Zero-Friction Privacy & Sensitive Data Shield for AI Coding CLIs.
Transparently intercepts developer prompts from tools like Claude Code, Google Antigravity (AGY), Aider, and Copilot CLIโmasking credentials, customer PII, and proprietary algorithms outbound, and restoring them inbound with fuzzy self-healing.
When developers use cutting-edge AI coding agents, entire source files, environment configurations (.env), production database connection strings, third-party API keys, and company trade secrets are uploaded in plaintext to third-party cloud LLM servers. This creates severe regulatory, compliance, and corporate espionage risks.
PrivyCLI creates an invisible, local air-gap layer on your developer machine:
- Transparent Interception: Keep typing
claude,agy, oraidernormally in your terminalโPrivyCLI silently intercepts outbound traffic. - Reversible Tokenization: Real secrets, connection strings, IPs, and PII are replaced with synthetic deterministic tokens (
[SECRET_UUID]) before transmission. - Fuzzy Self-Healing Restorer: When the cloud LLM generates code patches, PrivyCLI recovers and restores your original secrets locallyโeven if the LLM hallucinates or drops trailing characters.
- Filesystem Shield (
.privyignore): Blocks 25+ sensitive file patterns (.env,*.key,*.pem,*.sqlite,id_rsa*) from being ingested into LLM prompt contexts.
sequenceDiagram
autonumber
actor Dev as ๐จโ๐ป Developer (Terminal)
participant CLI as ๐ค AI Coding CLI (Claude / AGY / Aider)
participant Shield as ๐ก๏ธ PrivyCLI Engine (Proxy & Sanitizer)
participant Vault as ๐ Local SQLite Vault (AES-256)
participant Cloud as โ๏ธ Cloud LLM (Anthropic / OpenAI / Google)
Dev->>CLI: "Optimize database pool and fix payment webhook"
CLI->>Shield: Raw Request (Source code + Production secrets)
Shield->>Vault: Store real values & generate synthetic tokens
Vault-->>Shield: Tokens: [SECRET_UUID], [PII_IBAN_UUID]
Shield->>Cloud: Sanitized Request (Zero sensitive data leaves machine)
Note over Cloud: Model reasons on code architecture<br/>and generates refactored patch
Cloud-->>Shield: LLM Response (Code containing tokens)
Shield->>Vault: Restore tokens using Fuzzy Levenshtein Self-Healing
Vault-->>Shield: Original production values
Shield-->>Dev: Fully functional, pristine refactored code on disk!
PrivyCLI includes out-of-the-box dual-directional domain protection profiles tailored to regulated industries:
| Profile ID | Target Industry & Regulatory Compliance | Protected Concepts & Data Types |
|---|---|---|
financial |
Fintech, Banking, HFT, Crypto (PCI-DSS, SOC 2, GLBA) | Order book spreads, arbitrage algorithms, dark pool discovery, liquidity depths, SWIFT BIC, margin call rules. |
healthcare |
Healthtech, Biotech, Pharma, Hospitals (HIPAA, GDPR) | Patient identifiers, ICD-10 diagnosis codes, clinical trial cohorts, drug molecule structures, dosages, genomic vectors. |
enterprise_ip |
Big Tech, SaaS, E-Commerce (Trade Secrets, ISO 27001) | Proprietary ranking formulas, churn prediction matrices, dynamic pricing engines, confidential financial margins. |
defense |
Aerospace, Autonomous Systems, Defense IT | Guidance acceleration vectors, radar tracking loops, payload telemetry, electronic warfare parameters. |
universal |
Global Cross-Industry (Default) | All industry rules active simultaneously with zero configuration. |
Option A: Quick Direct Install (Recommended)
pip install git+https://github.com/Farukes/privycli.git@v0.5.0-betaOption B: Clone & Local Setup (Developers)
# Clone the repository
git clone https://github.com/Farukes/privycli.git
cd privycli
# Create and activate virtual environment
python -m venv venv
# Windows (PowerShell):
.\venv\Scripts\activate
# Linux / macOS (Bash/Zsh):
source venv/bin/activate
# Install dependencies and local editable CLI
pip install -e .privycli setupInstalls the local trusted root SSL certificate, configures shell aliases in your PowerShell ($PROFILE) / Bash (~/.bashrc), generates default .privyignore, and boots the background privacy proxy.
Verify everything is working with a health check:
privycli doctorPrivyCLI provides an intuitive, friction-free developer experience with just 8 essential commands:
# --- Daily Workflow ---
privycli on # Enable privacy shield (intercepts and sanitizes all AI calls)
privycli off # Temporarily disable shield (zero-friction raw pass-through)
privycli status # View real-time shield status, ports, and intercepted endpoints
# --- Testing & Diagnostics ---
privycli sim # Run an interactive end-to-end simulation of Claude/AGY under PrivyCLI
privycli doctor # Inspect system health, CA certificate trust, and shell hooks
privycli logs -f # Stream live proxy and redaction events in your terminal
# --- Zero-Trace Uninstallation ---
privycli uninstall # Completely remove certificates, shell hooks, daemon, and local vaultsOnce privycli on is active, you don't need to change how you work:
# Work with your favorite AI coding CLI completely normally:
claude "Refactor database connection pool and fix payment webhook"
# or
agy "Fix production bugs in auth_service.py"
# or
aider --message "Add unit tests for payment webhook"- Outbound Prompt: PrivyCLI automatically detects
.envsecrets, database URIs, passwords, and API keys, replacing them with synthetic tokens ([SECRET_UUID]) before transmission to the cloud LLM. - Inbound Patch: When the AI returns code diffs or solutions, PrivyCLI restores the original secrets locally from your encrypted SQLite vault.
PrivyCLI includes a built-in file filter engine similar to .gitignore. It prevents AI coding tools from ingesting sensitive configuration and credential files into prompt context.
- Automated:
privycli setupautomatically generates a default.privyignorefile in your project root. - Manual: Run
privycli init-ignoreinside any project folder to place the template. - Zero-Config Fallback: Even without an explicit
.privyignorefile in your workspace, PrivyCLI's core engine automatically blocks 25+ critical file patterns by default.
- Environment Configurations:
.env,.env.*,*.env.local,*.env.production - Private Keys & Certificates:
*.pem,*.key,id_rsa*,id_ed25519*,*.pfx,*.kdbx - Cloud & Service Accounts:
credentials.json,service_account*.json,.aws/*,.ssh/* - Local Databases & Dumps:
*.sqlite,*.sqlite3,*.db,*.sql,*.dump
Any attempt by an AI tool or prompt context to access or read these files is intercepted and blocked at the operating system layer. You can customize .privyignore with project-specific rules at any time.
Run the full automated test battery:
pytest -v tests46/46 unit, integration, stress, and multi-module enterprise repository benchmark tests passing (100% green):
- Multi-Module Enterprise Repository Benchmark (Cross-file token consistency across 8+ microservices)
- 50-Thread Concurrent SQLite Vault Stress Testing
- 5,000-Line Code Ingestion Performance (<0.46s throughput)
- ReDoS Vulnerability Protection (13,000x speedup bounded matching)
- 100-Token Fuzzy Self-Healing Restoration (Levenshtein distance self-recovery)
- Deep AST Code Morphing & Domain Transmutation
- System Health Doctor & Diagnostics
- Live Event Log Streaming
- Transparent Shell Interception Hooks & Instant ON/OFF Master Switch
- Upstream Corporate Proxy Chaining & Local Air-Gap LLM Fallback
Distributed under the MIT License. Free for individual, open-source, and commercial enterprise use.