Back to Browse

Ztds MCP Server

by Moxno
Developer ToolsScan in ProgressMCP RegistryLocal
Free

Server data from the Official MCP Registry

Open standard MCP server for Zero-Trust Data Sanitization (ZTDS RFC v1.0). In-memory PII masking.

About

Open standard MCP server for Zero-Trust Data Sanitization (ZTDS RFC v1.0). In-memory PII masking.

Security Report

0.0
Use Caution0.0Moderate Risk

2 tools verified · Open access · No issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.

How to Install

Add this to your MCP configuration file:

{
  "mcpServers": {
    "io-github-moxno-ztds": {
      "args": [
        "-y",
        "ztds-mcp"
      ],
      "command": "npx"
    }
  }
}

Documentation

View on GitHub

From the project's GitHub README.

ztds-audit — Zero-Trust Data Sanitization (ZTDS™ RFC v1.0) Invariant Auditor

Specification License: Apache-2.0 Zenodo DOI OSF DOI Patent Pending WAN Egress

The official developer CLI and automated CI/CD auditor for the Zero-Trust Data Sanitization (ZTDS™ RFC v1.0) architecture. Maintained by the ZTDS AI Consortium.

ZTDS™ is an open industry standard governing in-memory data sanitization for artificial intelligence, retrieval-augmented generation (RAG), and Large Language Model (LLM) pipelines.


1. The 4 Fundamental Invariants (RFC v1.0)

Every AI pipeline audited by ztds-audit is verified against the 4 core mathematical and architectural invariants:

  1. Invariant 1: Zero External Egress Prior to Sanitization: Raw sensitive cleartext (PII, PHI, API secrets, private financial numbers) must never cross the local execution boundary prior to reversible surrogate tokenization.
  2. Invariant 2: Deterministic Reversible Tokenization: Semantic, syntactic, and structural context must be preserved for LLM reasoning while de-identification lookup tables remain strictly in local host volatile memory.
  3. Invariant 3: Cryptographic & In-Memory Isolation: Operations run in volatile heap or hardware-attested enclaves (WASM, Nitro Enclaves, C-ABI) with zero unencrypted disk spill and immediate memory zeroization.
  4. Invariant 4: Continuous Subprocessor Exclusion: Local client-side execution eliminates third-party transmission, legally exempting deployments from GDPR Article 28 data processing agreements (Zero-DPA).

2. Quickstart

Run a zero-install security and invariant audit across your codebase or AI agent repository:

npx ztds-audit --dir ./src --strict

Command-Line Flags

FlagDescriptionDefault
-d, --dir <path>Target directory to auditCurrent working directory
--jsonOutput structured machine-readable JSON reportfalse
--strictFail build on any low-severity or informational findingfalse
-h, --helpDisplay CLI options and usageN/A

Example Output

[ZTDS] ZTDS.ai In-Memory Codebase Auditor (RFC v1.0 Conformance)
----------------------------------------------------------------------
Directory:     /home/runner/work/ai-agent/src
Files Scanned: 48 files in 18ms
Audit Hash:    sha256:7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069
----------------------------------------------------------------------

[PASS] CONFORMANCE CONFIRMED: 0 INVARIANT VIOLATIONS DETECTED
All scanned files comply with ZTDS Invariant 1 (Zero-Egress) and Invariant 3 (RAM isolation).

[LEGAL STATUS] Qualifies for GDPR Article 28 DPA Exemption (Zero-Subprocessor Chain)
[PERFORMANCE]  0.00 Bytes Sensitive WAN Egress | Pure In-Memory Execution

Next Steps for Builders & Maintainers:
1. Include this audit hash in your pull request: https://ztds.ai/apply/
2. Embed your Verified Trust Badge in README.md to claim your registry backlink:
   [![ZTDS Verified](https://ztds.ai/badge/your-app.svg)](https://ztds.ai/registry/)

