io.github.moxno/privacyscrubber-mcp
Zero-Trust PII & secrets sanitizer. Locally scrubs data in-memory before sending context to LLMs.
Open source Open in the app JSON README (API)
About
Zero-Trust PII & secrets sanitizer. Locally scrubs data in-memory before sending context to LLMs.
Details
- Kind
- MCP servers
- Topic
- AI, RAG & memory
- Publisher
- moxno
- Origin
- official
- Category
- ferramentas
- Transport
- local
- Version
- 1.0.2
- Stars
- 2
- Last push
- 2026-08-30T15:22:13Z
- Repository state
- ativo
- Language
- JavaScript
- License
- MIT
- Added
- 2026-08-29 04:00:51
- Updated
- 2026-08-29 04:00:51
- Origin id
io.github.moxno/privacyscrubber-mcp
README
# @privacyscrubber/mcp-server
[](https://www.npmjs.com/package/@privacyscrubber/mcp-server)
[](https://www.npmjs.com/package/@privacyscrubber/mcp-server)
[](https://opensource.org/licenses/MIT)
[](https://zenodo.org/records/22058770)
[](https://osf.io/5byjf/)
[](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7335581)
[](https://smithery.ai/servers/privacyscrubber/pii-masking-mcp)
[](https://cursor.directory/plugins/privacyscrubber-mcp)
[](https://glama.ai/mcp/servers/moxno/privacyscrubber-mcp)
[](https://privacyscrubber.com)
[](https://privacyscrubber.com)
**CISO-Approved Zero-Trust PII & Secrets Redaction MCP Server for Cursor, Windsurf, and Claude Desktop.**
Locally scrubs PII, secrets, credentials, and custom regex rules from files and text contexts before they reach remote LLM providers to prevent API leaks and ensure HIPAA/SOC 2 compliance at the developer endpoint.
---
## π Zero-Trust Data Flow
All sensitive parameters, identifiers, and variables are intercepted locally inside your machine's RAM. They are replaced by tokens (e.g. `[EMAIL_1]`) before being sent to the AI. Once the AI responds, the tokens are safely swapped back to original values in your local context.
```text
[Raw Input / Files] ββ> [MCP sanitize_text] ββ> [Masked Tokens] ββ> [LLM API]
β β
(In-Memory Map) (Result)
β β
[Original Output] <βββ [MCP reveal_text] <ββββββββββββββββββββββββββββββ
```
---
## π Installation
### 1. Install via Smithery
To automatically configure and run with your preferred client, install using Smithery:
```bash
npx -y @smithery/cli install @privacyscrubber/mcp-server --write-to-clients
```
### 2. Instant Run with NPX
Run the server directly without local installation:
```bash
npx -y @privacyscrubber/mcp-server
```
---
## βοΈ Client Integrations
### Claude Desktop
Add this to your Claude Desktop config file:
* **macOS:** `~/Library/Application Support/Claude/claude_desktop_config.json`
* **Windows:** `%APPDATA%\Claude\claude_desktop_config.json`
```json
{
"mcpServers": {
"privacyscrubber": {
"command": "npx",
"args": ["-y", "@privacyscrubber/mcp-server"],
"env": {
"PRIVACYSCRUBBER_KEY": "YOUR_OPTIONAL_PRO_LICENSE_KEY"
}
}
}
}
```
### Cursor / Windsurf
1. Navigate to Settings -> Features -> MCP.
2. Add new MCP server:
* **Name:** `privacyscrubber`
* **Type:** `command`
* **Command:** `npx -y @privacyscrubber/mcp-server`
3. Optional: Set `PRIVACYSCRUBBER_KEY` as an environment variable in your system shell.
---
## π οΈ Provided Tools & JSON-RPC Specifications
### 1. `sanitize_text`
Redacts PII, secrets, API keys, and credentials from a text block and populates the volatile local replacement mapping.
* **Arguments:**
* `text` (string, required): The raw content or logs to sanitize.
* `profile` (string, optional): Gated industry detection profile (e.g., 'General', 'Dev', 'Medical', 'Legal', 'Compliance'). Defaults to 'General'.
