Client-Side PII Sanitizer & GenAI Protection — Privacy Scrubber Case Study
Zero-Trust Data Sanitization (ZTDS): Free local MCP server for IDEs, Developer SDK with free trial, and 100% in-browser PII sanitizer eliminating GenAI data leakage.

Key Metric
The Challenge
Enterprise teams in insurance, finance, and legal risked massive compliance fines by pasting confidential documents into ChatGPT, while Cloud DLP tools added secondary exposure points.
- 87% of enterprises lack technical controls to prevent PII from entering GenAI (K2view 2026 data), leaving companies vulnerable during the 471M breach wave.
- Server-side DLP proxies (like Integral Privacy or cloud gateways) create catastrophic supply-chain attack vectors, as proven by the LiteLLM breach leaking terabytes of secrets.
- Gartner projects that by 2029 majority of privacy incidents will stem from AI inferences rather than direct leaks, requiring mandatory client-side pre-processing.
Our Approach
Invented Zero-Trust Data Sanitization (ZTDS) in volatile RAM: 100% free local MCP server for Cursor & IDEs (npx), Developer SDK with free trial for backends, and browser extensions.
- 1Invented Zero-Trust Data Sanitization (ZTDS): all PII detection and masking runs in volatile browser RAM. No data ever leaves the device. A mathematical guarantee, not a policy promise.
- 2Built a 20+ entity detection engine: Names, Emails, Phones, SSNs, Credit Cards, IBANs, Medical Record Numbers, API Keys, Passwords, IPs with 17+ industry profiles (HIPAA, GDPR, SOC 2, Legal, Finance, HR, Developer).
- 3Shipped Chrome and Firefox extensions working automatically across ChatGPT, Claude, Gemini, Copilot, Grok, DeepSeek, and Qwen, scrubbing in real-time before text reaches AI servers.
- 4Shipped Free Local MCP Server and Developer SDK on npm: developers run npx -y @privacyscrubber/mcp-server in Cursor/Claude Desktop for 0ms in-memory protection, while backends use @privacyscrubber/sdk with a free limited trial.
- 5Reversible tokenisation: PII is replaced with [NAME_1], [CARD_2] tokens. The AI reasons with full context intact. One click restores originals from the local session map.
Tech Stack
The Result
Zero data leakage risk. Seamless free developer onboarding in local IDEs with automated upgrade path to Enterprise TEAMS ($99/mo) and bespoke air-gapped MCP gateways.
What We Delivered
- Web app (PWA), Airplane Mode verified, zero server dependency
- Chrome extension, live in Chrome Web Store
- Free Local MCP Server (Cursor, Windsurf, Claude Desktop) via npx -y @privacyscrubber/mcp-server
- Developer SDK with free limited trial (@privacyscrubber/sdk) for Node.js / Next.js backends
- 17+ industry detection profiles: HIPAA, GDPR, SOC 2, Legal, Finance, HR
- CISO Enterprise Whitepaper, lead magnet for enterprise clients
End-Audience Impact
End-users (lawyers, doctors, insurance adjusters) can safely leverage modern AI tools without exposing confidential client files, medical history, or financial records to public AI training datasets.
Finally a tool our compliance team approved without a single revision. Nothing leaves the machine and we can prove it via the Network tab. That is the only standard that works for us.
Want results like these?
Get in touch for a free strategy session.