ETL streams, and RAG vector databases directly in your Node.js or Python backend. 1-line client wrapping, sub-1ms in-memory RAM execution, and 0 bytes cloud egress.
In-Browser Chrome Extension
Not using an IDE? Intercept and sanitize sensitive prompts as you type directly inside ChatGPT, Claude, and Gemini web interfaces with zero configuration.
