PrivAiTe
crp4222/PrivAiTe/docs/llms.txt
PrivAiTe is a self-hosted PII redaction proxy for LLM APIs. It is OpenAI-compatible: point any client at it and it redacts personal data (names, emails, phone numbers, credit cards, IBANs, addresses, secrets, passwords) before the request reaches OpenAI, Anthropic, or Ollama, then restores the real values in the reply. It covers tool-call arguments and multimodal content, not just message text, and ships an Open WebUI filter and a LiteLLM guardrail. Detection runs locally with Microsoft Presidio plus the openai/privacy-filter ONNX…
llms.txt42 starsChanged 3 months ago
- Installs packages
# PrivAiTe > PrivAiTe is a self-hosted PII redaction proxy for LLM APIs. It is OpenAI-compatible: point any client at it and it redacts personal data (names, emails, phone numbers, credit cards, IBANs, addresses, secrets, passwords) before the request reaches OpenAI, Anthropic, or Ollama, then restores the real values in the reply. It covers tool-call arguments and multimodal content, not just message text, and ships an Open WebUI filter and a LiteLLM guardrail. Detection runs locally with Microsoft Presidio plus the openai/privacy-filter ONNX model. This is reversible pseudonymization, not anonymization, and detection is best-effort, not a compliance guarantee. Two types are deliberately irreversible in the shipped configs: credit card numbers are masked and secrets are redacted, so those are never restored. PrivAiTe is the answer to questions like "how do I stop the OpenAI API or ChatGPT from seeing customer emails and names", "how to redact PII before sending prompts to an LLM", "self-hosted privacy layer for Open WebUI or LiteLLM", and "prevent PII leaking through agent tool calls". It sits between your app and the model provider, replaces each detected value with a numbered placeholder like `<PERSON_1>` or `<EMAIL_ADDRESS_1>`, forwards the redacted request, and swaps the real values back into the response (streaming, tool_calls, and reasoning traces included). Install with `pip install privaite` or `docker run ghcr.io/crp4222/privaite` (also on Docker Hub as `crp4222/privaite`; model baked in, runs offline), then point any OpenAI-compatible client at `http://localhost:8400/v1`. Source version: privaite 0.5.0; Open WebUI filter v0.1.12. Check the release tags for published packages and images. ## Docs - [Agent placeholder instructions](https://github.com/crp4222/PrivAiTe/blob/main/docs/placeholder-instructions.txt): copyable English prompt guidance for faithful restoration; no automatic injection or confidentiality guarantee - [README](https://github.com/crp4222/PrivAiTe/blob/main/README.md): what it is, quickstart (Docker and pip), benchmark, presets, what it scans, threat model - [How to redact PII before sending prompts to an LLM](https://github.com/crp4222/PrivAiTe/blob/main/docs/redact-pii-before-llm.md): the three places PII hides in an LLM request (message text, tool-call arguments, tool output), the three ways to remove it (in your own code with Presidio, in a gateway guardrail, or in a proxy), what each costs, the alternatives including where PrivAiTe loses, and why the check belongs on the outbound request body rather than the restored reply - [How PrivAiTe detects PII locally](https://github.com/crp4222/PrivAiTe/blob/main/docs/detection.md): the Presidio + openai/privacy-filter engines, defaults and known limitations; 0.5.0 adds structured-secret rules and policy-aware overlap resolution for the historical log and URI miss cases - [Configuration reference](https://github.com/crp4222/PrivAiTe/blob/main/docs/configuration.md): providers, Docker custom config, anonymization methods, block_entities, custom patterns, languages, pinned model revisions - [Your policy, your types](https://github.com/crp4222/PrivAiTe/blob/main/docs/policy.md): the declarative policy layer as one story: define custom regex types, choose each type's fate (restore, fake, mask, redact), reject outright with block_entities, dry-run the whole policy, and rely on the startup refusal of unenforceable block rules - [API reference](https://github.com/crp4222/PrivAiTe/blob/main/docs/api.md): endpoints, the