+972(54) 867-81-80
BrandMeWeb
Tracker
In-Browser Zero-Trust Linter • ZTDS™ RFC v1.0

Is Your Team Leaking Sensitive Data into OpenAI & Anthropic?

Audit prompts, customer data, and RAG pipelines for PII, financial secrets, and credentials before they leave your perimeter. Runs 100% in local memory with zero network egress.

Zero Network Egress: This engine executes strictly inside client V8/WASM memory. You can disconnect your internet (Airplane Mode ON) and verify sub-2ms local execution.

Execution Speed
0.11 ms
Network Egress
0 Bytes
Entities Detected
5
ZTDS Safety Score
30% (Critical Regulatory Breach)

Regulatory Violations & Statutory Liability:

Israel Privacy Protection Law Amendment 13 (תיקון 13)
Direct administrative fine up to ₪3,200,000 for transferring personal databases to external LLM providers without explicit authorization. Statutory civil damages up to ₪10,000 per data subject without proof of injury.
GDPR Article 28 / Recital 26 Subprocessor Chain Breach
Transmitting unmasked PII to US AI cloud APIs creates an uncertified subprocessor relationship without a valid DPA. Regulatory fines up to €20,000,000 or 4% of annual global turnover.
Detected Sensitive Entities & Reversible Token Vault:
Israeli National ID (תעודת זהות):03•••••91{{ISRAELI_ID_1}}
Bank Account / IBAN (חשבון בנק):IL02 •••• •••• 4567{{BANK_IBAN_1}}
Financial Valuation / AUM (היקף הון / שווי):[CONFIDENTIAL_VALUATION]{{FINANCIAL_VALUATION_1}}
Email Address (דואר אלקטרוני):yo•••@enterprise.co.il{{EMAIL_TOKEN_1}}
Phone Number (מספר טלפון):054-••••80{{PHONE_TOKEN_1}}
Reversible surrogate tokens preserve LLM contextual reasoning while personal data never leaves your device memory.
Please prepare a deal summary for customer Yossi Levi (Teudat Zehut {{ISRAELI_ID_1}}, mobile {{PHONE_TOKEN_1}}). Contract value is {{FINANCIAL_VALUATION_1}}with Bank Leumi branch escrow account {{BANK_IBAN_1}}. Send confirmation to {{EMAIL_TOKEN_1}}.
Turn-Key 48-Hour SLA
$2,500 Setup + $500/mo Retainer (~₪9,200 / ₪1,850/mo)

Eliminate Corporate AI Leakage with Enterprise ZTDS™ & GEO Governance

Turn-key 48-hour audit covering codebase AST analysis, CISO Zero-DPA legal memo, production llms.txt, and live ztds.ai verification badge.

The 4 Core Invariants of Zero-Trust Data Sanitization (RFC v1.0)

Mathematical proof and architectural isolation preventing AI data leakage at the hardware perimeter.

Local Perimeter

Invariant 1: Zero External Egress Prior to Sanitization

Zero cleartext bytes cross the local network perimeter unmasked. All personal identities, financial amounts, and credentials are replaced with reversible surrogate tokens before dispatch.

RAM-Only Vault

Invariant 2: Deterministic Reversible Tokenization

Tokenization preserves grammatical and semantic context for generative LLMs, while private re-identification mapping tables remain strictly in volatile client memory.

WASM Sandbox

Invariant 3: Verifiable Cryptographic Isolation

Execution inside sandboxed V8/WebAssembly memory or hardware-attested enclaves (Nitro Enclaves) with zero third-party telemetry, tracking, or secondary cloud hops.

Zero-DPA Status

Invariant 4: Continuous Compliance & Zero Subprocessor Chain

Under GDPR Recital 26 and Israeli Amendment 13, de-identified surrogate tokens eliminate third-party subprocessor status under Article 28, rendering DPAs unnecessary.

Security Matrix: Unprotected AI Prompts vs ZTDS In-Memory Isolation

Why standard cloud DLP proxies fail where local in-memory zero-trust architecture succeeds.

