Server data from the Official MCP Registry
Open standard MCP server for Zero-Trust Data Sanitization (ZTDS RFC v1.0). In-memory PII masking.
About
Open standard MCP server for Zero-Trust Data Sanitization (ZTDS RFC v1.0). In-memory PII masking.
Security Report
2 tools verified · Open access · No issues found
Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.
Remote servers are capped at 8.0 because source code is not available for review. The score reflects endpoint verification only.
How to Install
Add this to your MCP configuration file:
{
"mcpServers": {
"io-github-moxno-ztds": {
"args": [
"-y",
"ztds-mcp"
],
"command": "npx"
}
}
}Documentation
View on GitHubFrom the project's GitHub README.
ztds-audit — Zero-Trust Data Sanitization (ZTDS™ RFC v1.0) Invariant Auditor
The official developer CLI and automated CI/CD auditor for the Zero-Trust Data Sanitization (ZTDS™ RFC v1.0) architecture. Maintained by the ZTDS AI Consortium.
ZTDS™ is an open industry standard governing in-memory data sanitization for artificial intelligence, retrieval-augmented generation (RAG), and Large Language Model (LLM) pipelines.
1. The 4 Fundamental Invariants (RFC v1.0)
Every AI pipeline audited by ztds-audit is verified against the 4 core mathematical and architectural invariants:
- Invariant 1: Zero External Egress Prior to Sanitization: Raw sensitive cleartext (PII, PHI, API secrets, private financial numbers) must never cross the local execution boundary prior to reversible surrogate tokenization.
- Invariant 2: Deterministic Reversible Tokenization: Semantic, syntactic, and structural context must be preserved for LLM reasoning while de-identification lookup tables remain strictly in local host volatile memory.
- Invariant 3: Cryptographic & In-Memory Isolation: Operations run in volatile heap or hardware-attested enclaves (WASM, Nitro Enclaves, C-ABI) with zero unencrypted disk spill and immediate memory zeroization.
- Invariant 4: Continuous Subprocessor Exclusion: Local client-side execution eliminates third-party transmission, legally exempting deployments from GDPR Article 28 data processing agreements (Zero-DPA).
2. Quickstart
Run a zero-install security and invariant audit across your codebase or AI agent repository:
npx ztds-audit --dir ./src --strict
Command-Line Flags
| Flag | Description | Default |
|---|---|---|
-d, --dir <path> | Target directory to audit | Current working directory |
--json | Output structured machine-readable JSON report | false |
--strict | Fail build on any low-severity or informational finding | false |
-h, --help | Display CLI options and usage | N/A |
Example Output
[ZTDS] ZTDS.ai In-Memory Codebase Auditor (RFC v1.0 Conformance)
----------------------------------------------------------------------
Directory: /home/runner/work/ai-agent/src
Files Scanned: 48 files in 18ms
Audit Hash: sha256:7f83b1657ff1fc53b92dc18148a1d65dfc2d4b1fa3d677284addd200126d9069
----------------------------------------------------------------------
[PASS] CONFORMANCE CONFIRMED: 0 INVARIANT VIOLATIONS DETECTED
All scanned files comply with ZTDS Invariant 1 (Zero-Egress) and Invariant 3 (RAM isolation).
