Skip to main content

🛡️ ScrubVault: Zero-Data-Leak AI Airgap & Reversible PII Masking Engine

License: Apache 2.0 Zero Dependencies Raptor Guard Certified GDPR Art. 32

Send sensitive data to Cloud LLMs (ChatGPT, Claude, Gemini) without ever leaking confidential PII.

ScrubVault is a lightweight, zero-dependency in-memory privacy proxy and Model Context Protocol (MCP) server. It intercept prompts, replaces personal identifiable information (emails, IBANs, IP addresses, credit cards, tax IDs) with deterministic local tokens ({{EMAIL_1}}, {{IBAN_1}}), and restores the original values when the AI responds.


🚀 The Architecture

                   +----------------------------------+
                   |  Your Prompt (Confidential PII)  |
                   +----------------------------------+
                                     │
                                     ▼
                      ┌─────────────────────────────┐
                      │    ScrubVault (Local RAM)   │
                      │  - Scans & Masks Sensitive  │
                      │  - Stores Mapping in Memory │
                      └─────────────────────────────┘
                                     │
                                     ▼ (Masked Prompt: "{{EMAIL_1}}, {{IBAN_1}}")
                      ┌─────────────────────────────┐
                      │    Public Cloud LLM API     │
                      │   (OpenAI / Anthropic / ...) │
                      │   *Zero PII is transmitted* │
                      └─────────────────────────────┘
                                     │
                                     ▼ (Response with tokens)
                      ┌─────────────────────────────┐
                      │    ScrubVault (Local RAM)   │
                      │  - Deterministic Unmasking  │
                      └─────────────────────────────┘
                                     │
                                     ▼
                   +----------------------------------+
                   |  End-User Result (Restored PII)  |
                   +----------------------------------+

⚡ Quickstart

1. Python SDK (Zero Dependencies)

from src.core.vault import ScrubVault

vault = ScrubVault()

# 1. Mask sensitive input
input_text = "Order for client Max, email: max@corp.de, IBAN: DE89370400440532013000"
result = vault.mask(input_text)

print(result.masked_text)
# Output: "Order for client Max, email: {{EMAIL_1}}, IBAN: {{IBAN_1}}"

# 2. Transmit result.masked_text to your LLM of choice...
ai_response = "Received confirmation for {{EMAIL_1}} on account {{IBAN_1}}."

# 3. Unmask locally
clean_response = vault.unmask(ai_response, result.token_map)
print(clean_response)
# Output: "Received confirmation for max@corp.de on account DE89370400440532013000."

2. Standalone CLI

# Calculate GDPR Art. 32 Risk Score
python -m src.cli.main audit "Contract with Herr Schmidt, IBAN: DE89370400440532013000"

# Mask a dataset file directly
python -m src.cli.main scrub-dataset input.json output_clean.json

🤖 Model Context Protocol (MCP) Integration

ScrubVault includes a native stdio Model Context Protocol (MCP) server. Add it to your claude_desktop_config.json or Antigravity configuration:

{
  "mcpServers": {
    "scrub_vault": {
      "command": "python",
      "args": ["-m", "src.mcp.server"],
      "cwd": "/path/to/scrub_vault"
    }
  }
}

Available MCP Tools:

  • scrub_mask_text: Masks PII in input text and returns a reversible token map.
  • scrub_unmask_text: Replaces tokens with original values.
  • scrub_audit_risk: Calculates risk scores and detection breakdowns.
  • scrub_anonymize_json: Recursively scrubs JSON structures.

🛡️ Security & Clean Code Standard

  • Pure Python Standard Library: Zero third-party dependencies (re, json, sys, typing).
  • In-Memory Vault: Token maps live exclusively in volatile RAM and are never written to disk.
  • ReDoS Hardened: Regex patterns are strictly bounded against algorithmic complexity attacks.
  • Audit Passed: Tested and verified by Raptor Guard SAST (0 Critical, 0 High, 0 Medium findings).

📄 License

Apache License 2.0. Open-source research and engineering by the Diamantenschmiede.

Release files for scrub-vault 1.0.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for scrub-vault 1.0.0
File Size Uploaded
scrub_vault-1.0.0.tar.gz 11.4 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for scrub-vault 1.0.0
File Interpreter ABI Platform
scrub_vault-1.0.0-py3-none-any.whl Python 3 none any Details

Total release size: 21.7 kB

Release files / scrub_vault-1.0.0.tar.gz

Download URL scrub_vault-1.0.0.tar.gz
Size 11.4 kB
Tags Source
SHA-256 checksum
How to use checksums
1ba27b52a05270f78879855e3d644ac26a74200ba02fd2049eb6521e030bb58c
BLAKE2b-256 checksum
How to use checksums
13c303e985b48d554a6e6b4c87e9a01b8df9c4057940d8b0019844d2c1537458
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release files / scrub_vault-1.0.0-py3-none-any.whl

Download URL scrub_vault-1.0.0-py3-none-any.whl
Size 10.3 kB
Tags Python 3
SHA-256 checksum
How to use checksums
b9342c4e424073f1fb2c57bd22e6dcf035ead20ef615d1933a4d9ebc795ba04b
BLAKE2b-256 checksum
How to use checksums
0a96ecf404f37116c8807fe70d519bef3aa9b97d9bd61a72e3233ab7017e4f41
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via twine/7.0.0 CPython/3.11.15

Release history Release notifications | RSS feed

This release

1.0.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page