ZTDS Data Sanitizer

Zero-Trust Data Sanitization reference MCP server for Cursor and Claude Desktop. Local in-memory PII de-identification and deterministic surrogate tokenization (RFC v1.0, Apache-2.0).

Documentation

ZTDS MCP Server (ztds-mcp)

License: Apache-2.0 Specification: RFC v1.0 IETF Draft DOI Zero Network Egress

Open-source reference implementation of the Zero-Trust Data Sanitization (ZTDS) protocol for the Model Context Protocol (MCP) ecosystem. Conforms to RFC v1.0 and IETF draft draft-sibiryakov-ztds-protocol-02.

Runs 100% locally with zero network calls, zero external subprocessors, zero disk writes, and zero telemetry.


The 4 Core Protocol Invariants

  1. Invariant 1: Zero External Egress Prior to Sanitization
    Cleartext PII, PHI, and credentials never cross the local execution boundary unmasked.
  2. Invariant 2: Deterministic Context-Preserving Reversible Tokenization
    Sensitive values are replaced by synthetic tokens ([EMAIL_TOKEN_1], [API_SECRET_TOKEN_1]) maintaining syntactic context for LLMs.
  3. Invariant 3: Verifiable Ephemeral RAM Isolation (Theorem 2 Zeroization)
    Mapping tables exist strictly in volatile memory and are zeroized upon session termination.
  4. Invariant 4: Subprocessor Chain Exclusion
    Operates strictly as a local computational utility under GDPR Recital 26, rendering Data Processing Agreements (DPAs) unnecessary.

Installation & Client Configuration

1. Claude Desktop

Add to your claude_desktop_config.json:

{
  "mcpServers": {
    "ztds": {
      "command": "npx",
      "args": ["-y", "ztds-mcp"]
    }
  }
}

Config file locations:

  • macOS: ~/Library/Application Support/Claude/claude_desktop_config.json
  • Windows: %APPDATA%\Claude\claude_desktop_config.json
  • Linux: ~/.config/Claude/claude_desktop_config.json

2. Cursor IDE

Add to your Cursor MCP settings (Settings -> Features -> MCP -> Add New MCP Server):

  • Name: ztds
  • Type: command
  • Command: npx -y ztds-mcp

Or add to .cursor/mcp.json in your workspace:

{
  "mcpServers": {
    "ztds": {
      "command": "npx",
      "args": ["-y", "ztds-mcp"]
    }
  }
}

3. Windsurf / Codeium

Add to ~/.codeium/windsurf/mcp_config.json:

{
  "mcpServers": {
    "ztds": {
      "command": "npx",
      "args": ["-y", "ztds-mcp"]
    }
  }
}

Available MCP Tools

ToolDescription
ztds_sanitizeMasks sensitive PII/credentials with deterministic surrogate tokens prior to LLM transmission.
ztds_restoreRestores original cleartext from volatile in-memory mapping into LLM output.
ztds_auditScans text for exposed credentials and PII, returning SHA-256 integrity receipt and risk score.
ztds_infoRetrieves RFC v1.0 standard details, academic citations, and enterprise documentation.
ztds_reset_sessionPurges and zeroizes all volatile session token mappings (Theorem 2).

Universal Baseline vs Commercial Production Profiles

This open-source server covers universal baseline entities (Email, Phone, SSN, Credit Cards, IPv4, IBAN, API Secrets).

For production enterprise workloads requiring:

  • 30+ Specialized Industry Profiles: HIPAA PHI (18 identifiers), PCI-DSS (cardholder data & CVV), GLBA Financial, SEC 17a-4, CJIS Law Enforcement, FERPA Student Records, European National IDs.
  • Agentic Guard Automation: Autonomous zero-trust tool wrappers (guard_exec, guard_read_file, guard_apply_patch).
  • Team Seat Licensing: Offline air-gapped license tokens without cloud telemetry.
  • Headless SDK: Backend RAG pipeline redaction for Node.js / TypeScript / Python.

Deploy the production commercial engine:

# Production MCP Server
npm install -g @privacyscrubber/mcp-server

# Headless Backend SDK
npm install @privacyscrubber/sdk

Website: https://privacyscrubber.com


Verification & Self-Test

To run the offline test suite:

node test.js

Conforms to standard JSON-RPC 2.0 stdio protocol. Zero runtime dependencies.


License

Apache-2.0. Maintained by the ZTDS AI Consortium (Working Group WG-1). Website: https://ztds.ai