RAGLeakGuard
Scan your AI's vector database for exposed sensitive data — before it becomes a breach you can't delete.
RAGLeakGuard is a CLI that connects to your vector store (Chroma today; more soon), reads what's stored, detects sensitive data (PII, health, financial), and writes a risk-scored report. No changes to your app — point it at the store and scan.
What it is: a data-inventory & compliance scanner — it answers the question a compliance officer actually asks: "what regulated data is sitting in our vector store, and can we prove we can delete it?" Read-only; safe to run against production.
What it isn't: a red-team tool. It doesn't fire prompt-injection or jailbreak attacks — it audits the data at rest, not how the model responds under attack.
🚧 Early development — building in public. Not production-ready yet.
Why this matters
RAG systems embed your private data into vector databases. That data can be reconstructed from the vectors (embedding inversion), is hard to delete (backups, replicas, caches, fine-tuned models), and usually isn't inventoried. RAGLeakGuard finds it.
Install (from source)
git clone https://github.com/Agenvana/RAGLeakGuard.git
cd RAGLeakGuard
python3 -m venv .venv
source .venv/bin/activate
pip install --upgrade pip # fresh venvs ship an old pip; the editable install needs a newer one
pip install -e ".[chroma,detect,dev]"
python -m spacy download en_core_web_sm
Python 3.9 note: dependencies are pinned (
spaCy<3.8,numpy<2) so prebuilt wheels are used — no source build needed.
Quickstart (≈2 minutes)
# 1. Create a test vector store full of FAKE sensitive records
python scripts/seed_synthetic.py # -> ./sample_store (100 fake clinic records)
# 2. Scan it — global + US recognisers are on by default
ragleakguard scan --source chroma --path ./sample_store --report report.md
# 3. The fixture is Australian, so add the AU locale pack for full coverage
ragleakguard scan --source chroma --path ./sample_store --locale au --report report.md
# 4. Open report.md (summary, findings by type + severity, risk level, remediation)
Detection
- Default: global + US recognisers — SSN, bank number, driver license, credit card, email, phone, names, locations, dates, IP, crypto…
- Locale packs (
--locale):au(Medicare / TFN / ABN),uk,sg,in— opt-in country IDs.
Roadmap
See ROADMAP.md — next up includes a custom AU phone recogniser, more connectors (Pinecone, pgvector), and the Fix/Prove layers.
License
Apache-2.0
Metadata
Release files for ragleakguard 0.1.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| ragleakguard-0.1.0.tar.gz | 17.6 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| ragleakguard-0.1.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.2 kB
Release files / ragleakguard-0.1.0.tar.gz
| Download URL | ragleakguard-0.1.0.tar.gz |
|---|---|
| Size | 17.6 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
a2dadb025fe65e7e2582b74356dc773399dda524488e27d872418f5b6e225de3
|
|
BLAKE2b-256 checksum How to use checksums |
5073a4757d9532850a67752f9562c2af7bce4bdfc14f34ab2900a2e4bf5d23bb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|
Release files / ragleakguard-0.1.0-py3-none-any.whl
| Download URL | ragleakguard-0.1.0-py3-none-any.whl |
|---|---|
| Size | 14.6 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
0ba250dd2a70b9666b02dbc6b18bb2d735dfd10ab5f489498b1be4699c9c2d2a
|
|
BLAKE2b-256 checksum How to use checksums |
3afd729fba78de1447212295c791cfe2f4cf6d3a3737edc520c84a6b4a8dba65
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
No |
| Uploaded via |
twine/6.2.0 CPython/3.9.6
|