+972(54) 867-81-80| INFO@BRANDMEWEB.COM| CONTACT US
BrandMeWeb
||
LOGINFREE QUOTE
Security & RLSOngoingprivacyscrubber.com

Privacy Scrubber – Zero-Trust PII Sanitizer

Secured enterprise data completely with a 100% client-side, offline-first PII sanitizer. Zero data ever transmitted.

Privacy Scrubber

Key Metric

Zero
bytes of PII ever transmitted
20+
entity types detected
17+
industry profiles
7
AI platforms covered

The Challenge

Enterprise teams in insurance, finance, and legal risked massive compliance fines by pasting confidential documents into ChatGPT, as Cloud DLP tools added secondary exposure points.

  • 87% of enterprises lack technical controls to prevent PII from entering GenAI (K2view 2026 data), leaving companies vulnerable during the 471M breach wave.
  • Server-side DLP proxies (like Integral Privacy or cloud gateways) create catastrophic supply-chain attack vectors, as proven by the LiteLLM breach leaking terabytes of secrets.
  • Gartner projects that by 2029 majority of privacy incidents will stem from AI inferences rather than direct leaks, requiring mandatory client-side pre-processing.

Our Approach

Invented Zero-Trust Data Sanitization (ZTDS) to run all PII detection entirely in volatile RAM. Deployed a Chrome extension, offline PWA, and an MCP server for secure AI agent integration.

  1. 1Invented Zero-Trust Data Sanitization (ZTDS): all PII detection and masking runs in volatile browser RAM. No data ever leaves the device. A mathematical guarantee, not a policy promise.
  2. 2Built a 20+ entity detection engine: Names, Emails, Phones, SSNs, Credit Cards, IBANs, Medical Record Numbers, API Keys, Passwords, IPs with 17+ industry profiles (HIPAA, GDPR, SOC 2, Legal, Finance, HR, Developer).
  3. 3Shipped Chrome and Firefox extensions working automatically across ChatGPT, Claude, Gemini, Copilot, Grok, DeepSeek, and Qwen, scrubbing in real-time before text reaches AI servers.
  4. 4Published an MCP Server on npm: local AI agents call scrub_pii() and reveal_pii() as native tools. Zero data leaves the machine. Air-gapped compatible.
  5. 5Reversible tokenisation: PII is replaced with [NAME_1], [CARD_2] tokens. The AI reasons with full context intact. One click restores originals from the local session map.

Tech Stack

Vanilla JS (ES Modules)WebAssembly (WASM)Tesseract.js OCRChrome Extension MV3Firefox ExtensionMCP Server (npm)libsodium (XChaCha20-Poly1305)Vercel

The Result

Eliminated all data leakage risk. Secured paying enterprise clients in finance and insurance by supporting HIPAA, GDPR, and SOC 2 compliance profiles.

What We Delivered

  • Web app (PWA), Airplane Mode verified, zero server dependency
  • Chrome extension, live in Chrome Web Store
  • MCP Server published on npm for local AI agent integration
  • 17+ industry detection profiles: HIPAA, GDPR, SOC 2, Legal, Finance, HR
  • CISO Enterprise Whitepaper, lead magnet for enterprise clients

Finally a tool our compliance team approved without a single revision. Nothing leaves the machine and we can prove it via the Network tab. That is the only standard that works for us.

Client

Want results like these?

Get in touch for a free strategy session.