Privacy Core for Secure Global AI Usage
An enterprise security layer that intercepts PII, financial accounts, national IDs, and proprietary secrets before sending prompts to Generative AI / LLM APIs - with 100% exact roundtrip rehydration.
🌱 Open-Source Sustainable Development
🏥 SDG 3: Good Health and Well-Being
Health & Life Sciences
▼
- Mechanism: Scans for and tokenizes Protected Health Information (PHI) - including Medical Record Numbers (MRN), National Prescriber Identifiers (NPI/DEA), clinical diagnostic codes, and healthcare beneficiary numbers (such as US Medicare MBI or Australian Medicare) - before diagnostic summaries, intake notes, or lab inquiries hit third-party LLMs.
- Impact: Enables public health facilities, clinical triage bots, and telemedicine providers to adopt frontier AI workflows while maintaining strict compliance with medical confidentiality mandates (such as HIPAA and national digital health data acts).
- Mechanism: Allows researchers to feed raw clinical symptom sets and epidemiological case narratives through the engine, stripping personal patient indicators while preserving syntactic relationships and biomedical terminology.
- Impact: Unlocks multi-jurisdiction infectious disease modeling and collaborative public-health telemetry without risking cross-border patient data exfiltration or regulatory penalties.
📈 SDG 8: Decent Work and Economic Growth
Financial Inclusion
▼
- Mechanism: Provides a high-throughput, edge-native de-identification layer operating at sub-5ms latency, allowing developers to upgrade legacy backends to generative AI without expensive infrastructure redesigns.
- Impact: Eliminates compliance and latency bottlenecks for startups, digital agencies, and independent developers building AI-assisted enterprise tools.
- Mechanism: Algorithmic Mod-10 (Luhn) card validation, Mod-97 (ISO 7064) IBAN validation, and domestic banking routing checks (e.g., US ABA, Indian IFSC, SEPA) neutralize financial identifiers before prompt transmission.
- Impact: Allows community banks, microfinance institutions, and emerging fintech scaleups to implement AI-driven fraud detection, invoice reconciliation, and customer support without violating PCI-DSS standards or enterprise audit requirements.
🏭 SDG 9: Industry, Innovation, and Infrastructure
Digital Infrastructure
▼
- Mechanism: Operates statelessly inside serverless edge isolates (such as Cloudflare Workers) without requiring multi-gigabyte machine learning models, dedicated GPU hardware, or heavy container runtimes.
- Impact: Democratizes enterprise-grade privacy protection for developers in bandwidth-constrained and low-compute environments, preventing citizen data extraction as global internet adoption expands.
- Mechanism: Open-sources 67 mathematical checksum algorithms, AST pattern extractors, and reversible state-machine logic under the permissive Apache-2.0 license.
- Impact: Supplies foundational, transparent Digital Public Infrastructure (DPI) that universities, sovereign research teams, and local engineering ecosystems can independently inspect, adapt, and run without vendor lock-in.
⚖️ SDG 10: Reduced Inequalities
Global South Parity
▼
- Mechanism: Provides 185 sovereign identity and tax pattern checks covering 109 countries across 9 Canonical Packs, delivering out-of-the-box parity for nations across ASEAN, Africa, Latin America, and South Asia.
- Impact: Counteracts the systemic bias of legacy DLP tools that prioritize Western formats (US SSN, EU VAT) while neglecting Global South citizen identifiers.
- Mechanism: Distributes sovereign data privacy infrastructure at zero cost under an open standard, eliminating the multi-thousand-dollar licensing barriers imposed by legacy enterprise cybersecurity monopolies.
- Impact: Levels the competitive playing field for developers and public entities in emerging economies, enabling them to build sovereign, privacy-compliant AI systems with the same security assurances as multinational tech firms.
🕊️ SDG 16: Peace, Justice, and Strong Institutions
Public Registry Defense
▼
- Mechanism: Intercepts civil registration codes, national voter indices, and foundational citizen identification numbers across 75+ sovereign jurisdictions, replacing them with deterministic surrogates prior to third-party model ingestion.
