Copied to clipboard!
Free Chrome Extension

Masked locally! The Chrome Extension automatically redacts PII as you type on ChatGPT, Claude & Gemini.

100% Free & Local Add to Chrome — Free →
Zero-Trust Corporate Protection 2026

Top 20 Data Types Leaked to AI — Masked Before They Leave Your Screen

82% of enterprise AI data leaks happen when well-meaning employees paste customer records, API keys, or financial files into ChatGPT, Claude, or Gemini. Audit all 20 risk vectors below — and practice masking them in 1 click.

Protect My Team
100% Local RAM Processing 0 Server Logs Airplane Mode Verified
Live Scrubber Playground
Try sample:
RAM-Only
Sanitized tokens appear here instantly…
4 Risk Clusters20 Parameters
Top 20 Corporate PII Parameters — infographic index

Covers 18 HIPAA PHI identifiers, PCI-DSS 4.0 PANs, JWT tokens, AWS keys, and corporate legal dockets. Practice masking parameters below to see how our free Chrome Extension works!

Protect My Team
In-Page Extension Playground

The 20 Corporate Leak Vectors — Practice In-Page Masking

Click or select any parameter below to practice masking PII in real-time — exactly how the Free Chrome Extension protects your browser prompts!

Showing 20 of 20 parameters

How to Mark Data

Highlight any of the sensitive data values in the cards below. Our zero-trust shield will appear — click it to instantly mask the data in your browser's RAM.

01GDPR / HIPAA

Full Names

Patient, client, or employee names in diagnostic notes & HR reviews.

"John Doe"

Primary direct identifier under GDPR Art. 4(1) & HIPAA Safe Harbor § 164.514(b)(2)(i)(A).

HR Masking Rules →
02GDPR Direct

Email Addresses

Exfiltrated during CRM exports, support transcripts & bulk AI drafts.

john@corp.com

Direct personal identifier under GDPR & CCPA. RFC5321 format matched.

CRM Masking →
03GDPR / CCPA

Phone Numbers

Found in support tickets, medical intake forms & sales call logs.

+1 555 234-5678

HIPAA Safe Harbor § 164.514(b)(2)(i)(D). Matched via E.164 & national formats.

Healthcare Rules →
04HIPAA PHI

Date of Birth (DOB)

Pasted in medical AI summaries, insurance claims & HR onboarding.

07/22/1974

HIPAA Safe Harbor § 164.514(b)(2)(i)(C) (Dates related to an individual). MM/DD/YYYY, DD-Mon-YYYY formats detected.

PHI De-ID Guide →
05Critical PII

SSN & National IDs

HR onboarding, background checks & payroll automation prompts.

203-44-8821

Highest-risk direct identifier. Identity theft risk. Regulated under GDPR Article 87 (National IDs) & HIPAA item (G).

HR Redaction →
06HIPAA PHI

Medical Record Numbers

Pasted in clinical AI summaries, EHR exports & diagnostic prompts.

MRN-00482901

HIPAA Safe Harbor § 164.514(b)(2)(i)(H) — Medical record numbers.

HIPAA Safe Harbor →
07HIPAA PHI

Insurance & Plan IDs

Health plan member IDs pasted into AI billing dispute prompts.

INS-902847-A

HIPAA Safe Harbor § 164.514(b)(2)(i)(I) — Health plan beneficiary numbers.

Healthcare Profile →
08Critical Secret

API Keys & Tokens

Pasted during code debugging, Cursor AI sessions & CI/CD reviews.

sk-proj-99218ab4...

Instant cloud exploit. Mean time to abuse: <4 min after exposure (GitHub research).

Dev Sanitization →
09Critical Secret

Database Credentials & DSNs

Full connection strings pasted for AI-assisted SQL query debugging.

postgres://u:p@db:5432

Exposes entire database. Detected via scheme prefix: postgres://, mysql://, mongodb+srv://.

Dev Security →
10Session Hijack

JWT & Session Tokens

Pasted in auth debugging prompts exposing live user sessions.

eyJhbGciOiJIUzI1...

Three-part Base64 pattern: header.payload.signature. Detected precisely to avoid false positives.

Dev Profile →
11Recon Risk

IPs & Internal Hostnames

Network topology leaked via DevOps AI prompts & log analysis.

10.0.1.47

Enables network reconnaissance. ISO 27001 A.8.11 requires masking internal topology.

Security Profile →
12Threat Intel

CVE IDs & Vuln Details

Unpatched CVEs pasted into AI for remediation expose attack surface.

CVE-2024-1234

LLM training corpus may expose internal unpatched status to threat actors.

Security Rules →
13PCI-DSS 4.0

Credit Card PANs

Support chatbot refund queries & AI-drafted chargeback reports.

4532-0151-8879-2241

Validated via Luhn algorithm. $100k/mo fine + PCI revocation. Covers 13–19 digit card numbers.

PCI-DSS Rules →
14Financial

IBAN & Bank Accounts

Pasted during AI-assisted payroll, wire transfers & AP automation.