3. GitHub Actions CI/CD Integration

Enforce zero-trust data sanitization on every pull request by creating .github/workflows/ztds-audit.yml:

name: ZTDS Zero-Trust Compliance Audit

on:
  push:
    branches: [ main, master ]
  pull_request:
    branches: [ main, master ]

jobs:
  audit:
    name: Verify ZTDS RFC v1.0 Invariants
    runs-on: ubuntu-latest
    steps:
      - name: Checkout Codebase
        uses: actions/checkout@v4

      - name: Setup Node.js Runtime
        uses: actions/setup-node@v4
        with:
          node-version: '20'

      - name: Execute ZTDS Invariant Audit
        uses: moxno/ztds.ai@main
        with:
          dir: './src'
          strict: true

Or run via npx:

npx ztds-audit --dir ./src --strict

4. Empirical AI Safety Benchmark (Frontier LLMs)

Verify cleartext leakage prevention, bijective fidelity, and microsecond latency across OpenAI GPT-4o, Anthropic Claude 3.5 Sonnet, Google Gemini 2.0 Pro, and DeepSeek-V3:

# Execute 25 multi-domain enterprise scenarios across 4 frontier LLM families
npx ztds-bench

# Generate formal Markdown evaluation report & Ed25519 cryptographic certificate
npx ztds-bench --out-report benchmark-report.md --cert
Frontier ModelRaw Egress (No ZTDS)Protected Egress (ZTDS)Leakage Prevention RateBijective Fidelity
openai/gpt-4o100.0%0.00%100.0%100.0%
anthropic/claude-3-5-sonnet100.0%0.00%100.0%100.0%
google/gemini-2.0-pro100.0%0.00%100.0%100.0%
deepseek/deepseek-v3100.0%0.00%100.0%100.0%

Full report: ZTDS AI Safety Benchmark Report (2026)


5. Remediation & Certified Implementation Engines

If ztds-audit detects sensitive credentials, unmasked PII, or third-party telemetry in your AI pipeline, install a certified ZTDS execution engine to achieve instant conformance:

TierPackageLicenseRole & Deployment
Open Reference Core@ztds/coreApache-2.0Vendor-neutral in-memory TypeScript/JS baseline. Universal regex rules (Email, Phone, PAN, SSN, API Keys). Docs
Open Reference MCPztds-mcpApache-2.0Official zero-dependency reference MCP server (io.github.moxno/ztds on Anthropic Registry) for Cursor, Claude Desktop, and Zed. MCP Guide
Certified Pioneer SDK@privacyscrubber/sdkCommercial / Air-GappedHigh-throughput WASM engine with 30 high-ACV industry profiles (HIPAA, PCI-DSS, Legal FRE-502), multi-threaded pipeline bindings, offline Ed25519 node licensing. Get SDK
Air-Gapped IDE MCP@privacyscrubber/mcp-serverCommercial / StdioStdio MCP proxy (io.github.moxno/privacyscrubber-mcp) for Cursor, Windsurf, Claude Code, and autonomous developer agents with 30 enterprise profiles. MCP Guide

6. Ecosystem Demarcation & Neutrality

  • ZTDS.ai (ztds.ai): Independent, vendor-neutral open standard, certification authority, and technical consortium. Governs RFC v1.0 specifications under Apache 2.0 / CC BY 4.0.
  • PrivacyScrubber (privacyscrubber.com): Commercial reference implementation and pioneer engine provider.

7. Intellectual Property & Statutory Governance

  • Patent Application: Israel Patent Office (ILPO) Application No. IL 331905 (System and Method for Client-Side Zero-Trust Data Sanitization and Cryptographic Multi-Party Pipeline Handoff). WIPO DAS Access Code: B17B. Paris Convention international priority locked through 14/09/2027.
  • Registered Trademark: ZTDS™ (ILPO Order #182655957, Classes 9 & 42).
  • Academic DOIs:
  • Author & Founder: Ilya Sibiryakov (BrandMeWeb)

8. License

Licensed under the Apache License, Version 2.0. Copyright 2024–2026 Ilya Sibiryakov (ZTDS AI Consortium / BrandMeWeb).

Reviews

No reviews yet

Be the first to review this server!