- Impact: Prevents national digital legal identities from leaking into commercial LLM training corpora, operational telemetry, or vector embeddings, defending public registry infrastructure against bulk surveillance and automated identity theft.
- Mechanism: Enforces cryptographic zero-retention through automated session destruction (
purgeAfterRead) and client-side encryption options, preventing edge nodes or intermediaries from persisting raw logs. - Impact: Upholds the fundamental human right to digital privacy (UN Universal Declaration of Human Rights, Article 12). Public agencies, investigative journalists, and legal researchers can analyze sensitive public policy or whistleblower submissions via frontier AI without compromising sources or institutional confidentiality.
| UN SDG | Target Focus | Core Engine Mechanism | Practical Impact |
|---|---|---|---|
| SDG 3 | 3.8, 3.d |
Intercepts PHI, MRN, NPI, and clinical identifiers before model ingress. | Enables HIPAA-compliant clinical AI adoption and cross-border research. |
| SDG 8 | 8.2, 8.10 |
Checksum validation for PCI-DSS cards, IBANs, and banking codes. | Lowers regulatory compliance barriers for early-stage fintechs and banks. |
| SDG 9 | 9.c, 9.5 |
Stateless sub-5ms edge isolate runtime; Apache-2.0 open-source release. | Delivers open Digital Public Infrastructure (DPI) without GPU/cloud lock-in. |
| SDG 10 | 10.2, 10.3 |
185 rules across 109 countries covering ASEAN, Africa, and Latin America. | Eliminates Global South exclusion inherent in Western-centric legacy DLP tools. |
| SDG 16 | 16.9, 16.10 |
Reversible masking of sovereign IDs with cryptographic zero-retention (purgeAfterRead). |
Protects national identity registries and defends privacy under UN Article 12. |
🎮 Live Interactive API Playground
POST /v1/tokenize & /v1/detokenize⚡ 60-Second Quickstart
Integrate the engine into any LLM application with standard HTTP requests in any language.
Endpoint: De-identification (Tokenize)
Parses prompt text, executes sovereign mathematical checksum validators, and replaces sensitive entities with surrogate tokens. Supports ephemeral in-memory RAM storage (zero disk writes) as well as optional persistent storage via Cloudflare D1.
DB is unbound, session mappings reside purely in volatile RAM with automatic TTL eviction and zero disk persistence. For multi-datacenter global isolates, Cloudflare D1 (or Redis/PostgreSQL) can be optionally bound. Setting "purgeAfterRead": true on detokenize ensures instant cryptographic memory destruction upon first read.
Request Body (JSON)
| Field | Type | Description |
|---|---|---|
| textrequired | string | Raw prompt or payload to de-identify (Max 1MB). |
| categoriesoptional | string[] | Array of Canonical Pack IDs to activate (Max 2). E.g. ["asia_non_sea"]. |
| modeoptional | "structural" | "fpe" | Default: "structural" (Tokens like CARD_1). "fpe" replaces with realistic mocks. |
| customKeywordsoptional | string[] | Array of enterprise terms (e.g. project codenames) to mask as CUSTOM_X. |
| ttlSecondsoptional | number | Session lifetime in seconds (Default: 300, Max: 86400). |
Response (200 OK)
Endpoint: Reversible Detokenization
Rehydrates tokenized output generated by an LLM back into original sensitive values using the session vault.
"purgeAfterRead": true, the engine enforces Zero Data Retention (ZDR). The session token mapping is instantly, cryptographically obliterated from volatile RAM and D1 SQL the exact microsecond it is read. Subsequent attempts to rehydrate using that sessionId fail with 404 session_expired_error. This architecture satisfies stringent Enterprise CISO zero-retention mandates, GDPR Art. 17 (Right to Erasure), and SOC 2 Type II trust criteria.
