Skip to main content

ogentic-shield

Regulatory sensitivity detection for legal privilege, clinical PHI, and financial MNPI.

PyPI Python License

ogentic-shield classifies whether a piece of text — or a whole document — contains content that shouldn't leave a regulated boundary. Attorney-client privilege. HIPAA-protected clinical content. Material non-public financial information. The long tail of PII. It returns a structured AnalysisResult (score, category groups, detected entities, suggested routing) and can redact masked tokens back into plaintext after a round-trip through an external LLM.

Built for the legal, clinical, and financial AI workflows where the wrong default is "ship the prompt to OpenAI and hope."

Why this exists

On February 10, 2026, US v. Heppner (S.D.N.Y.) established that sending privileged content through a third-party AI tool can constitute waiver. The guardrail every regulated org now needs — classify before you call — didn't exist as an OSS primitive. Shield is that primitive.

Install

pip install ogentic-shield                # core (Layer 1 + 2)
pip install 'ogentic-shield[llm]'         # + Layer 3 (Ollama-backed disambiguation)
pip install 'ogentic-shield[mcp]'         # + MCP server (Claude Desktop / Goose / Cursor)
pip install 'ogentic-shield[server]'      # + FastAPI HTTP surface
pip install 'ogentic-shield[all]'         # everything

Layer 1 + 2 require the spaCy en_core_web_lg model: python -m spacy download en_core_web_lg

30-second example

from ogentic_shield import Shield

shield = Shield(profiles=["shield-legal"])

# Text-level analysis
result = shield.analyze(
    "Privileged attorney-client memo: do not disclose to opposing counsel."
)
print(result.score)                  # 0..100 sensitivity score
print(result.category_groups_found)  # {CategoryGroup.PRIVILEGE}
print(result.routing_suggestion)     # "local_only"

# Document-level redaction (v0.4.0+)
redacted = shield.redact_document("memo.txt")
print(redacted.redacted_text)        # entities replaced with deterministic tokens
print(redacted.mapping.tokens)       # token -> original, for round-trip after LLM

The full API — profiles, layers, calibration, redaction, async, MCP, HTTP server, document analysis — is documented on GitHub. See the README on GitHub for the complete reference.

What's in the box

  • Three-layer detection — fast regex (Layer 1) → spaCy NER (Layer 2) → optional local-LLM disambiguation (Layer 3). Each layer adds precision without surrendering recall.
  • Profile-drivenshield-legal, shield-finance, shield-healthcare, custom. Profiles define which categories to flag and at what threshold.
  • Documents APIShield.analyze_document() and Shield.redact_document() handle .txt / .md / .log today; PDF / DOCX / XLSX / EML / MSG / HTML on the roadmap.
  • Token-preserving redactionShield.redact() and the new Shield.redact_document() substitute entities with deterministic [Label_abc123] tokens. Pair with unredact_text() to restore originals after a round-trip through OpenAI / Anthropic / Ollama.
  • MCP serverogentic-shield --mcp exposes Shield as an MCP tool surface (shield.analyze, shield.profiles, shield.calibration). Claude Desktop, Goose, and Cursor all work out of the box.
  • Privacy-first — runs entirely in-process. No telemetry, no Ogentic-hosted infra. The audit row Shield emits is shape-only (hashes, scores, category names) — never the prompt text itself.

Part of a stack

ogentic-shield is the classification leg of the OgenticAI privacy-routing stack:

ogentic-shield  →  ogentic-router  →  ogentic-audit
   (classify)        (route)            (forensic log)

Together they form the open-source foundation for Sotto, OgenticAI's commercial product for regulated professionals.

Links

Release files for ogentic-shield 0.6.1

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for ogentic-shield 0.6.1
File Size Uploaded
ogentic_shield-0.6.1.tar.gz 332.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for ogentic-shield 0.6.1
File Interpreter ABI Platform
ogentic_shield-0.6.1-py3-none-any.whl Python 3 none any Details

Total release size: 426.6 kB

Release files / ogentic_shield-0.6.1.tar.gz

Download URL ogentic_shield-0.6.1.tar.gz
Size 332.9 kB
Tags Source
SHA-256 checksum
How to use checksums
5d29334219dd13ed55c4992357cbadebd724fc5cf3f7eb5e72cce5eae0c7f40c
BLAKE2b-256 checksum
How to use checksums
2b7ee609eecb7712ac4c919409d12b000934fa9d14fa718981248b0d33a10b19
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release files / ogentic_shield-0.6.1-py3-none-any.whl

Download URL ogentic_shield-0.6.1-py3-none-any.whl
Size 93.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
3347611eaae56a70f0fc600eff77fa2d3cfc49e512b22ebb916751e123e56f52
BLAKE2b-256 checksum
How to use checksums
7ae3c093321f4299c1597e541ca60d701badf66db6f33238ab80348f8b4c01b8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/6.1.0 CPython/3.13.14

Release history Release notifications | RSS feed

This release

0.6.1 This release

2 release files

0.6.0

2 release files

0.5.0

2 release files

0.4.0

2 release files

0.3.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page