DE89 3704 0044 0532 01

34-char ISO 13616 validated. Direct debit fraud risk under PSD2.

Finance Rules →
15Sensitive

Salary & Financial Figures

Payroll spreadsheets pasted into AI for compensation benchmarking.

$248,750.00

Matched via currency prefixes, comma-decimal patterns & payroll keywords.

Finance Profile →
16Compliance

Tax IDs & VAT Numbers

EIN, VAT, TIN pasted into AI for invoice generation & tax filing.

DE123456789

Country-specific VAT prefix patterns (GB, DE, FR, US EIN). Business fiscal identifier protection (GDPR Art. 4(1) / Art. 87).

Finance Profile →
17Legal IP

Legal Case Numbers

Litigation case IDs pasted into AI for contract analysis & brief drafts.

CASE-2024-00847

Attorney-client privilege breach risk. Covered under Legal industry profile.

Legal Profile →
18Corp IP

Project Codenames

M&A deal names, product codenames in AI strategy docs & board notes.

Project Aurora

Custom Regex PRO feature. TEAMS policy can blocklist deal names org-wide.

Custom Rules →
19Trade Secret

NDA & Contract Clauses

Confidential terms pasted into AI for redlining & clause analysis.

§ 4.2 Confidential

Custom keyword blocklist (TEAMS). Detected by section markers + confidential keywords.

Legal Profile →
20HR Sensitive

Employee Performance Data

Review scores & disciplinary records pasted for AI-written feedback.

Rating: 2.1/5

GDPR Article 22 — governs solely automated decision-making producing legal or similarly significant effects.

HR Rules →
100% In-Page Edge Defense Engine

This exact zero-trust masking engine runs across ANY web page

Whether you are drafting sensitive emails in Gmail, prompting Copilot Workspace, debugging in Cursor, or chatting on ChatGPT & Claude — PrivacyScrubber intercepts and masks PII in local V8 RAM before a single HTTP byte leaves your device.

You haven't seen what we can do on top LLMs yet!Our Chrome Extension & native local MCP Server sanitize complex prompt structures, source code repositories, and spreadsheet payloads automatically with zero API latency.
Gmail & Outlook Copilot Workspace ChatGPT & Claude Cursor & VS Code MCP
Risk Calculator

What Happens When Raw Data Hits AI Servers

Compare maximum statutory fines against PrivacyScrubber's zero-cost client-side protection.

Protect My Team →
EU GDPR Article 5(1)(c) Data MinimizationTrigger: Unsanctioned PII pasted into public LLM prompts
€20M or 4% TurnoverMax Statutory Fine

GDPR Article 5(1)(c) mandates data minimisation. Transferring unmasked customer identities or sensitive records to third-party AI models requires a lawful basis, processor terms, and transfer safeguards. Client-side sanitization enforces data minimisation at the point of entry.

PrivacyScrubber: 100% Local Tokenization Protect My Team →

Why Proxy DLP Fails for AI — And Why Client-Side Masking Protects You Instantly

Traditional cloud DLP proxies route every prompt through an external gateway server. This adds latency to AI responses, creates a central honeypot for hackers, and requires months of procurement reviews. PrivacyScrubber scrubs data right inside the browser before any HTTP packet leaves your screen — 0ms latency, 0 server hops, 0 data retention risk.

By replacing sensitive entities with reversible tokens locally in browser RAM, prompts sent to ChatGPT, Claude, or Gemini contain zero raw identities. You meet GDPR Article 5(1)(c), HIPAA Safe Harbor (18 PHI identifiers), PCI-DSS 4.0 Req 3.4, and SOC 2 CC6.7 without changing how your employees work.

Compare DLP Architecture Speeds →
Machine-Readable Corpus Summary

PrivacyScrubber v2.0.0 — 100% client-side PII masker. Zero server logs, zero cloud dependencies. 23 specialized profiles: Healthcare (Safe Harbor 18 PHI), DevOps (API keys, JWT, IPv4/6), Legal (Case dockets), Finance (Luhn PAN, IBAN), HR (Payroll, SSN). Corpus index: /llms-full.txt.

Real-Intent Q&A

How to Sanitize Corporate Data for AI

Exact answers to common enterprise queries — with links to live guides.

