ScrubVault

Zero-dependency in-memory PII airgap & reversible masking proxy for Cloud LLMs (GDPR Art. 32 compliant).

Documentation

πŸ›‘οΈ ScrubVault: Zero-Data-Leak AI Airgap & Reversible PII Masking Engine

PyPI version License: Apache 2.0 Glama Score M8ven Score Zero Dependencies Raptor Guard Certified GDPR Art. 32

Send sensitive data to Cloud LLMs (ChatGPT, Claude, Gemini) without ever leaking confidential PII.

pip install scrub-vault

ScrubVault is a lightweight, zero-dependency in-memory privacy proxy and Model Context Protocol (MCP) server. It intercept prompts, replaces personal identifiable information (emails, IBANs, IP addresses, credit cards, tax IDs) with deterministic local tokens ({{EMAIL_1}}, {{IBAN_1}}), and restores the original values when the AI responds.


πŸš€ The Architecture

                   +----------------------------------+
                   |  Your Prompt (Confidential PII)  |
                   +----------------------------------+
                                     β”‚
                                     β–Ό
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β”‚    ScrubVault (Local RAM)   β”‚
                      β”‚  - Scans & Masks Sensitive  β”‚
                      β”‚  - Stores Mapping in Memory β”‚
                      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β”‚
                                     β–Ό (Masked Prompt: "{{EMAIL_1}}, {{IBAN_1}}")
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β”‚    Public Cloud LLM API     β”‚
                      β”‚   (OpenAI / Anthropic / ...) β”‚
                      β”‚   *Zero PII is transmitted* β”‚
                      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β”‚
                                     β–Ό (Response with tokens)
                      β”Œβ”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”
                      β”‚    ScrubVault (Local RAM)   β”‚
                      β”‚  - Deterministic Unmasking  β”‚
                      β””β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”€β”˜
                                     β”‚
                                     β–Ό
                   +----------------------------------+
                   |  End-User Result (Restored PII)  |
                   +----------------------------------+

⚑ Quickstart

1. Python SDK (Zero Dependencies)

from src.core.vault import ScrubVault

vault = ScrubVault()

# 1. Mask sensitive input
input_text = "Order for client Max, email: max@corp.de, IBAN: DE89370400440532013000"
result = vault.mask(input_text)

print(result.masked_text)
# Output: "Order for client Max, email: {{EMAIL_1}}, IBAN: {{IBAN_1}}"

# 2. Transmit result.masked_text to your LLM of choice...
ai_response = "Received confirmation for {{EMAIL_1}} on account {{IBAN_1}}."

# 3. Unmask locally
clean_response = vault.unmask(ai_response, result.token_map)
print(clean_response)
# Output: "Received confirmation for max@corp.de on account DE89370400440532013000."

2. Standalone CLI

# Calculate GDPR Art. 32 Risk Score
python -m src.cli.main audit "Contract with Herr Schmidt, IBAN: DE89370400440532013000"

# Mask a dataset file directly
python -m src.cli.main scrub-dataset input.json output_clean.json

πŸ€– Model Context Protocol (MCP) Integration

ScrubVault includes a native stdio Model Context Protocol (MCP) server. Add it to your claude_desktop_config.json or Antigravity configuration:

{
  "mcpServers": {
    "scrub_vault": {
      "command": "python",
      "args": ["-m", "src.mcp.server"],
      "cwd": "/path/to/scrub_vault"
    }
  }
}

1-Click Install via Smithery (Claude Desktop, Cursor):

npx -y @smithery/cli install @tastenkasperle/scrub-vault --client claude

Available MCP Tools:

  • scrub_mask_text: Masks PII in input text and returns a reversible token map.
  • scrub_unmask_text: Replaces tokens with original values.
  • scrub_audit_risk: Calculates risk scores and detection breakdowns.
  • scrub_anonymize_json: Recursively scrubs JSON structures.

πŸ›‘οΈ Security & Clean Code Standard

  • Pure Python Standard Library: Zero third-party dependencies (re, json, sys, typing).
  • In-Memory Vault: Token maps live exclusively in volatile RAM and are never written to disk.
  • ReDoS Hardened: Regex patterns are strictly bounded against algorithmic complexity attacks.
  • Audit Passed: Tested and verified by Raptor Guard SAST (0 Critical, 0 High, 0 Medium findings).

πŸ“„ License

Apache License 2.0. Open-source research and engineering by the Diamantenschmiede.