ZTDS.ai Open AI Security Standard
PS

PrivacyScrubber

Canonical Reference Implementation

Zero-Server Privacy & Data Sanitization · Headquarters: International

CONFORMANCE STATUS
100% Zero-Egress Verified
VERIFICATION DATE
2026-09-15 (RFC v1.0)
CERTIFICATE ID
ZTDS-CANONICAL-2026-PS-01
AUDIT ATTESTATION
sha256:d02dc6b12...

Organizational Overview & Mandate

The pioneer consumer and enterprise implementation of the ZTDS standard. Operates pure client-side V8/WASM engines in browser extensions and headless SDKs with zero server logging.

As part of the ZTDS verified ecosystem, PrivacyScrubber enforces hardware-isolated and in-memory reversible tokenization to eliminate external cloud intermediary leaks before outgoing prompts reach foundation models.

Certified Compliance Scope

Pure client-side V8/WASM zero-server execution. Zero cloud ingress or egress.

  • Invariant 1 (Zero WAN Egress): High-risk corporate identifiers and domain entities are masked in local RAM prior to WAN transmission.
  • Invariant 2 (Deterministic Tokenization): Syntactic surrogate tokens maintain prompt context for LLMs while private mapping tables remain strictly in volatile memory.
  • Invariant 4 (Zero Subprocessor Chain): Eliminates third-party cloud proxy servers and excludes vendor sub-processor liability under GDPR Article 28.
CASE STUDY GDPR Article 28 Subprocessor Exclusion & ISO/IEC 27001 CC6.7

1,000,000+ Sensitive Entities Sanitized Locally with Zero Server Overhead

Operational Challenge:

Enterprises and knowledge workers need client-side PII protection when pasting data into ChatGPT, Claude, and Gemini, but traditional proxy tools act as centralized honeypots requiring complex DPAs and security audits.

ZTDS Architecture & SDK Integration:

Native WebAssembly (WASM) core running within Chrome MV3 service worker and headless @privacyscrubber/sdk package.

Reference Architecture Snippet Volatile RAM Execution
import { PrivacyScrubberWasmCore } from '@privacyscrubber/sdk/wasm';

// Pure client-side WebAssembly engine — zero cloud ingress/egress
const scrubber = await PrivacyScrubberWasmCore.init();

// Sanitizes 100+ PII / financial tokens in local V8 memory
const result = scrubber.tokenize({
  text: userPastedPrompt,
  preserveFormatting: true,
  strictMode: true
});

// Dispatched directly to LLM endpoint with zero PII
console.log('Sanitized payload:', result.maskedText);
console.log('Perimeter network egress bytes:', result.egressBytes); // 0
Verified Outcome:

100% elimination of cloud proxy server infrastructure costs. Sub-millisecond deterministic tokenization with instant local reversal.

WAN EGRESS
0.00 B
DPA OVERHEAD
0 Days
IN-RAM LATENCY
< 0.4ms
STATUTORY ROI
1M+ Records Protected
TURN-KEY RETAINER $2,500 setup + $500/mo

BrandMeWeb Enterprise AI Safety & GEO Audit Retainer

Get turn-key ZTDS conformance verification, 30-minute CISO DPA exemption memorandums, machine-readable llms.txt knowledge corpuses, and continuous CI/CD audit gates for your enterprise AI workflows.

View Enterprise SOW & Retainer Details →
OFFICIAL TRUST BADGE
ZTDS Verified — PrivacyScrubber

Display the official ZTDS Verified Badge on your corporate website, documentation, or security portal.

<a href="https://ztds.ai/companies/privacyscrubber/" target="_blank" rel="noopener" title="ZTDS Verified Corporate Member">
  <img src="https://ztds.ai/badge/privacyscrubber.svg" alt="ZTDS Verified" width="138" height="22" />
</a>
← Back to All Corporate Adopters Register Your Company →