Prompt sanitizer
Paste the log, the stack trace, the config file or the customer email you were about to hand to a model. This page masks the keys, tokens, credentials and personal data in it, leaves the structure intact so the model can still reason about it, and then puts the real values back into the reply you get. Nothing you paste is uploaded — which is the only arrangement that makes sense for a tool whose whole job is the things you cannot afford to send anywhere.
What this tool does
Every paste into a hosted model is a disclosure. Not necessarily a breach, and not necessarily training data — but a copy of whatever you pasted now exists on infrastructure you do not run, inside an account someone else can be subpoenaed for, logged for a retention window you did not choose. Most of the time that is fine. The problem is that the thing people paste most often — a stack trace, a failing request, a config, a chunk of a support thread — is exactly the kind of text that carries a live credential or somebody's personal data without anyone meaning it to.
So this page reads the text first. It finds the things that should not travel, replaces
each one with a stable placeholder like [AWS_KEY_1] or [EMAIL_2],
and gives you back something you can paste without flinching. The placeholders are stable on
purpose: the same value gets the same number everywhere it appears, so a model can still
follow that the request in line 4 came from the same user as the error in line 40. Redaction
that replaces everything with XXXX destroys that, and then the answer you get
back is worse.
And then it reverses
The second half is the part other redactors skip. When the model answers — with a patched config, a rewritten query, a draft reply — paste its answer into the restore box and the placeholders turn back into the real values. The mapping never left the page, so the round trip costs you nothing. That is what makes this usable more than once: you are not choosing between a safe paste and a useful answer.
What it looks for
Credentials and keys. AWS access key IDs and secret keys, GitHub tokens
including fine-grained PATs, OpenAI and Anthropic keys, Google API keys, Stripe live and
test keys, Slack tokens and webhook URLs, SendGrid, Twilio, npm and PyPI tokens, Mailgun and
Postmark keys, private keys of every kind (-----BEGIN … PRIVATE KEY-----),
JSON Web Tokens, and the generic shapes — API_KEY=…,
"password": "…", Authorization: Bearer …,
Cookie: headers, and database connection strings with the password still in
them.
People. Email addresses, phone numbers in international and common
national formats, and the home-directory paths that carry your username —
/Users/you, C:\Users\you, /home/you — which is how a
screenshot of a stack trace quietly names an employee.
Money and identity numbers. Card numbers, checked against the Luhn algorithm so a random sixteen-digit order id is not mistaken for one. IBANs. US Social Security numbers, Indian PAN and Aadhaar numbers, UK National Insurance numbers.
Network detail. Public IPv4 and IPv6 addresses, MAC addresses, and
internal hostnames — anything ending .internal, .local,
.corp, .lan. Private-range addresses are deliberately left alone:
10.0.0.4 tells an outsider nothing, and masking it only makes the text harder
to reason about.
What it cannot find, and you should assume it will not
This is pattern matching, not comprehension. It cannot recognise a person's name, because a name is just a word. It cannot tell that a project codename is confidential, that a revenue figure is unpublished, or that the architecture you described in the paragraph above the log is the part your competitor would want. It will not catch a credential in a format nobody has standardised, and it will not catch anything in an image you attach.
Treat it as the thing that catches the mechanical mistakes — the pasted key, the stray address — and treat the judgement about everything else as still yours. A tool that promised otherwise would be selling you a feeling.
If it found a real key, that key is already spent
Worth saying plainly, because people reach for a redactor after the fact as often as before it. If you paste something here and it finds a live credential that you had already sent to a model, masking it now changes nothing about the copy that is already out there. Rotate it. The same goes for a key that reached a chat log, a ticket, a Slack channel, or a screenshot in a bug report — a secret that has been somewhere it should not have been is not a secret you still own, and the only honest response is a new one.
Nothing you paste leaves your browser
The scanning, the masking and the reversal all happen in this page, on your machine. There is no upload, no account, and no server to send anything to; the page makes no network request carrying any part of your text, and the mapping between placeholders and real values is held in memory and discarded when you close the tab. Our analytics records that the tool was used and how many categories matched — never a value, never a length, never the text.
The longer argument for why this matters is in everything you paste into an LLM is a disclosure. If you are securing the model rather than the paste, the AI Audit is the other end of the same problem, and the lethal trifecta explains what happens when an agent can read your data and reach the network at once.