ztds-mcp
Click on "Deploy Server".
Wait a few minutes for the server to deploy. Once ready, it will show a "Started" state.
In the chat, type
@followed by the MCP server name and your instructions, e.g., "@ztds-mcpMask the PII in this support ticket before sending it to the LLM."
That's it! The server will respond to your query, and you can continue using it as needed.
Here is a step-by-step guide with screenshots.
ZTDS MCP Server (ztds-mcp)
Open-source reference implementation of the Zero-Trust Data Sanitization (ZTDS) protocol for the Model Context Protocol (MCP) ecosystem. Conforms to the open architectural specification and IETF Internet-Draft draft-sibiryakov-ztds-protocol-00.
Runs 100% locally with zero network calls, zero external subprocessors, zero disk writes, and zero telemetry.
The 4 Core Protocol Invariants
Invariant 1: Zero External Egress Prior to Sanitization
Cleartext PII, PHI, and credentials never cross the local execution boundary unmasked.Invariant 2: Deterministic Context-Preserving Reversible Tokenization
Sensitive values are replaced by synthetic tokens ([EMAIL_TOKEN_1],[API_SECRET_TOKEN_1]) maintaining syntactic context for LLMs.Invariant 3: Verifiable Ephemeral RAM Isolation (Theorem 2 Zeroization)
Mapping tables exist strictly in volatile memory and are zeroized upon session termination.Invariant 4: Subprocessor Chain Exclusion
Operates strictly as a local computational utility under GDPR Recital 26, rendering Data Processing Agreements (DPAs) unnecessary.
Related MCP server: phantomswap
Installation & Client Configuration
1. Claude Desktop
Add to your claude_desktop_config.json:
{
"mcpServers": {
"ztds": {
"command": "npx",
"args": ["-y", "ztds-mcp"]
}
}
}Config file locations:
macOS:
~/Library/Application Support/Claude/claude_desktop_config.jsonWindows:
%APPDATA%\Claude\claude_desktop_config.jsonLinux:
~/.config/Claude/claude_desktop_config.json
2. Cursor IDE
Add to your Cursor MCP settings (Settings -> Features -> MCP -> Add New MCP Server):
Name:
ztdsType:
commandCommand:
npx -y ztds-mcp
Or add to .cursor/mcp.json in your workspace:
{
"mcpServers": {
"ztds": {
"command": "npx",
"args": ["-y", "ztds-mcp"]
}
}
}3. Windsurf / Codeium
Add to ~/.codeium/windsurf/mcp_config.json:
{
"mcpServers": {
"ztds": {
"command": "npx",
"args": ["-y", "ztds-mcp"]
}
}
}Available MCP Tools
Tool | Description |
| Masks sensitive PII/credentials with deterministic surrogate tokens prior to LLM transmission. |
| Restores original cleartext from volatile in-memory mapping into LLM output. |
| Scans text for exposed credentials and PII, returning SHA-256 integrity receipt and risk score. |
| Retrieves RFC v1.0 standard details, academic citations, and enterprise documentation. |
| Purges and zeroizes all volatile session token mappings (Theorem 2). |
Universal Baseline vs Commercial Production Profiles
This open-source server covers universal baseline entities (Email, Phone, SSN, Credit Cards, IPv4, IBAN, API Secrets).
For production enterprise workloads requiring:
30+ Specialized Industry Profiles: HIPAA PHI (18 identifiers), PCI-DSS (cardholder data & CVV), GLBA Financial, SEC 17a-4, CJIS Law Enforcement, FERPA Student Records, European National IDs.
Agentic Guard Automation: Autonomous zero-trust tool wrappers (
guard_exec,guard_read_file,guard_apply_patch).Team Seat Licensing: Offline air-gapped license tokens without cloud telemetry.
Headless SDK: Backend RAG pipeline redaction for Node.js / TypeScript / Python.
Deploy the production commercial engine:
# Production MCP Server
npm install -g @privacyscrubber/mcp-server
# Headless Backend SDK
npm install @privacyscrubber/sdkWebsite: https://privacyscrubber.com
Verification & Self-Test
To run the offline test suite:
node test.jsConforms to standard JSON-RPC 2.0 stdio protocol. Zero runtime dependencies.
License
Apache-2.0. Maintained by the ZTDS AI Consortium (Working Group WG-1). Website: https://ztds.ai
This server cannot be deployed
Maintenance
Related MCP Connectors
Detect and redact PII and secrets before text reaches an LLM, with reversible placeholders.
Redact PII from text before it reaches a model. Nothing stored, no third-party AI.
Deterministic runtime safety for AI agents: scan PII, gate tool actions, verify LLM output.
Deterministic trust gate for AI output: leaked-secret, prompt-injection & PII in one call.
Related MCP Servers
- AlicenseAqualityDmaintenanceScans prompts for PII and masks or redacts sensitive data locally before sending to an LLM, supporting multiple anonymization modes.1MIT
- AlicenseAqualityCmaintenanceEnables AI assistants to mask sensitive personal data and project directories before sending to AI, then unmask responses to restore original values using configurable swap sessions.7MIT
- AlicenseAqualityBmaintenanceEnables safe interaction with cloud LLMs by redacting sensitive entities into reversible placeholders, enforcing deterministic egress policies with human approval, and rehydrating responses so real data never leaves the process.4MIT
- FlicenseNot gradedqualityBmaintenanceEnables local zero-knowledge encryption of a personal vault and sanitization of PII such as credentials, credit cards, and addresses before dispatch to cloud LLMs, with client-side rehydration of masked data.7-