* **JSON-RPC Call Example:**
```json
{
"method": "tools/call",
"params": {
"name": "sanitize_text",
"arguments": {
"text": "Contact me at dev-key-1234 or jane.doe@company.com",
"profile": "General"
}
}
}
```
* **Response Example:**
```json
{
"content": [
{
"type": "text",
"text": "Contact me at [SECRET_1] or [EMAIL_1]"
}
]
}
```
### 2. `reveal_text`
Detokenizes the AI response back to the original values locally.
* **Arguments:**
* `text` (string, required): The response from the LLM containing tokenized placeholders.
* **JSON-RPC Call Example:**
```json
{
"method": "tools/call",
"params": {
"name": "reveal_text",
"arguments": {
"text": "Please reach out to [EMAIL_1] regarding the update."
}
}
}
```
* **Response Example:**
```json
{
"content": [
{
"type": "text",
"text": "Please reach out to jane.doe@company.com regarding the update."
}
]
}
```
### 3. `sanitize_file`
Reads a local file, extracts text, sanitizes it, and returns the redacted template for LLM analysis.
* **Supported Formats:** Plain text (source code, logs, CSV, JSON, markdown) and Microsoft Word (`.docx`) documents.
* **Arguments:**
* `filePath` (string, required): Absolute file path to read and sanitize.
* `profile` (string, optional): The industry detection profile.
---
## π Browser Extension & Web Client
Looking for real-time protection directly inside your web browser?
* **Chrome Extension:** Get the [PrivacyScrubber Chrome Extension](https://chromewebstore.google.com/detail/privacyscrubber-%E2%80%94-pii-red/pimoejgefeilajmmbpghifdmhdlkgjol) to sanitize prompts directly inside ChatGPT, Claude, and Gemini in real-time.
* **Web Sandbox:** Use the zero-server browser sanitization tools at [PrivacyScrubber Homepage](https://privacyscrubber.com/?utm_source=npm&utm_medium=readme&utm_campaign=mcp_server).
## π License & Commercial Upgrade
By default, the server runs under the **Free Tier** (restricted to 50,000 characters per request and the basic `General` PII profile). To unlock advanced engineering, medical, legal, and financial PII profiles, as well as team-wide custom rules, you can purchase a commercial license.
### Feature Comparison
| Feature | Free Tier | PRO Tier | TEAMS Tier |
| :--- | :--- | :--- | :--- |
| **Volatile Tokenization** | β
Yes | β
Yes | β
Yes |
| **Standard PII Masking** | β
Yes | β
Yes | β
Yes |
| **Max Character Length** | 50,000 chars | βΎοΈ Unlimited | βΎοΈ Unlimited |
| **Industry Profiles** | General Only | 22+ Profiles | 22+ Profiles |
| **Custom Regex Rules** | β Locked | βΎοΈ Unlimited | βΎοΈ Unlimited |
| **Team Rules Sync (GPO)** | β No | β No | β
Yes (Shared Link) |
| **Licensing Cost** | $0 | **$110 Lifetime** | **$99/mo Flat Rate** |
π **[Acquire a PRO / TEAMS License Key at privacyscrubber.com/pricing](https://privacyscrubber.com/pricing?utm_source=npm&utm_medium=readme&utm_campaign=mcp_server)**
---
### 4. `check_status`
Returns a visual dashboard showing your current tier, session request count, active profiles, and upgrade instructions. Use it at any time to check your license status or get setup help.
* **Arguments:** _(none required)_
* **JSON-RPC Call Example:**
```json
{
"method": "tools/call",
"params": { "name": "check_status", "arguments": {} }
}
```
* **Response Example (Free Tier):**
```
ββββββββββββββββββββββββββββββββββββββββββββββββββββ
β PrivacyScrubber MCP Server v1.6.6 β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ£
β π Tier: FREE β
β π Session requests: 5 β
β π Input size limit: 50,000 characters per requestβ
β βββββββββββββββββββββββββββββββββββββββββββββββββββ£
β π·οΈ Profiles: General only β PRO unlocks 22 more β
β π Custom rules: π Locked β requires PRO β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ£
β π³ Upgrade to PRO β $110 Lifetime β
β https://privacyscrubber.com/pricing?utm_source=npm&utm_medium=readme&utm_campaign=mcp_server β
β βββββββββββββββββββββββββββββββββββββββββββββββββββ£
β After purchase, add your key to MCP config: β
β "PRIVACYSCRUBBER_KEY": "<your-key-here>" β
β Full setup guide: β
β https://privacyscrubber.com/features/mcp/?utm_source=npm&utm_medium=readme&utm_campaign=mcp_server β
ββββββββββββββββββββββββββββββββββββββββββββββββββββ
```
---
## π After Purchase: Activate PRO in Your MCP Client
After purchasing a PRO license at [privacyscrubber.com/pricing](https://privacyscrubber.com/pricing?utm_source=npm&utm_medium=readme&utm_campaign=mcp_server), you will receive a license key. Add it to your MCP client config as an environment variable: `PRIVACYSCRUBBER_KEY`.
