How Shield's Filter Packs Work
Shield layers four detection engines — each designed for a different class of sensitive data. They run simultaneously on every outgoing API call, and you can toggle each one independently. Any match from any layer triggers redaction before the data leaves your machine.
PII / PHI
Personally Identifiable Information and Protected Health Information — names, emails, SSNs, phone numbers, physical addresses, dates of birth, medical record numbers.
Secrets & Tokens
API keys, auth tokens, connection strings, private keys, and any high-entropy strings that look like machine-generated secrets.
Cloud Credentials
AWS access keys, GCP service account keys, Azure connection strings, and other cloud provider credentials that grant infrastructure access.
Custom / Advanced
Credit card numbers, IP addresses, internal project codes, and custom regex patterns configured per deployment. Shield lets you define your own sensitive data patterns.
Interactive Redaction Sandbox
Match Details — hover or click to see why each was caught
Filter Pack Reference
Frequently Asked Questions
See Shield Redact in Your Own Environment
Shield runs locally on your machine — no cloud component, no data leaving your device. Install it, configure your filter packs, and start redacting sensitive data from every LLM API call in under 5 minutes.