Request Body (JSON)
| Field | Type | Description |
|---|---|---|
| sessionIdrequired | string | The sessionId received from the original /v1/tokenize call. |
| tokenizedTextrequired | string | The text containing tokens (e.g. LLM output) to restore. |
| purgeAfterReadoptional | boolean |
Zero Data Retention (ZDR) Flag: When set to true, permanently destroys the session mapping immediately upon read. Returns "sessionStatus": "purged". Default: false.
|
Response with ZDR Enforced (200 OK)
Endpoint: System Health
🌐 Canonical Regional Packs Catalog
To maintain the strict sub-5ms SLA guarantee, requests can specify at most 2 Regional Packs per call. Individual country codes (e.g. ["in", "us"]) are rejected.
🌍 Country-Wise Sovereign ID Coverage
The engine provides mathematical checksum verification across 75+ sovereign nations and territories, in addition to universal coverage across 200+ countries for global financial and communication standards.
| Country / Territory | Canonical Pack | Sovereign Identifiers | Validation Algorithm / Engine |
|---|---|---|---|
| 🌐 Global Universal 200+ Countries |
global |
Credit/Debit Cards, IBAN, SWIFT/BIC, IPv4/IPv6, Crypto (BTC, ETH), Secrets | ISO 7064 Mod-97-10, Luhn Checksum, Base58/Bech32, E.164, Regex AST |
| 🇸🇬 Singapore | south_east_asia |
NRIC / FIN, UEN (Unique Entity Number) | Weighted Mod-11 with century prefix offsets (S, T, F, G, M) |
| 🇲🇾 Malaysia | south_east_asia |
MyKad (National Registration Identity) | 12-digit DOB, state code & gender parity validation |
| 🇮🇩 Indonesia | south_east_asia |
NIK (KTP Citizen ID), NPWP (Tax ID) | 16-digit provincial/DOB structure, 15-digit Tax Office algorithm |
| 🇹🇭 Thailand | south_east_asia |
Thai National ID (บัตรประชาชน) | 13-digit weighted Mod-11 checksum formula |
| 🇻🇳 Vietnam | south_east_asia |
CCCD (Citizen Identity Chip Card), MST (Tax) | 12-digit provincial/century/gender code & 10/13-digit tax verify |
| 🇵🇭 Philippines | south_east_asia |
PhilSys PCN, SSS (Social Security Number) | 16-digit PhilID Luhn verification & 10-digit SSS checksum |
| 🇲🇲 Myanmar | south_east_asia |
NRC (National Registration Certificate) | State/Township alphanumeric code structure |
| 🇰🇭 Cambodia | south_east_asia |
Khmer National ID Card | 9-digit sovereign citizen registry verification |
| 🇱🇦 Laos | south_east_asia |
Lao National Citizen Identity Card | 9-digit provincial registry code |
| 🇮🇳 India | asia_non_sea |
Aadhaar, PAN, GSTIN, Voter ID (EPIC) | Verhoeff Dihedral D5 Checksum, Alphanumeric Tax AST, Mod-36 Checksum |
| 🇯🇵 Japan | asia_non_sea |
My Number (マイナンバー / Individual Number) | 12-digit weighted Mod-11 scalar verification |
| 🇰🇷 South Korea | asia_non_sea |
RRN (주민등록번호 / Resident Registration) | 13-digit century/gender coding & Mod-11 check digit |
| 🇨🇳 China | asia_non_sea |
Resident Identity Card (居民身份证) | GB 11643-1999 ISO 7064 Mod 11-2 check character ('X' support) |
| 🇹🇼 Taiwan | asia_non_sea |
National Identification Card (國民身分證) | 10-character letter geographic weighting Mod-10 algorithm |
| 🇭🇰 Hong Kong | asia_non_sea |
HKID (Hong Kong Identity Card) | Weighted Mod-11 check digit algorithm (supports check 'A') |
| 🇸🇦 Saudi Arabia | asia_non_sea |
National ID / Iqama (الهوية الوطنية) | 10-digit citizenship prefix (1/2) & Luhn checksum algorithm |