[LEGAL STATUS] Qualifies for GDPR Article 28 DPA Exemption (Zero-Subprocessor Chain)
[PERFORMANCE] 0.00 Bytes Sensitive WAN Egress | Pure In-Memory Execution
Next Steps for Builders & Maintainers:
1. Include this audit hash in your pull request: https://ztds.ai/apply/
2. Embed your Verified Trust Badge in README.md to claim your registry backlink:
[](https://ztds.ai/registry/)
3. GitHub Actions CI/CD Integration
Enforce zero-trust data sanitization on every pull request by creating .github/workflows/ztds-audit.yml:
name: ZTDS Zero-Trust Compliance Audit
on:
push:
branches: [ main, master ]
pull_request:
branches: [ main, master ]
jobs:
audit:
name: Verify ZTDS RFC v1.0 Invariants
runs-on: ubuntu-latest
steps:
- name: Checkout Codebase
uses: actions/checkout@v4
- name: Setup Node.js Runtime
uses: actions/setup-node@v4
with:
node-version: '20'
- name: Execute ZTDS Invariant Audit
uses: moxno/ztds.ai@main
with:
dir: './src'
strict: true
Or run via npx:
npx ztds-audit --dir ./src --strict
4. Empirical AI Safety Benchmark (Frontier LLMs)
Verify cleartext leakage prevention, bijective fidelity, and microsecond latency across OpenAI GPT-4o, Anthropic Claude 3.5 Sonnet, Google Gemini 2.0 Pro, and DeepSeek-V3:
# Execute 25 multi-domain enterprise scenarios across 4 frontier LLM families
npx ztds-bench
# Generate formal Markdown evaluation report & Ed25519 cryptographic certificate
npx ztds-bench --out-report benchmark-report.md --cert
| Frontier Model | Raw Egress (No ZTDS) | Protected Egress (ZTDS) | Leakage Prevention Rate | Bijective Fidelity |
|---|---|---|---|---|
openai/gpt-4o | 100.0% | 0.00% | 100.0% | 100.0% |
anthropic/claude-3-5-sonnet | 100.0% | 0.00% | 100.0% | 100.0% |
google/gemini-2.0-pro | 100.0% | 0.00% | 100.0% | 100.0% |
deepseek/deepseek-v3 | 100.0% | 0.00% | 100.0% | 100.0% |
Full report: ZTDS AI Safety Benchmark Report (2026)
5. Remediation & Certified Implementation Engines
If ztds-audit detects sensitive credentials, unmasked PII, or third-party telemetry in your AI pipeline, install a certified ZTDS execution engine to achieve instant conformance:
| Tier | Package | License | Role & Deployment |
|---|---|---|---|
| Open Reference Core | @ztds/core | Apache-2.0 | Vendor-neutral in-memory TypeScript/JS baseline. Universal regex rules (Email, Phone, PAN, SSN, API Keys). Docs |
| Open Reference MCP | ztds-mcp | Apache-2.0 | Official zero-dependency reference MCP server (io.github.moxno/ztds on Anthropic Registry) for Cursor, Claude Desktop, and Zed. MCP Guide |
| Certified Pioneer SDK | @privacyscrubber/sdk | Commercial / Air-Gapped | High-throughput WASM engine with 30 high-ACV industry profiles (HIPAA, PCI-DSS, Legal FRE-502), multi-threaded pipeline bindings, offline Ed25519 node licensing. Get SDK |
| Air-Gapped IDE MCP | @privacyscrubber/mcp-server | Commercial / Stdio | Stdio MCP proxy (io.github.moxno/privacyscrubber-mcp) for Cursor, Windsurf, Claude Code, and autonomous developer agents with 30 enterprise profiles. MCP Guide |
6. Ecosystem Demarcation & Neutrality
- ZTDS.ai (
ztds.ai): Independent, vendor-neutral open standard, certification authority, and technical consortium. Governs RFC v1.0 specifications under Apache 2.0 / CC BY 4.0. - PrivacyScrubber (
privacyscrubber.com): Commercial reference implementation and pioneer engine provider.
7. Intellectual Property & Statutory Governance
- Patent Application: Israel Patent Office (ILPO) Application No. IL 331905 (System and Method for Client-Side Zero-Trust Data Sanitization and Cryptographic Multi-Party Pipeline Handoff). WIPO DAS Access Code: B17B. Paris Convention international priority locked through 14/09/2027.
- Registered Trademark: ZTDS™ (ILPO Order #182655957, Classes 9 & 42).
- Academic DOIs:
- Zenodo: 10.5281/zenodo.22058770
- Open Science Framework (OSF): 10.17605/OSF.IO/5BYJF
- SSRN: 7335581
- Author & Founder: Ilya Sibiryakov (BrandMeWeb)
8. License
Licensed under the Apache License, Version 2.0. Copyright 2024–2026 Ilya Sibiryakov (ZTDS AI Consortium / BrandMeWeb).
Reviews
No reviews yet
Be the first to review this server!
More Developer Tools MCP Servers
Git
Freeby Modelcontextprotocol · Developer Tools
Read, search, and manipulate Git repositories programmatically
Fetch
Freeby Modelcontextprotocol · Developer Tools
Web content fetching and conversion for efficient LLM usage
Worldmonitor
Freeby Koala73 · Developer Tools
Live markets, conflicts, country risk, chokepoints, energy, and China decision signals. 86 tools.
Paperclip
Freeby Paperclipai · Developer Tools
Trending hip-hop artist momentum scores across four cultural dimensions.
Toleno
Freeby Toleno · Developer Tools
Toleno Network MCP Server — Manage your Toleno mining account with Claude AI using natural language.
mcp-creator-python
Freeby mcp-marketplace · Developer Tools
Create, build, and publish Python MCP servers to PyPI — conversationally.