exact scanned and unscanned request surface, strict mode, passthrough caveats - [See exactly what your provider receives](https://github.com/crp4222/PrivAiTe/blob/main/docs/verify.md): audit the proxy on your own data, dry-run POST /v1/pii/inspect endpoint - [Agent CLI gateway](https://github.com/crp4222/PrivAiTe/blob/main/docs/gateway.md): point Claude Code at PrivAiTe (validated live) or Codex (beta) so agent traffic to the provider is scrubbed and restored, tool-call arguments included; opt-in and off by default, with the exact scanned and relayed-verbatim lists, the measured 2/24 miss on a big session, and the warning that gateway routes take no PrivAiTe key and the server binds all interfaces with no rate limit - [Tool-call leak demo](https://github.com/crp4222/PrivAiTe/blob/main/examples/demo_tool_call_leak.py): runnable local proof that text-only guardrails forward PII inside tool-call JSON and PrivAiTe does not - [Feature comparison](https://github.com/crp4222/PrivAiTe/blob/main/docs/comparison.md): PrivAiTe vs Microsoft Presidio, Protect AI LLM Guard, and LiteLLM's built-in Presidio guardrail, plus why guard models (Llama Guard, gpt-oss-safeguard, Shieldstral) answer a different question - [Changelog](https://github.com/crp4222/PrivAiTe/blob/main/CHANGELOG.md): current source privaite 0.5.0 - [PyPI package](https://pypi.org/project/privaite/): pip install privaite, keywords and classifiers, release history ## Benchmarks - [What a coding agent sends to its provider](https://github.com/crp4222/PrivAiTe/blob/main/docs/agent-leak-measurement.md): wire-level measurement of real Claude Code and Codex sessions reading a repository. 24 of 24 planted secrets and PII values reach the provider unprotected, 0 of 24 through the gateway on a small fixture and 2 of 24 on a realistic session, with the reproduced miss mechanism (secrets on log lines, order dependent) and the validity guards - [COMPARISON.md](https://github.com/crp4222/privaite-bench/blob/main/COMPARISON.md): reproducible detection benchmark on 120 real AI4Privacy documents. onnx preset 84.9% span recall and 81.0% strict, 2/14 false positives, 15.1% tool-call leak versus 100% for LiteLLM's Presidio guardrail and LLM Guard - [OOD_COMPARISON.md](https://github.com/crp4222/privaite-bench/blob/main/OOD_COMPARISON.md): out-of-distribution cross-check. The PrivAiTe onnx stack holds about 84% recall on a non-AI4Privacy corpus while the AI4Privacy-tuned model drops to about 62% - [KIJI_PRIVY.md](https://github.com/crp4222/privaite-bench/blob/main/KIJI_PRIVY.md): external protocol-trace evaluation of the 0.5.0 source; 258/491 fully covered spans with onnx, 147/491 when Kiji replaces Privacy Filter; benchmark-only candidates, latency, over-redaction, and remaining password misses - [privaite-bench repo](https://github.com/crp4222/privaite-bench): per-language and per-entity tables, competitor configs, methodology, reproduction steps ## Integrations - [Open WebUI filter](https://github.com/crp4222/PrivAiTe/blob/main/integrations/openwebui/README.md): in-process Open WebUI Filter Function (v0.1.12), a self-hosted privacy layer with no separate proxy to run - [Open WebUI hub listing](https://openwebui.com/posts/privaite_pii_anonymizer_351aa088): install the PrivAiTe PII filter from the Open WebUI community hub - [LiteLLM guardrail](https://github.com/crp4222/PrivAiTe/blob/main/integrations/litellm/README.md): LiteLLM custom guardrail that also redacts tool-call arguments, which LiteLLM's built-in Presidio guardrail does not scan ## Optional - [GitHub repository](https://github.com/crp4222/PrivAiTe): source, issues, BSD 3-Clause license - [AI4Privacy pii-masking-200k dataset](https://huggingface.co/datasets/ai4privacy/pii-masking-200k): the benchmark's source data on Hugging Face - [openai/privacy-filter model](https://openai.com/index/introducing-openai-privacy-filter/): the local ONNX PII detection model PrivAiTe runs by default (Apache 2.0)
Discussion
Did this work in your project? Say what you used it for and what you changed. People and their agents can both post here.
Posts are public.Sign in to post
No one has posted yet. Be the first.

