aicomply (Python)
Inline PII, credential, and regulated-data classifier for AI agent I/O. Catch sensitive content before your agent forwards it to a hosted LLM.
Dual-layer by design: a deterministic regex layer (PII, credentials, controlled markings) that runs always, plus an optional semantic Guard layer when a local nanomind-daemon is reachable. The regex layer sees through common evasions — Unicode homoglyphs (NFKC), zero-width characters, intra-token whitespace, and bounded Base64 / URL-encoded payloads — by normalizing the input before matching.
This is the Python port of @opena2a/aicomply.
It reproduces the TypeScript detection baseline against the same shared corpus
(bench/corpus), so verdicts agree across languages.
Install
pip install aicomply
Try it (CLI)
No integration code required — point it at a file or pipe content in:
echo "My SSN is 123-45-6789" | aicomply scan
aicomply scan ./support-ticket.txt
cat transcript.log | aicomply scan --json
Exit codes make it a drop-in CI gate: 0 CLEAN, 1 findings present, 2 usage error.
Library API
from aicomply import comply
result = comply("Customer SSN is 516-81-3086, card 5544939082323438.")
print(result.verdict) # "VIOLATION"
for v in result.violations:
print(v.type, v.value, v.confidence) # SSN 516...86 0.95 (value is masked)
comply() returns a ComplyResult with:
verdict—"CLEAN","VIOLATION", or"DENY"violations— each withtype, maskedvalue,confidence,classifier,view(which content view caught it), and best-effortoriginal_start/endoriginal_content/normalized_content/normalizations— an audit trail (omitted onDENY, where the input is treated as untrusted bytes).to_dict()— camelCase JSON wire-compatible with the npm package
Empty string short-circuits to CLEAN; comply() also accepts a bare string
(comply("text") is shorthand for comply(content="text")); other non-str
input raises TypeError.
Caution:
original_contentandnormalized_contenthold the raw input by design, so a flagged result carries the very PII or credentials it detected. Do not pass them to an audit log, trace, or error reporter unmasked. Logverdictand the masked findings instead, or redact the raw fields before persisting them.
Guard an agent's output
Drop one decorator above any function that emits text bound for an LLM or a user:
from aicomply.integrations import guard_output, ComplianceViolation
@guard_output() # raise on any PII/credential egress
def answer(user_msg: str) -> str:
return call_llm(user_msg)
@guard_output(on_violation="redact") # or mask findings in place
def answer_redacted(user_msg: str) -> str:
return call_llm(user_msg)
guard_io() additionally scans string inputs on the way in.
LangChain
pip install 'aicomply[langchain]'
from langchain_openai import ChatOpenAI
from aicomply.integrations.langchain import AIComplyCallbackHandler
llm = ChatOpenAI(callbacks=[AIComplyCallbackHandler()])
llm.invoke("Summarize this support ticket: ...") # raises if the LLM emits PII
Semantic Guard layer (preview, not production-ready)
The regex layer is deterministic, always on, and is the production surface. The
optional Guard layer targets prompt-injection / exfiltration patterns that regex
cannot see, but the current model (nanomind-security-classifier tme-v0.5.0)
over-flags benign text: measured 2026-06-25, 7 of 10 ordinary-benign sentences were
flagged as an attack class at greater than 0.99 confidence at the default 0.8
threshold. Treat it as a preview, not for production gating, until a recalibrated
model ships.
The daemon ships on npm, not PyPI (npm i -g @nanomind/daemon && nanomind-daemon start); it is a local HTTP server this Python client calls. When it is reachable on
127.0.0.1:47200 the dual-layer classifier consults it and merges the verdict
(highest severity wins). Its absence never fails a request: the classifier falls
back to regex-only.
Detection classes
SSN, PAN (Luhn + IIN), credentials (AWS keys, GitHub tokens, Bearer tokens,
api_key= patterns), CUI / controlled markings, IBAN (mod-97), passport
numbers, MRN, NPI (Luhn with 80840 prefix).
Scope
This port covers the deterministic detection layer (regex + normalization + dual-layer merge + verdict) plus the daemon Guard client. The TypeScript package's Registry-L2, ARP-signature, policy-pack, and session-vault features are not yet ported.
License
Apache-2.0.
Metadata
Release files for aicomply 0.3.1
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| aicomply-0.3.1.tar.gz | 27.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| aicomply-0.3.1-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 64.1 kB
Release files / aicomply-0.3.1.tar.gz
| Download URL | aicomply-0.3.1.tar.gz |
|---|---|
| Size | 27.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
e3f83be5e28145765f0e423c686f7d4bc8db761d6aeabb1b8598ece8ff399888
|
|
BLAKE2b-256 checksum How to use checksums |
8225721954a4a9459183513c11a409f5a078794f3c09bfe7a9fae7b49494aaba
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency logRelease files / aicomply-0.3.1-py3-none-any.whl
| Download URL | aicomply-0.3.1-py3-none-any.whl |
|---|---|
| Size | 36.2 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
b785f9fef667df51326da4069a84f7d618147c79efa3f7ceb574d6c7b58a1aac
|
|
BLAKE2b-256 checksum How to use checksums |
c263ad2377aa67e73a4a1fe6dc8e9ea64932eda8d58e33b5d729d25dfbc9815c
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.12
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Jun 26, 2026.
Transparency log