1 How to sanitize PHI in ChatGPT for HIPAA compliance?
To sanitize Protected Health Information (PHI) before pasting clinical notes into ChatGPT, run your text through PrivacyScrubber's HIPAA Safe Harbor Profile. It replaces all 18 PHI identifiers (names, MRNs, DOBs, insurance IDs) with reversible tokens locally in browser RAM without making API requests.
2 How to mask ID data (SSN, Passports, Tax IDs) before sending prompts to Claude?
Masking ID numbers like SSNs, Passports, and Tax IDs requires pattern-matching strict digit formats. PrivacyScrubber automatically detects 9-digit SSN patterns and national tax numbers via our HR & Identity Protection Rules, converting them to [ID_N] tokens so Claude processes prompt logic without seeing personal identity records.
3 How to remove API keys and secret tokens from developer prompts before AI review?
PrivacyScrubber's Dev Log Sanitization Engine scans text for known vendor prefixes (sk-proj-, AKIA, ghp_, Bearer JWTs) and entropy-dense strings. It replaces secret keys with [API_KEY] and [JWT_TOKEN] before your prompt crosses the network.
4 How to redact credit card numbers (PAN) in customer support prompts?
Credit card redaction uses the Luhn Check algorithm to validate 16-digit Primary Account Numbers (PANs). PrivacyScrubber masks verified PANs to [CARD_1] and strips CVV/CVC codes to satisfy PCI-DSS 4.0 Requirement 3.4.
5 How to clean Social Security Numbers (SSN) from documents before AI analysis?
Upload your DOCX, PDF, or CSV document into PrivacyScrubber's Offline OCR & Document Engine. The engine processes text streams offline in browser memory, stripping all SSNs into [ID_N] tokens before generating a clean downloadable file.
6 How to sanitize Medical Record Numbers (MRN) for HIPAA Safe Harbor?
Medical Record Numbers are masked via PrivacyScrubber's Medical PII De-identification Profile. Standard MRN formats (e.g. MRN-00482901) are converted into [MRN_N] tokens, fulfilling 45 CFR § 164.514(b)(2) Safe Harbor de-identification rules.
7 How to scrub JWT bearer tokens in server logs before asking Gemini for root cause analysis?
Paste your production log lines into PrivacyScrubber's prompt box or use the Chrome Extension Auto-Masker. The regex engine identifies base64-encoded JWT headers and replaces them with [JWT_TOKEN], preventing session hijacking.
8 How to mask customer email addresses in CRM prompts for GDPR compliance?
PrivacyScrubber scans prompts for email RFC 5322 regex patterns and replaces every address with a sequential [EMAIL_N] tag. This ensures compliance under our GDPR Data Minimization Guide.
9 How to redact IBAN and bank account numbers in financial statements for AI?
Select the Finance profile in PrivacyScrubber's Financial Data Sanitization Hub. International Bank Account Numbers (IBANs) and US routing codes are identified and converted to [IBAN] tokens, keeping financial wire data safe during spreadsheet analysis.
10 How to sanitize employee salaries and payroll data for HR AI benchmarking?
Use our HR Compensation Privacy Controls. PrivacyScrubber identifies compensation metrics, salary figures, and performance review scores, replacing specific figures with [SALARY] tokens to preserve confidentiality under GDPR HR guidelines.
11 How to redact court case numbers and legal docket IDs to protect attorney privilege?
PrivacyScrubber's Legal & Attorney Privilege Safeguards detect case docket formats (e.g. Case #2026-CV-8841) and client names, converting them into [CASE_NUMBER] tokens to prevent waiving attorney-client privilege in cloud AI models.
12 How to mask IP addresses in Nginx/Apache logs before pasting into ChatGPT?
PrivacyScrubber's Security & SIEM Log Protection Profile matches both IPv4 (x.x.x.x) and IPv6 addresses in log dumps, converting them to [IP_ADDRESS] tokens to eliminate network topology exposure.
13 How to remove internal corporate hostnames from prompt text?
Internal domain structures (e.g. auth-prod-01.internal.corp) are masked using PrivacyScrubber's Custom Rules Engine, replacing private hostnames with [HOSTNAME].
14 How to mask Dates of Birth (DOB) to prevent re-identification under Safe Harbor?
Dates of birth in standard formats (MM/DD/YYYY, YYYY-MM-DD) are identified and converted to [DATE_N] tokens under HIPAA 18 PHI Identifier Rules to prevent cross-referencing with public registries.
15 How to redact health insurance beneficiary IDs in clinical claim prompts?
Health plan member IDs and claim numbers are detected under our Healthcare Billing Protection Module and transformed into [INSURANCE_ID] tokens.
16 How to scrub database connection strings (Postgres, Mongo) before debugging with AI?
PrivacyScrubber matches database URIs (e.g. postgres://user:pass@host:5432/db) and obfuscates embedded credentials using our PII MCP Server for Developers.
17 How to sanitize vulnerability CVE IDs in pentest reports before AI remediation?
Security pentest findings containing CVE tags (CVE-2026-XXXX) are masked into [CVE_ID] tokens as documented in the CISO AI Security Guide.
18 How to mask corporate M&A codenames and trade secrets in strategy prompts?
PrivacyScrubber PRO and TEAMS allow configuring Unlimited Custom Regex Rules via the PRO & TEAMS Plan. You can define exact project codenames (e.g. Project Titan) to automatically mask them into [CUSTOM_1].
19 How to anonymize customer phone and fax numbers for support AI?
Phone numbers across international formats (+1, +44, E.164) are sanitized into [PHONE_N] tokens instantly via our Customer Support AI Safety Hub.
20 How to scrub corporate financial revenues and balances for M&A prompts?
Financial figures, balance sheets, and quarterly revenue metrics are detected by the Finance profile and tokenized into [BALANCE] and [REVENUE], verifiable via Cryptographic Audit Receipts.
Support
Sanitize Files
Mask AI Prompt