Skip to main content

esys-watch

Catch secrets and PII before you paste them into ChatGPT, Cursor, Copilot, or any AI tool — locally, with zero setup, zero account, zero data ever leaving your machine. $ echo "my key is AKIAIQK2919AHEJ8CX9J" | esys-watch ESYS WATCH

1 finding(s):

[secret] aws_access_key -> AK****************9J (pos 10-30)

Decisão: BLOCK

NÃO cola isto num prompt de IA contém dados sensíveis que não deviam sair da tua máquina.

Why

Every team using AI is leaking data through it and most don't know it yet — a stack trace with an AWS key in it, a support ticket with a customer's card number, a log line with a database password. esys-watch is the first line of defense: a local check, before anything gets pasted anywhere.

What it catches

  • Secrets: AWS/GCP/Azure keys, GitHub tokens, JWTs, OAuth tokens (Stripe, SendGrid, Slack, Twilio), DB connection strings, SSH keys — including base64-encoded and split/obfuscated variants
  • PII, across 4 regions: emails, phones, credit cards, US SSN, Angola national ID, Brazil CPF/CNPJ (checksum-validated), South Africa national ID (checksum-validated), Nigeria NIN, EU IBAN (checksum-validated)

Validated against a 320-case labeled dataset: 100% recall, 0% false positives. See the root README.md for the full methodology. Testing this for the founder? See TESTING.md for what to actually try and how to report what you find.

Install

git clone https://github.com/osvaldoC-Dev/ESYS.git
cd ESYS/detector
pip install -e .

No external dependencies — pure Python standard library. Works offline.

Use

esys-watch path/to/file.txt          # scan a file
cat something.log | esys-watch       # or pipe anything into it
echo "some text" | esys-watch

Exit codes (useful for scripting / git hooks / CI): 0 = clean, 1 = blocked (secret or high-sensitivity PII found), 2 = redactable PII found (a safe version is printed for you to copy).

Review past blocks

Every block gets logged locally (never sent anywhere). If you ever need to check what got flagged, or decide something was a false positive:

esys-review              # list pending blocks
esys-review show <id>    # see the full original content
esys-review approve <id> # mark as reviewed / false positive

What this is not (yet)

This is v0 — it proves the core detection works, reused from the same engine that powers the full ESYS gateway. It doesn't yet watch your clipboard automatically, and it's not published to PyPI (you install from source). Both are on the roadmap once this gets real usage.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

esys_watch-0.1.0.tar.gz (19.0 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

esys_watch-0.1.0-py3-none-any.whl (20.9 kB view details)

Uploaded Python 3

File details

Details for the file esys_watch-0.1.0.tar.gz.

File metadata

  • Download URL: esys_watch-0.1.0.tar.gz
  • Upload date:
  • Size: 19.0 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.0

File hashes

Hashes for esys_watch-0.1.0.tar.gz
Algorithm Hash digest
SHA256 a4a52e64fb777c4b072444f93351c81a5dd09b38fe47d7b023ba1e163163edba
MD5 d156f27922b3f840a5d190b0b324572f
BLAKE2b-256 6096921e416df576c27ac1e6a51d285fcfb3deeb72d4ba80841ae9d44edd16f6

See more details on using hashes here.

File details

Details for the file esys_watch-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: esys_watch-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 20.9 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? No
  • Uploaded via: twine/7.0.0 CPython/3.14.0

File hashes

Hashes for esys_watch-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 959eec9406d4e69e385e1e12ff0de7bee994c91c4b15aed7a5d2ff52442569ec
MD5 2b31ebb88b236b7baadc3a5314300088
BLAKE2b-256 f3fceae2daae809f16f8f01c4e0297a18e1e8b26d6bca9c43e757f818e8890e6

See more details on using hashes here.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page