PrivacyScrubber PII Masker

by moxno

1.4k downloads Not rated yet

About

Zero-Trust Data Sanitization (ZTDS) local PII and secrets scrubber for secure LLM pipelines.

Explore

Setting up with Highlight

This MCP is not yet compatible with Highlight’s one-click setup. However, you can still use it with Highlight by following these steps:

  1. Download and install Highlight from highlightai.com/download
  2. Navigate to the plugins tab and select "Add Custom Plugin"
  3. Configure the plugin with the settings below
    Plugin Name PrivacyScrubber PII Masker
    Command (node, npx, python, etc.)

    Please refer to the README for specific instructions on how to obtain API keys or other required environment variables.

  4. Enable "Start Automatically" if you want the plugin to start when Highlight launches

text

(string, required): The raw content or logs to sanitize.

profile

(string, optional): Gated industry detection profile (e.g., 'General', 'Dev', 'Medical', 'Legal', 'Compliance'). Defaults to 'General'.

filePath

(string, required): Absolute file path to read and sanitize.

Redacts PII, secrets, API keys, and credentials from a text block and populates the volatile local replacement mapping.

- Arguments:

- text(string, required): The raw content or logs to sanitize.
- profile(string, optional): Gated industry detection profile (e.g., 'General', 'Dev', 'Medical', 'Legal', 'Compliance'). Defaults to 'General'.

{ "method": "tools/call", "params": { "name": "sanitize_text", "arguments": { "text": "Contact me at dev-key-1234 or [email protected]", "profile": "General" } } }
{ "content": [ { "type": "text", "text": "Contact me at [SECRET_1] or [EMAIL_1]" } ] }

Detokenizes the AI response back to the original values locally.

- Arguments:

- text(string, required): The response from the LLM containing tokenized placeholders.

{ "method": "tools/call", "params": { "name": "reveal_text", "arguments": { "text": "Please reach out to [EMAIL_1] regarding the update." } } }
{ "content": [ { "type": "text", "text": "Please reach out to [email protected] regarding the update." } ] }

Reads a local file, extracts text, sanitizes it, and returns the redacted template for LLM analysis.

- Supported Formats:Plain text (source code, logs, CSV, JSON, markdown) and Microsoft Word (.docx) documents.
- Arguments:

- filePath(string, required): Absolute file path to read and sanitize.
- profile(string, optional): The industry detection profile.

Looking for real-time protection directly inside your web browser?

- Chrome Extension:Get thePrivacyScrubber Chrome Extensionto sanitize prompts directly inside ChatGPT, Claude, and Gemini in real-time.
- Web Sandbox:Use the zero-server browser sanitization tools at
PrivacyScrubber Homepage.

By default, the server runs under theFree Tier(restricted to 50,000 characters per request and the basicGeneralPII profile). To unlock advanced engineering, medical, legal, and financial PII profiles, as well as team-wide custom rules, you can purchase a commercial license.

πŸ‘‰[Acquire a PRO / TEAMS License Key at privacyscrubber.com/pricing

Returns a visual dashboard showing your current tier, session request count, active profiles, and upgrade instructions. Use it at any time to check your license status or get setup help.

- Arguments:(none required)
- JSON-RPC Call Example:

{ "method": "tools/call", "params": { "name": "check_status", "arguments": {} } }
╔══════════════════════════════════════════════════╗ β•‘ PrivacyScrubber MCP Server v1.6.6 β•‘ ╠══════════════════════════════════════════════════╣ β•‘ πŸ”“ Tier: FREE β•‘ β•‘ πŸ“Š Session requests: 5 β•‘ β•‘ πŸ“ Input size limit: 50,000 characters per requestβ•‘ ╠══════════════════════════════════════════════════╣ β•‘ 🏷️ Profiles: General only β€” PRO unlocks 22 more β•‘ β•‘ πŸ“‹ Custom rules: πŸ”’ Locked β€” requires PRO β•‘ ╠══════════════════════════════════════════════════╣ β•‘ πŸ’³ Upgrade to PRO β€” $110 Lifetime β•‘ β•‘ https://privacyscrubber.com/pricing β•‘ ╠══════════════════════════════════════════════════╣ β•‘ After purchase, add your key to MCP config: β•‘ β•‘ "PRIVACYSCRUBBER_KEY": "<your-key-here>" β•‘ β•‘ Full setup guide: β•‘ β•‘ https://privacyscrubber.com/features/mcp/ β•‘ β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

Claude Desktop / Cursor

Paste into your MCP client config file to install this server.