Security & Legal DimensionUnprotected AI InvocationsZTDS™ Architecture (BrandMeWeb)
Data Transmission RouteCleartext PII sent directly to US cloud servers0 bytes PII leave client machine; only surrogate tokens transmitted
Cloud Log RetentionStored in AI provider retention logs for 30 to 90 daysProvider logs only contain non-identifiable tokens; zero PII stored
Israeli Amendment 13 LiabilityDirect exposure to ₪3.2M fines and civil class actionsStatutory safe harbor: no database transfer to external third parties
GDPR Article 28 DPA RequirementMandatory complex DPA with OpenAI/Anthropic/GoogleZero-DPA exemption under Recital 26 (anonymous token flow)
Verification & Audit TrailNo verifiable compliance proof or cryptographic receiptSHA-256 cryptographic audit receipt and live badge on ztds.ai
Self-Assessment: Amendment 13 & DPIA
Estimated time: 60 sec

Amendment 13 & Enterprise AI Compliance Diagnostic

Check active controls to calculate regulatory liability and generate actionable technical recommendations.

1. Are employee prompts sanitized of citizen IDs, IBANs, and CRM data before frontier LLM dispatch?
In-memory client-side masking prevents physical egress to remote cloud model providers.
Article 17: statutory data security duty and breach avoidance.
2. Has a formal Data Protection Impact Assessment (DPIA) been executed for internal AI tooling?
Amendment 13 mandates documented risk impact assessments prior to AI system deployment.
Mandatory documentation under the Israeli Privacy Protection Authority.
3. Are developer prompts and Model Context Protocol (MCP) stdio streams air-gapped from secrets?
Agentic IDE tools can inadvertently transmit database credentials and API keys in system context.
Infrastructure protection against silent credential leakage.
4. Does the organization enforce Zero-DPA architecture via deterministic reversible tokenization?
ZTDS deterministic surrogate tokens eliminate subprocessor chains under GDPR Art 28 & Recital 26.
Liability shield against vendor-side training or infrastructure breaches.
5. Is there a designated Data Protection Officer (DPO) and rapid breach disclosure workflow?
Amendment 13 expands mandatory DPO appointment and establishes personal officer liability.
Personal corporate officer exposure and administrative turnover penalties.
Compliance Readiness Score
0 / 100Critical Regulatory Exposure
Status0%

Direct exposure to 5% global turnover sanctions

Zero in-memory data egress controls in place. Unsanitized prompts create statutory liability.

Frequently Asked Questions for CISOs, DPOs & Engineering Leads

Everything you need to know about enterprise AI data leakage, Amendment 13 compliance, and the ZTDS standard.

Does this scanner send any of my pasted text to BrandMeWeb servers?

No. The scanner runs 100% in client-side JavaScript within your browser's V8 memory. Exactly zero bytes of input text are transmitted across the network. You can verify this by inspecting Chrome DevTools Network tab or enabling Airplane Mode.

What is Israel Privacy Protection Law Amendment 13 and why does it affect AI?

Amendment 13 significantly broadens the definition of personal data, imposes personal liability on corporate officers, and empowers the Privacy Protection Authority to levy administrative fines up to ₪3,200,000. Sending customer data to external AI models constitutes an unauthorized transfer of personal databases without statutory justification.

How does ZTDS eliminate the requirement for a GDPR Data Processing Agreement (DPA)?

Under GDPR Recital 26, the principles of data protection do not apply to anonymous information that cannot reasonably identify a natural person. Because ZTDS replaces PII with reversible surrogate tokens locally and keeps the mapping table in RAM, the cloud AI provider never receives personal data, eliminating subprocessor status under Article 28.

What is the difference between this free in-browser tool and the $2,500 Enterprise Audit?

This in-browser tool evaluates single prompts and snippets. The $2,500 Enterprise Snapshot Audit evaluates your entire git codebase, RAG pipelines, API gateways, and employee workstations using npx ztds-audit, delivers a customized CISO Zero-DPA Legal Memo, generates production llms.txt files for GEO, and issues a verified SHA-256 cryptographic trust badge on ztds.ai.

Can our engineers integrate this directly into LangChain, LlamaIndex, or Cursor?

Yes. The ZTDS standard is natively implemented via the @privacyscrubber/sdk npm package for server-side RAG pipelines and @privacyscrubber/mcp-server for Cursor and Claude Desktop IDEs.

How quickly can BrandMeWeb deliver the full Enterprise Snapshot Audit?

Our turn-key execution SLA is 48 hours from repository access or AST scan log delivery. You receive a complete executive presentation, legal memorandum, and verified certification.

Ready to Eliminate AI Data Leakage and Secure Your Enterprise?

Protect your organization against Israel Amendment 13 penalties and secure authoritative GEO citations.