ZTDS.ai Open AI Security Standard
Public Directory · Verifiable Cryptographic Receipts

ZTDS Verified™ Registry

Browse AI applications, browser extensions, agent gateways, and developer SDKs certified compliant with the ZTDS RFC v1.0 standard. All listed products prove 0.00 bytes external sensitive data egress.

For AI Builders & SaaS Founders

Built an AI Agent, RAG Pipeline, or LLM Tool? Get Verified in 5 Minutes.

Enterprise CISOs use this directory to discover zero-data-leakage software. Pass our zero-egress audit, submit your GitOps pull request, and display the official ZTDS seal to fast-track B2B sales and gain high-DR backlink authority.

OPEN REFERENCE SPECIFICATION Apache 2.0

@ztds/core

Vendor-Neutral RFC v1.0 Reference Engine

Official open-source baseline engine and TypeScript interface. Pure in-memory execution enforcing Invariants 1 through 4 with universal base regex entities (Email, Phone, PAN, SSN, IPv4, Secrets). Zero dependencies, 100% free forever for builders and academic validation.

Install: npm install @ztds/core
Invariant Proof: 0.00 Bytes WAN Egress · RAM Only
Open Source TypeScript Apache-2.0 Sub-0.8ms
ZTDS VERIFIED · PIONEER RFC v1.0

PrivacyScrubber Web

Client-Side Document & Prompt Sanitizer

Zero-server, 100% client-side PII/PHI de-identification web utility. Processes large text, PDFs, and conversation prompts strictly inside browser volatile RAM before passing to LLMs.

Perimeter Invariant: 0.00 bytes socket transmission prior to sanitization.
Compliance Basis: GDPR Recital 26 · HIPAA Safe Harbor · EU AI Act Art. 50.
WebAssembly V8 Volatile RAM Maps Zero Server Storage
privacyscrubber.com →
ZTDS VERIFIED · BROWSER RFC v1.0

PrivacyScrubber Extension

Manifest V3 Real-Time Interceptor

Chrome extension running client-side on ChatGPT, Claude, Gemini, Perplexity, and DeepSeek. Intercepts sensitive prompts before DOM submit, tokenizes locally, and restores on response.

Perimeter Invariant: Pure client-side DOM injection; zero external telemetry.
Memory Scope: Tab-isolated ephemeral RAM maps; wiped on tab close.
Chrome MV3 DOM Interceptor Multi-Model
Chrome Web Store →
REFERENCE SDK Apache 2.0

@privacyscrubber/sdk

Headless Engine for Node.js, Web & Python

Official developer engine sponsored by the consortium. Embeds directly into LangChain, LlamaIndex, CrewAI, or custom REST pipelines with < 0.8ms local execution latency.

Package: npm install @privacyscrubber/sdk
Benchmark: Audited on Open Science Framework (OSF DOI: 10.17605).
TypeScript Python Bridge Sub-1ms
ZTDS VERIFIED · GATEWAY RFC v1.0

ZTDS MCP Gateway

Cursor, Windsurf & Claude Desktop Connector

Standard Model Context Protocol stdio adapter running on localhost. Automatically strips developer secrets, database passwords, and client PII before passing prompts to coding LLMs.

Transport: stdio stream on local workstation.
Egress: Zero socket transmission beyond verified client.
MCP Standard Cursor Ready Claude Desktop
Setup MCP Stdio →
ZTDS VERIFIED · BLUEPRINT RFC v1.0

LangChain ZTDS Callback

AI Framework Connector & Agent Hook

Zero-trust client-side callback handler for LangChain & LangGraph workflows. Sanitizes tool inputs and conversation state strictly in local memory before invoking external LLMs.

Perimeter Invariant: In-memory async callback hook with volatile state isolation.
Compliance Basis: GDPR Recital 26 · HIPAA Safe Harbor · EU AI Act Art. 50.
LangChain LangGraph Python & TS Volatile RAM
View Blueprint →
ZTDS VERIFIED · BLUEPRINT RFC v1.0

LlamaIndex Air-Gap Sanitizer

RAG & Vector Pipeline Ingestion Node

Pre-indexing ingestion pipeline node and query sanitizer ensuring raw PII/PHI is never embedded into vector stores, preventing permanent GDPR Article 17 vector poisoning.

Perimeter Invariant: Client-side ingestion node & deterministic token substitution.
Compliance Basis: GDPR Art. 17 (Right to Erasure) · HIPAA Safe Harbor · SOC 2 Type II.
LlamaIndex Vector RAG Zero Storage Embedding Sanitizer
View Blueprint →
ZTDS VERIFIED · BLUEPRINT RFC v1.0

Ollama Local Privacy Filter

Local LLM Engine & Loopback Proxy

Sidecar proxy intercepting Ollama REST endpoints on localhost. Guarantees complete air-gapped de-identification and secret stripping before edge inference executes.

Perimeter Invariant: Loopback reverse proxy with RAM-only stream buffer.
Compliance Basis: NIST 800-53 · ISO 27001 A.8.11 · Zero External Socket Policy.
Ollama Local LLM Loopback Proxy Edge Privacy
View Blueprint →
ZTDS VERIFIED · ENTERPRISE RFC v1.0

Envoy Proxy WASM Filter

Enterprise Network Gateway & Service Mesh

High-performance WebAssembly HTTP filter for Envoy and Istio service mesh. Enforces zero-egress PII sanitization at egress gateways with < 0.8ms overhead.

Perimeter Invariant: Proxy-WASM sandboxed bytecode engine (<0.8ms overhead).
Compliance Basis: SOC 2 CC6.7 · PCI-DSS v4.0 · FedRAMP Moderate · HIPAA Safe Harbor.
Envoy Proxy Istio Mesh WebAssembly Sub-1ms WASM
View Blueprint →
ZTDS VERIFIED · GATEWAY RFC v1.0

FastMCP Stdio Gateway

Sub-millisecond Python Model Context Protocol Adapter

High-throughput FastMCP stdio daemon running locally for Python agent workflows. Strips corporate secrets, database connection strings, and PII before dispatch to Cursor, Windsurf, or Claude Desktop.

Perimeter Invariant: Stdio stream filter with RAM-only ephemeral surrogate table.
Compliance Basis: SOC 2 CC6.7 · ISO 27001 A.8.11 · GDPR Art. 28 Vendor Exemption.
FastMCP Python 3.10+ Claude Desktop Sub-1ms
Setup FastMCP →
ZTDS VERIFIED · BLUEPRINT RFC v1.0

CrewAI Privacy Agent

Multi-Agent Inter-Node Communication Sanitizer

Memory-isolated hook preventing sensitive data cross-contamination between autonomous multi-agent swarms. Enforces 0.00 bytes leakage during delegated task execution and tool handoffs.

Perimeter Invariant: In-memory message interceptor & reversible ephemeral token mapping.
Compliance Basis: EU AI Act Art. 50 · GDPR Art. 28 Vendor Exemption · HIPAA Safe Harbor.
CrewAI Multi-Agent Ephemeral RAM Zero Egress
View Blueprint →