| 🇦🇪 United Arab Emirates | asia_non_sea |
Emirates ID (بطاقة الهوية) | 15-digit national prefix 784, birth year & Luhn check verification |
| 🇮🇱 Israel | asia_non_sea |
Teudat Zehut (תעודת זהות) | 9-digit Israeli Ministry of Interior Luhn checksum |
| 🇹🇷 Turkey | asia_non_sea |
T.C. Kimlik No (Identity Number) | 11-digit dual Mod-10 cross-parity verification rules |
| 🇰🇿 Kazakhstan | asia_non_sea |
IIN (Individual Identification Number) | 12-digit century/birth date & weighted Mod-11 algorithm |
| 🇵🇰 Pakistan | asia_non_sea |
CNIC (Computerized National Identity Card) | 13-digit NADRA provincial/gender coding |
| 🇺🇸 United States | north_america |
SSN, ABA Routing Number, Medicare MBI | Area code exclusions (no 000, 666, 900+), Federal Reserve Mod-10, CMS MBI |
| 🇨🇦 Canada | north_america |
SIN (Social Insurance Number), Ontario OHIP | 9-digit Employment Canada Luhn check & 10-digit Health Card Luhn |
| 🇲🇽 Mexico | north_america |
CURP, RFC (Tax), NSS (IMSS Social Security) | 18-char RENAPO homonym check, SAT RFC formula, 11-digit Mod-10 |
| 🇩🇴 Dominican Republic | north_america |
Cédula de Identidad y Electoral | 11-digit JCE series Luhn check digit algorithm |
| 🇧🇷 Brazil | south_america |
CPF (Individual Tax), CNPJ (Enterprise Tax) | Receita Federal Two-Stage Mod-11 Checksum (Dual Check Digits) |
| 🇦🇷 Argentina | south_america |
CUIT / CUIL (Código Único de Identificación) | 11-digit AFIP gender/type prefix & Mod-11 check digit |
| 🇨🇱 Chile | south_america |
RUN / RUT (Rol Único Nacional) | Registro Civil Mod-11 verification (supports 'K' check digit) |
| 🇨🇴 Colombia | south_america |
NIT (Número de Identificación Tributaria), Cédula | DIAN Mod-11 prime sequence weighting algorithm |
| 🇵🇪 Peru | south_america |
DNI (Documento Nacional), RUC (Tax) | RENIEC 8-digit format & SUNAT 11-digit Mod-11 verification |
| 🇪🇨 Ecuador | south_america |
Cédula de Identidad y Ciudadanía | 10-digit provincial code & Mod-10 check digit formula |
| 🇺🇾 Uruguay | south_america |
Cédula de Identidad (CI) | 8-digit weighted Mod-10 check digit verification |
| 🇻🇪 Venezuela | south_america |
Cédula de Identidad (V/E/J) | SAIME nationality prefix & citizen sequence |
| 🇧🇴 Bolivia | south_america |
Cédula de Identidad (CI) | SEGIP departmental code & citizen series |
| 🇵🇾 Paraguay | south_america |
Cédula de Identidad (CI) | Identificaciones registry sequence format |
| 🇨🇷 Costa Rica | south_america |
Cédula de Identidad | 9-digit TSE provincial volume/folio sequence |
| 🇵🇦 Panama | south_america |
Cédula de Identidad Personal | Tribunal Electoral provincial/volume/entry format |
| 🇪🇸 Spain | european_union |
DNI (Documento Nacional), NIE (Foreigner) | Mod-23 letter lookup table (TRWAGMYFPDXBNJZSQVHLCKE) |
| 🇮🇹 Italy | european_union |
Codice Fiscale, Partita IVA | Mod-26 odd/even letter parity calculation & 11-digit Mod-10 P.IVA |
| 🇵🇱 Poland | european_union |
PESEL (National ID), NIP (Tax Number) | 11-digit weighted Mod-10 & 10-digit Ministry of Finance Mod-11 |
| 🇳🇱 Netherlands | european_union |
BSN (Burgerservicenummer) | 9-digit Elfproef (11-proof) scalar verification test |
| 🇧🇪 Belgium | european_union |
RRN (Registre National / Rijksregisternummer) | 11-digit Mod-97 verification with century offset checks |
| 🇸🇪 Sweden | european_union |
