Open Source · MIT License · 100% Local · No account · Free

Agent Redactor

Your AI agents never see your secrets. Agent Redactor is a free open source Windows and Linux desktop app that sits between your AI agents and their LLM endpoints as a local proxy redacting PII, credentials and proprietary data from every request, and transparently restoring the original values in every response.

Prefer not to use the Microsoft Store? Enter this in PowerShell:

iex "& { $(irm https://api.agentredactor.negativestarinnovators.com/install.ps1) }"
Agent Redactor masked fox mascot holding a permanent marker

How it works

A transparent firewall for your AI traffic. Your tools talk to localhost. Agent Redactor does the rest.

  1. Redact on the way out. A local ONNX AI model detects PII (names, emails, phone numbers, credentials and more), while your own regex rules and keyword lists catch project-specific secrets. Values become <<REDACTED_PII_1>> style labels.
  2. Forward safely. Only the scrubbed request leaves your machine, with your real API key injected locally at the last moment.
  3. Restore on the way back. Labels in the response even when split across streamed SSE chunks are transparently replaced with the original values. Your workflow never breaks.

Why Agent Redactor?

Trust is verified, not given. Everything runs on your hardware. Neither we nor any third party ever sees your redactions or your LLM traffic.

🤖

On-Device AI Detection

A local ONNX model identifies and redacts names, emails, credentials, account numbers and more. You control the categories and confidence threshold.

🔩

Deterministic Regex Rules

Total control for project-specific data: block internal IPs, proprietary hostnames, customer IDs or unique secret formats with your own patterns.

🔑

Keyword Redaction

Strict, exact-match blocking for specific words, phrases, project names or anything that must never reach a cloud provider.

🔄

Seamless Un-Redaction

Responses are reconstructed automatically including streaming SSE, where redaction labels split across chunks are pieced back together perfectly.

🛡

Keys Stay Local

Real upstream API keys are encrypted on disk and only ever decrypted on your machine, at the moment they're injected into the redacted outbound request. They never sit in agent configs, shell history, or environment variables.

📄

Open Source & Auditable

Free and MIT licensed, with no telemetry. Audit every line of the source on GitHub and verify exactly what leaves your machine.

🌐

Unlimited Profiles

Isolated environments per client, provider or project. Each profile has its own local port, upstream endpoint, rules, stats and logs.

📊

Granular Visibility

Inspect session redaction logs to see exactly what was matched and blocked before it hit the network, with per-profile statistics.

⌨

Fully Scriptable

Every install ships the agentredactor CLI. Manage profiles, regex rules, keywords and PII types from the terminal, check live status and redaction stats, and run headless on Linux servers via a systemd user service. Run agentredactor help in a terminal to get started.

💬

Localized in 53 Languages

The full interface is available in 53 languages, including right-to-left layouts. Switch languages anytime from Settings.

Quick start

Up and running in under two minutes.

  1. Create a profile and assign it a local port, e.g. 8081.
  2. Enter the upstream API endpoint, e.g. https://api.openai.com/v1.
  3. Save your real API key in the profile. It is encrypted and never leaves your machine.
  4. Point your AI agent or IDE at http://localhost:8081 with any dummy API key.
  5. Enable PII categories, regex rules and keywords to match your project.
  6. Check the session redaction logs to verify your data is being scrubbed.

Support the project

Agent Redactor is free and open source. If it saves you from a leaked secret, here are a few ways to give back. Every one of them helps.