Skip to main content

Local DLP reverse proxy for LLM traffic

Project description

VeilLLM

A local DLP reverse proxy for LLM traffic. Mask PII, API keys, and secrets before they leave your machine — restore them on the way back.

banner

https://github.com/user-attachments/assets/dec6fb5d-64d2-4731-a4b3-40260ff8f461

Quickstart

# Install
pip install veil-llm

# Start the gateway
veil-llm serve --port 4000

On first run, VeilLLM creates a ./config.toml with a random salt and default settings. The spaCy model (en_core_web_lg, ~500MB) downloads automatically if missing.

CLI reference

veil-llm serve [options]
veil-llm config            # show resolved settings
veil-llm --help            # full help
Flag Env var Default Description
--port GATEWAY_PORT 4000 Listen port
--host 127.0.0.1 Listen host
--upstream-url GATEWAY_UPSTREAM_URL https://openrouter.ai/api/v1 Upstream API base URL
--model-name GATEWAY_MODEL_NAME en_core_web_lg spaCy model for PII detection
--debug GATEWAY_DEBUG=1 false Log placeholder→original map to stderr (⚠️ leaks secrets)
--high-entropy GATEWAY_HIGH_ENTROPY=1 false Enable high-entropy string detection
--entropy-threshold GATEWAY_ENTROPY_THRESHOLD 4.5 Shannon entropy threshold for high-entropy detection
--enabled-entities GATEWAY_ENABLED_ENTITIES PERSON,EMAIL_ADDRESS,… Comma-separated list of PII entity types to detect

Priority: config.toml defaults < config.toml values < env vars < CLI flags.

Available spaCy models

Model Size Vectors Accuracy Best for
en_core_web_sm 12 MB Low Minimal footprint, quick tests
en_core_web_md 40 MB Medium Balanced — smaller than lg, better NER than sm
en_core_web_lg 560 MB High Best CPU accuracy (default)
en_core_web_trf 460 MB Highest Transformer-based; slowest, needs GPU for practical use

Use --model-name or config to switch:

veil-llm serve --model-name en_core_web_md

Usage with any agentic harness

VeilLLM speaks the OpenAI-compatible API. Any harness that can point to a custom base URL — Hermes, Cline, Continue, Aider, OpenHands, or your own scripts — works with one config change:

# Before: harness hits provider directly
base_url: https://api.openai.com/v1

# After: harness hits VeilLLM, which masks then forwards
base_url: http://127.0.0.1:4000/v1

Your Authorization header is forwarded through unchanged. VeilLLM masks sensitive data in your prompts and restores it in responses transparently — the harness never knows it's there.

Important: VeilLLM v0.1 does not support streaming (stream: true). Configure your harness for non-streaming mode.

Configuration

VeilLLM auto-creates ./config.toml on first run with sensible defaults:

[gateway]
upstream_url = "https://openrouter.ai/api/v1"
port = 4000
salt = "<auto-generated>"
model_name = "en_core_web_lg"

[detection]
enabled_entities = [
    "PERSON",
    "EMAIL_ADDRESS",
    "PHONE_NUMBER",
    "CREDIT_CARD",
    "IBAN_CODE",
    "IP_ADDRESS",
    "LOCATION",
    "US_SSN",
]

[recognizers]
high_entropy_enabled = false
entropy_threshold = 4.5

Every setting can be overridden via environment variable or CLI flag (see table above). Run gateway config to see the resolved settings your gateway will use.

What gets masked

Category Examples
PII (Presidio) Names, emails, phone numbers, credit cards, IBANs, IPs, locations, SSNs
LLM API keys sk-..., sk-ant-..., sk-or-...
AWS keys AKIA... access keys and secret keys
GitHub tokens ghp_..., gho_..., github_pat_...
Google API keys AIza...
JWTs eyJ... three-segment tokens
Private keys PEM -----BEGIN ... PRIVATE KEY----- blocks
High-entropy strings Opt-in: strings with Shannon entropy > threshold

Gradio playground

For a hands-on feel, launch the Gradio UI to see masking live — no upstream API key needed for the detection tab:

uv run --with gradio --with python-dotenv python playground.py

Open http://127.0.0.1:7860. The PII Detection tab lets you paste text and see exactly what gets masked. The Chat tab sends masked prompts to an LLM and shows a transparency log of every entity detected, masked, and restored — the same thing the proxy does silently.

playground.py is a self-contained demo; read it alongside this README to understand the full flow.

How it works

VeilLLM replaces detected values with deterministic placeholders:

"Jane" → <PERSON_a3f2>
"jane@example.com" → <EMAIL_9c1d4e>
"sk-abc123..." → <API_KEY_77b0af>

The same value always maps to the same placeholder (salted hash), so agent conversation history stays coherent across turns. The salt is a random value in ./config.toml — never sent over the network.

On the response, placeholders are restored using tolerant regex matching (handles LLM-mangled casing, spaces, and punctuation).

Endpoints

Endpoint Behavior
POST /v1/chat/completions Mask → forward → unmask
GET /v1/models Pass-through
GET /healthz Liveness check
Any other /v1/* Pass-through (no masking, warning logged)

Telemetry

Per-request log line (stderr):

[req a3f2bc8d] masked 3 entities: API_KEY×1, EMAIL_ADDRESS×1, PERSON×1 | detect 35ms | upstream 1850ms | unmask 2ms

Set GATEWAY_DEBUG=1 to see the placeholder→original map (with a prominent warning).

Docker

docker build -t veilllm .
docker run -p 4000:4000 -v ./config.toml:/app/config.toml veilllm

Limitations (v0.1)

  • No streaming (SSE) — returns 400 if stream: true
  • English-only PII detection
  • Single upstream URL (defaults to OpenRouter; any OpenAI-compatible API works via GATEWAY_UPSTREAM_URL or config.toml)
  • Not a full proxy — only the /v1/* paths are forwarded

License

MIT

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

veil_llm-0.1.0.tar.gz (4.7 MB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

veil_llm-0.1.0-py3-none-any.whl (18.5 kB view details)

Uploaded Python 3

File details

Details for the file veil_llm-0.1.0.tar.gz.

File metadata

  • Download URL: veil_llm-0.1.0.tar.gz
  • Upload date:
  • Size: 4.7 MB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for veil_llm-0.1.0.tar.gz
Algorithm Hash digest
SHA256 5bde5fd19aa1b27f9b58f7a8e6ca5a2ea887c0e8c1e0e6ec9e92cbca783345d3
MD5 3cd22c78d0d14ef1a1d63ee51e0b2bec
BLAKE2b-256 fdcc388d329fe58c6408a05b75437515f74a722c5f526d3d211cc73fc00af84b

See more details on using hashes here.

Provenance

The following attestation bundles were made for veil_llm-0.1.0.tar.gz:

Publisher: publish.yml on h-f-fares/VeilLLM

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file veil_llm-0.1.0-py3-none-any.whl.

File metadata

  • Download URL: veil_llm-0.1.0-py3-none-any.whl
  • Upload date:
  • Size: 18.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for veil_llm-0.1.0-py3-none-any.whl
Algorithm Hash digest
SHA256 85b39e823807de7754ce0a6ae09f4841b8867d4df83365a033c100e95efa6243
MD5 67255e800450f70866e71d684c6ec464
BLAKE2b-256 ff5338aea82dbb95c48c1522656afe26c96ad80aa8cd6e1d5766e7a3a12d6a6a

See more details on using hashes here.

Provenance

The following attestation bundles were made for veil_llm-0.1.0-py3-none-any.whl:

Publisher: publish.yml on h-f-fares/VeilLLM

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page