Skip to main content
Glama
tylerscomic-lab

PII & Secret Redactor

PII & Secret Redactor

Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.

Send the question, not the customer's data

Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.

Related MCP server: ai-security-gateway-mcp

What it detects

  • Verified, not just matched: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.

  • Contact and identity: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.

  • Secrets: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.

Tools

  • detect_pii: findings with type, position and a masked preview. Never echoes full values.

  • redact_text: placeholder (stable tokens like <EMAIL_1>, same value gives the same token), mask, salted hash, or remove.

  • restore_text: swap placeholders back to the originals in the model's response, using the mapping you keep.

  • list_detectors: exactly what is and is not covered.

Be clear about the limits

Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.

Use it

Hosted on MCPize with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):

https://pii-redactor-mcp.mcpize.run/mcp

Or run it yourself:

npm install
node server.js   # listens on :8080, MCP at /mcp

MIT licensed.

Related MCP Connectors

Related MCP Servers

  • A
    license
    A
    quality
    A
    maintenance
    Sanitizes text and files by removing PII, secrets, and custom patterns locally before sending to LLMs, with optional reverse-scrubbing.
    3
    328 npm
    2
    Cryptographic Autonomy 1.0 (Combined Work Exception)