PII & Secret Redactor
README.md
# PII & Secret Redactor
Redact PII and secrets from text before it reaches an LLM. Checksum-verified cards, IBANs and routing numbers, SSN range rules, API keys, and reversible placeholders you can restore after the model responds.
## Send the question, not the customer's data
Strip personal data and credentials out of text before it goes to a model, a log or a ticket, then put the originals back in the answer.
## What it detects
- **Verified, not just matched**: credit cards (Luhn, brand identified), IBANs (mod-97), US routing numbers (ABA checksum), SSNs (invalid ranges rejected). Order numbers and random digit strings are left alone.
- **Contact and identity**: emails, phone numbers (US and international), labelled dates of birth, US street addresses, IPv4 and IPv6.
- **Secrets**: Anthropic, OpenAI, AWS, GitHub, Stripe, Slack and Google keys, JWTs, private keys, database URLs with credentials.
## Tools
- `detect_pii`: findings with type, position and a masked preview. Never echoes full values.
- `redact_text`: placeholder (stable tokens like `<EMAIL_1>`, same value gives the same token), mask, salted hash, or remove.
- `restore_text`: swap placeholders back to the originals in the model's response, using the mapping you keep.
- `list_detectors`: exactly what is and is not covered.
## Be clear about the limits
Pattern and checksum based. It does not detect personal names or free-form addresses in other formats, so it reduces exposure but is not a compliance guarantee for HIPAA, GDPR or PCI. Input is processed in memory and never stored or logged.
## Use it
Hosted on [MCPize](https://mcpize.com/mcp/pii-redactor-mcp) with a free tier (10 calls a day). Remote MCP endpoint (streamable HTTP, API key from MCPize):
```
https://pii-redactor-mcp.mcpize.run/mcp
```
Or run it yourself:
```bash
npm install
node server.js # listens on :8080, MCP at /mcp
```
MIT licensed.
This server cannot be deployed
Maintenance
ActivityMaintained
ResponsivenessNo issues