{
    "mcpServers": {
        "privacyscrubber pii masker": {
            "server": {
                "command": "npx",
                "args": [
                    "-y",
                    "@privacyscrubber/mcp-server"
                ],
                "env": {
                    "PRIVACYSCRUBBER_KEY": ""
                }
            }
        }
    }
}

McpServers

{
    "server": {
        "command": "npx",
        "args": [
            "-y",
            "@privacyscrubber/mcp-server"
        ],
        "env": {
            "PRIVACYSCRUBBER_KEY": ""
        }
    }
}

Transport

"stdio"

Package

"@privacyscrubber/mcp-server"

Registry

"npm"

CISO-Approved Zero-Trust PII & Secrets Redaction MCP Server for Cursor, Windsurf, and Claude Desktop.Locally scrubs PII, secrets, credentials, and custom regex rules from files and text contexts before they reach remote LLM providers to prevent API leaks and ensure HIPAA/SOC 2 compliance at the developer endpoint.

All sensitive parameters, identifiers, and variables are intercepted locally inside your machine's RAM. They are replaced by tokens (e.g.[EMAIL_1]) before being sent to the AI. Once the AI responds, the tokens are safely swapped back to original values in your local context.

[Raw Input / Files] ──> [MCP sanitize_text] ──> [Masked Tokens] ──> [LLM API] β”‚ β”‚ (In-Memory Map) (Result) β”‚ β”‚ [Original Output] <─── [MCP reveal_text] <β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜

To automatically configure and run with your preferred client, install using Smithery:

npx -y @smithery/cli install @privacyscrubber/mcp-server --write-to-clients

Run the server directly without local installation:

Add this to your Claude Desktop config file:

- macOS:~/Library/Application Support/Claude/claude_desktop_config.json
- Windows:%APPDATA%\Claude\claude_desktop_config.json

{ "mcpServers": { "privacyscrubber": { "command": "npx", "args": ["-y", "@privacyscrubber/mcp-server"], "env": { "PRIVACYSCRUBBER_KEY": "YOUR_OPTIONAL_PRO_LICENSE_KEY" } } } }

- Navigate to Settings -> Features -> MCP.
- Add new MCP server:

- Name:privacyscrubber
- Type:command
- Command:npx -y @privacyscrubber/mcp-server

πŸ› οΈ Provided Tools & JSON-RPC Specifications

Redacts PII, secrets, API keys, and credentials from a text block and populates the volatile local replacement mapping.

- Arguments:

- text(string, required): The raw content or logs to sanitize.
- profile(string, optional): Gated industry detection profile (e.g., 'General', 'Dev', 'Medical', 'Legal', 'Compliance'). Defaults to 'General'.

{ "method": "tools/call", "params": { "name": "sanitize_text", "arguments": { "text": "Contact me at dev-key-1234 or [email protected]", "profile": "General" } } }
{ "content": [ { "type": "text", "text": "Contact me at [SECRET_1] or [EMAIL_1]" } ] }

Detokenizes the AI response back to the original values locally.

- Arguments:

- text(string, required): The response from the LLM containing tokenized placeholders.

{ "method": "tools/call", "params": { "name": "reveal_text", "arguments": { "text": "Please reach out to [EMAIL_1] regarding the update." } } }
{ "content": [ { "type": "text", "text": "Please reach out to [email protected] regarding the update." } ] }

Reads a local file, extracts text, sanitizes it, and returns the redacted template for LLM analysis.

- Supported Formats:Plain text (source code, logs, CSV, JSON, markdown) and Microsoft Word (.docx) documents.
- Arguments:

- filePath(string, required): Absolute file path to read and sanitize.
- profile(string, optional): The industry detection profile.

Looking for real-time protection directly inside your web browser?

- Chrome Extension:Get thePrivacyScrubber Chrome Extensionto sanitize prompts directly inside ChatGPT, Claude, and Gemini in real-time.
- Web Sandbox:Use the zero-server browser sanitization tools at
PrivacyScrubber Homepage.

By default, the server runs under theFree Tier(restricted to 50,000 characters per request and the basicGeneralPII profile). To unlock advanced engineering, medical, legal, and financial PII profiles, as well as team-wide custom rules, you can purchase a commercial license.

πŸ‘‰Acquire a PRO / TEAMS License Key at privacyscrubber.com/pricing

Returns a visual dashboard showing your current tier, session request count, active profiles, and upgrade instructions. Use it at any time to check your license status or get setup help.