Personnummer (Personal Identity Number) | 10/12-digit Skatteverket Luhn check digit algorithm |
| 🇵🇹 Portugal | european_union |
NIF (Número de Identificação Fiscal) | 9-digit Autoridade Tributária Mod-11 verification |
| 🇮🇪 Ireland | european_union |
PPSN (Personal Public Service Number) | 7-digits + 1/2 alphabetic checksum verification |
| 🇷🇴 Romania | european_union |
CNP (Cod Numeric Personal) | 13-digit weighted Mod-11 algorithm (constant 279146358279) |
| 🇫🇮 Finland | european_union |
HETU (Henkilötunnus) | Mod-31 remainder character mapping table (0-9, A-Y) |
| 🇩🇪 Germany | european_union |
Steuer-ID (Tax Identification Number) | 11-digit Federal Central Tax Office (BZSt) check digit algorithm |
| 🇫🇷 France | european_union |
Numéro de Sécurité Sociale (NIR) | 15-digit INSEE demographic encoding with Mod-97 key check |
| 🇪🇺 Remaining EU-27 AT, DK, GR, CZ, HU, etc. |
european_union |
CPR, AMKA, Rodné číslo, Taj, etc. | National citizen registries & ISO 7064 tax formats |
| 🇬🇧 United Kingdom | europe_non_eu |
NHS Number, National Insurance Number (NINO) | 10-digit weighted Mod-11 checksum & HMRC prefix/suffix regex AST |
| 🇨🇭 Switzerland | europe_non_eu |
AHV / AVS Number, Enterprise UID | 13-digit country code 756 with EAN-13 check & CHE Mod-11 |
| 🇳🇴 Norway | europe_non_eu |
Fødselsnummer (National ID) | 11-digit dual Mod-11 cross-check digit validation |
| 🇮🇸 Iceland | europe_non_eu |
Kennitala (National Identification Code) | 10-digit weighted Mod-11 & century indicator |
| 🇺🇦 Ukraine | europe_non_eu |
IPN (Individual Tax Number) | 10-digit State Tax Service weighted Mod-11 check |
| 🇷🇸 🇧🇦 🇲🇪 🇲🇰 Balkans Serbia, Bosnia, Montenegro, N. Macedonia |
europe_non_eu |
JMBG (Unique Master Citizen Number) | 13-digit regional weighted Mod-11 check digit formula |
| 🇿🇦 South Africa | africa |
South African National ID Number | 13-digit citizenship, gender & Department of Home Affairs Luhn check |
| 🇪🇬 Egypt | africa |
National ID Card (الرقم القومي) | 14-digit century, governorate, sequence & verification digit |
| 🇷🇼 Rwanda | africa |
National Identity Card (Indangamuntu) | 16-digit NIDA sovereign citizen registry structure |
| 🇰🇪 Kenya | africa |
KRA PIN (Kenya Revenue Authority) | Alphanumeric taxpayer identification structure |
| 🇬🇭 Ghana | africa |
Ghana Card (National Identity Card) | NIA format GHA-xxxxxxxxx-x with check digit |
| 🇺🇬 Uganda | africa |
NIN (National Identification Number) | 14-character NIRA citizen identity format |
| 🇹🇿 Tanzania | africa |
NIDA Identity Number | 20-digit National Identification Authority sequence |
| 🇦🇺 Australia | oceania |
Tax File Number (TFN), Medicare, ABN | ATO 8/9-digit Mod-11, Medicare 10-digit Mod-10, ABN 11-digit Mod-89 |
| 🇳🇿 New Zealand | oceania |
IRD Number (Inland Revenue Department) | 8/9-digit Inland Revenue weighted Mod-11 checksum |
🛡️ SLA Guardrails & Security Limits
| Guardrail | Limit | Breach Status |
|---|---|---|
| Canonical Pack Composition | Maximum 2 Canonical Packs per request | 400 category_limit_exceeded |
| Payload Size Ceiling | 1 Megabyte (1,048,576 bytes) | 413 payload_too_large |
| Country Code Format | Must use Canonical Pack IDs (no ISO country aliases) | 400 invalid_request_error |
| Default Session TTL | 300 seconds (5 minutes) | 404 session_expired_error |