### Claude Desktop
Edit `~/Library/Application Support/Claude/claude_desktop_config.json` (macOS) or `%APPDATA%\Claude\claude_desktop_config.json` (Windows):
```json
{
"mcpServers": {
"privacyscrubber": {
"command": "npx",
"args": ["-y", "@privacyscrubber/mcp-server"],
"env": {
"PRIVACYSCRUBBER_KEY": "YOUR_LICENSE_KEY_HERE"
}
}
}
}
```
Restart Claude Desktop after saving.
### Cursor
1. Go to **Settings β Features β MCP Servers**.
2. Find `privacyscrubber` and click **Edit**.
3. Add the environment variable: `PRIVACYSCRUBBER_KEY=YOUR_LICENSE_KEY_HERE`.
4. Restart Cursor.
Alternatively, export it system-wide so all tools pick it up:
```bash
# macOS / Linux β add to ~/.zshrc or ~/.bashrc
export PRIVACYSCRUBBER_KEY="YOUR_LICENSE_KEY_HERE"
```
### Windsurf
Edit `~/.codeium/windsurf/mcp_config.json`:
```json
{
"mcpServers": {
"privacyscrubber": {
"command": "npx",
"args": ["-y", "@privacyscrubber/mcp-server"],
"env": {
"PRIVACYSCRUBBER_KEY": "YOUR_LICENSE_KEY_HERE"
}
}
}
}
```
### Verify Activation
After adding the key, ask your AI agent to call `check_status`:
```
Use the check_status tool from PrivacyScrubber MCP
```
The dashboard should show **Tier: PRO** and all profiles unlocked.
---
## π Academic Foundations & Regulatory Verification
PrivacyScrubber and the Zero-Trust Data Sanitization (ZTDS) protocol are backed by published scientific, clinical, and legal treatises:
| Repository / Archive | DOI / Identifier | Focus Area | Regulatory & Compliance Scope |
|---|---|---|---|
| **Zenodo / CERN** | [`10.5281/zenodo.22058770`](https://zenodo.org/records/22058770) | Zero-Trust Data Sanitization (ZTDS) Protocol Foundation | Cross-Border AI Privacy, ISO 27001 A.8.11 |
| **OSF (Center for Open Science)** | [`10.17605/OSF.IO/5BYJF`](https://osf.io/5byjf/) | Empirical Latency Benchmark & Memory Profiling (<2ms RAM) | Performance vs Cloud DLP Proxies |
| **SSRN / Elsevier** | [`SSRN ID: 7335581`](https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7335581) | Enterprise Generative AI Governance | EU AI Act, UK GDPR, US State Privacy |
| **medRxiv (Cold Spring Harbor)** | [`MEDRXIV/2026/361661`](https://submit.medrxiv.org/) | Multi-Center Clinical Trial De-Identification | HIPAA Safe Harbor Section 164.514(b) |
| **Law Archive / OSF** | [`LawArchive ID: 4wc86`](https://osf.io/preprints/lawarchive/4wc86/) | Preserving Attorney-Client Privilege in AI Workflows | ABA Model Rules & Legal Ethics |
### Citing PrivacyScrubber in Research & Audits
```bibtex
@software{sibiryakov2026privacyscrubber,
author = {Sibiryakov, Ilya},
title = {PrivacyScrubber: Zero-Trust Data Sanitization (ZTDS) Engine & MCP Server},
year = {2026},
publisher = {Zenodo},
doi = {10.5281/zenodo.22058770},
url = {https://github.com/moxno/privacyscrubber-mcp}
}
```
---
## π License
MIT Β© [Ilya Sibiryakov](https://privacyscrubber.com) (BrandMeWeb)