SYSTEM: REDACTR // EGRESS CONTROL▌ MONITORING ACTIVEUNIT RDX-01 · REV 2.6
proxy active · all traffic protected

Use AI on real code. Leak zero secrets.

Redactr scrubs secrets and PII out of every AI request before it leaves your machine. API keys, credentials, customer records: redacted before Claude, Copilot or ChatGPT ever see them.

One command to install. No code leaves your control.

outbound api.anthropic.com
 scanning
Move faster

Stop scrubbing code by hand

No more deleting keys before every prompt. Point your AI at real files and keep working. Redactr cleans each request on the way out.

Adopt safely

Roll out AI tools without the leak

Let your team use the tools that make them fast, without it becoming a credential leak or a customer-data incident.

Stay compliant

Give the auditor an answer

Keep PII out of third-party AI tools and get a metadata-only audit trail. The control and the evidence you need for GDPR, HIPAA and PCI reviews.

Works with Claude Code/GitHub Copilot/ ChatGPT Codex/Cursor & VS Code AI
The leak

AI tools send more than your code.

Every prompt carries whatever's in the open file. A key here, a customer record there. The tools are too useful to drop and too quiet to trust blindly, and right now nobody can see what's leaving the building.

SECRETS

Keys ride along for free

A hardcoded API key, a database URL, a private key someone committed two years ago. They travel with the context on every prompt, whether you meant to send them or not.

PII & COMPLIANCE

Customer data you can't un-send

A name in a test fixture, an email in a log line, an SSN in the row you're debugging. Once it's in someone else's logs, "we won't train on it" is not an answer you can give an auditor under GDPR, HIPAA or PCI.

VISIBILITY

A leak you can't measure

Which developers, which tools, which data, how often? There's no log and no number. You can't fix what you can't see.

How it works

One checkpoint. Every request.

Redactr sits between your AI tools and the model. It reads each outbound request, redacts the secrets and PII, and forwards the rest in milliseconds. Your AI still gets the code it needs to help. It just never sees the parts that should stay home.

YOU + YOUR AI TOOL
Claude
──▶
REDACTR
inspect · redact · sandbox
──▶
AI PROVIDER
key: REDACTED
LAYER 1

Known patterns Free

Emails, card numbers, SSNs, tokens and IDs that always look the same.

LAYER 2

Hidden secrets Free

Fresh API keys match no pattern. Redactr flags strings too random to be anything but a secret.

LAYER 3

Context-aware Enterprise

Catches names, addresses and other PII by how they're used, not just how they look.

The free Community edition runs Layers 1-2 (regex + entropy). Layer 3 (context-aware ML) and the benchmarks below are Redactr Enterprise.

Protection that stays out of the way.

It works in the background. You get a green light and keep coding. Your security team gets answers it never had before.

Layered redaction Enterprise

Catches the obvious secrets and the ones that don't look like anything, without stripping the context your AI needs. Free does regex + entropy; context-aware ML is Enterprise.

Sandboxed agents Enterprise

Each AI agent runs in a sealed container that can only reach the world through Redactr. A sketchy dependency stays boxed in.

Team control plane Enterprise

Set policy once, sign it, push it to every device. It applies automatically and keeps working even if the server is unreachable.

Fleet visibility Enterprise

See how many machines are protected right now, and get flagged the moment a tool talks to a provider outside the proxy.

Signed policy Enterprise

Policies are cryptographically signed, so one misconfigured or compromised device can't quietly weaken your protection.

Zero-config tools Free

Type redactr run claude and you're protected. Nothing new to learn.

Built to catch what turns into incidents.

Credentials, keys and customer data are the things that turn into incidents. Redactr is built to catch those, and to get better over time.

EnterpriseThese figures measure Redactr Enterprise's layered detection. The free Community edition does regex + entropy (no ML), so these benchmarks don't apply to it.

88%
of what Redactr flags is genuinely sensitive, few false alarms
80%
of sensitive data caught in our Enterprise benchmarks
1,611
pieces of PII tested across 5 public datasets
0
code, traffic or redacted values sent to our server

No scanner catches everything, and anyone who says theirs hits 100% is selling you something. Redactr is a very good seatbelt, not a force field: it turns an invisible, unmeasured leak into something you can see and steadily tighten. (Figures above are from our own testing of Redactr Enterprise on public PII datasets; the free edition runs regex + entropy and isn't covered. Full method on the blog.)

For security teams

Your team sees metadata. Never your code.

The server learns that "an AWS key was redacted on this machine" and nothing else. Not the code, not the traffic, not the redacted values themselves. Security gets the visibility to enforce policy. Developers keep their privacy. And when an auditor asks what leaves your network for AI, you have a real control and a log to point to.

metadata-only by design redaction audit trail for reviews helps meet HIPAA · PCI · GDPR obligations signed & auditable policy runs on your infrastructure

Start free. Upgrade when your team needs control.

Community
free · open source

The redaction proxy, running entirely on your machine. One command to install.

  • Regex + entropy detection for secrets & PII (no ML)
  • Redacts .env / credential file contents in-flight
  • redactr scan to find secrets in your files
  • Local HTTPS proxy, nothing leaves your machine
  • AGPL-3.0, source on GitHub
Enterprise
book a call

Everything in Community, plus the detection, isolation, and team control a fleet needs.

  • ML / context-aware detection beyond regex & entropy, with benchmarked precision & recall
  • Agent sandboxing in egress-locked containers
  • Fleet control plane · signed policy
  • Audit trail for GDPR / HIPAA / PCI reviews, metadata only
  • Runs on your infrastructure · SSO
Book a call →