- Arguments:(none required)
- JSON-RPC Call Example:

{ "method": "tools/call", "params": { "name": "check_status", "arguments": {} } }
╔══════════════════════════════════════════════════╗ β•‘ PrivacyScrubber MCP Server v1.6.6 β•‘ ╠══════════════════════════════════════════════════╣ β•‘ πŸ”“ Tier: FREE β•‘ β•‘ πŸ“Š Session requests: 5 β•‘ β•‘ πŸ“ Input size limit: 50,000 characters per requestβ•‘ ╠══════════════════════════════════════════════════╣ β•‘ 🏷️ Profiles: General only β€” PRO unlocks 22 more β•‘ β•‘ πŸ“‹ Custom rules: πŸ”’ Locked β€” requires PRO β•‘ ╠══════════════════════════════════════════════════╣ β•‘ πŸ’³ Upgrade to PRO β€” $110 Lifetime β•‘ β•‘ https://privacyscrubber.com/pricing β•‘ ╠══════════════════════════════════════════════════╣ β•‘ After purchase, add your key to MCP config: β•‘ β•‘ "PRIVACYSCRUBBER_KEY": "<your-key-here>" β•‘ β•‘ Full setup guide: β•‘ β•‘ https://privacyscrubber.com/features/mcp/ β•‘ β•šβ•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•β•

πŸ” After Purchase: Activate PRO in Your MCP Client

After purchasing a PRO license atprivacyscrubber.com/pricing, you will receive a license key. Add it to your MCP client config as an environment variable:PRIVACYSCRUBBER_KEY.

Edit~/Library/Application Support/Claude/claude_desktop_config.json(macOS) or%APPDATA%\Claude\claude_desktop_config.json(Windows):

{ "mcpServers": { "privacyscrubber": { "command": "npx", "args": ["-y", "@privacyscrubber/mcp-server"], "env": { "PRIVACYSCRUBBER_KEY": "YOUR_LICENSE_KEY_HERE" } } } }

- Go toSettings β†’ Features β†’ MCP Servers.
- Findprivacyscrubberand clickEdit.
- Add the environment variable:PRIVACYSCRUBBER_KEY=YOUR_LICENSE_KEY_HERE.
- Restart Cursor.

Alternatively, export it system-wide so all tools pick it up:

# macOS / Linux β€” add to ~/.zshrc or ~/.bashrc export PRIVACYSCRUBBER_KEY="YOUR_LICENSE_KEY_HERE"

Edit~/.codeium/windsurf/mcp_config.json:

{ "mcpServers": { "privacyscrubber": { "command": "npx", "args": ["-y", "@privacyscrubber/mcp-server"], "env": { "PRIVACYSCRUBBER_KEY": "YOUR_LICENSE_KEY_HERE" } } } }

After adding the key, ask your AI agent to callcheck_status:

Use the check_status tool from PrivacyScrubber MCP

The dashboard should showTier: PROand all profiles unlocked.

This is a web browser that enables your coding agent, such as Claude Code, to visit websites on your behalf and assist you in identifying bugs or creating UI test cases.

Local, privacy-preserving PII detection & redaction over MCP: the model works on shape (schemas, synthetic twins, masked output) while local code touches the real values and returns only masked, aggregated results. Deterministic (Presidio + checksums, AU ABN/ACN/TFN), no LLM calls, no runtime network.

Paid remote MCP for agent data-access boundary reviews, permission scope evidence, sensitive data notes, and governance receipts.

EXIF for AI. AKF embeds trust scores, source provenance, and compliance metadata into every file your AI touches β€” DOCX, PDF, images, code, and 20+ formats. 9 MCP tools: stamp, inspect, trust, audit, scan, embed, extract, detect. Audit against EU AI Act, SOX, HIPAA, NIST in one command.

Paid remote MCP for LLM trace PII scanning, payload redaction, sensitive field classification, privacy receipts, and trace audit exports.

Security and compliance layer for MCP agents. The analyze_prompt tool checks any input β€” user messages, RAG retrievals, tool outputs β€” for prompt injection (22 deterministic signatures, 7 languages) and PII before your model sees it. Every verdict returns a signed audit record (SHA-256 + UUID + UTC) you can retain as GDPR Art. 30 evidence. Free tier: 10,000 requests/month.

Allows access to DFIR / forensics data that was analyzed by the open source Autopsy platform

Connect to your CISO Adapt workspace to search, analyse, export, and manage risks and policies with natural language

CVE/SBOM security audits, licence compliance, frontend security scanning, domain intelligence, and public records β€” 55 tools, no API key required Category: Security (also fits: Compliance, Data)

MCP server that pseudonymizes PII before your LLM sees it and returns a cryptographically signed receipt for every response.

No reviews yet β€” be the first

Sign in to leave a review

Use Google, GitHub, or an email account so ratings stay tied to real people.

Email sign in

No reviews posted yet.