The ZTDS Protocol for Frontier AI Ingestion
A normative architectural specification establishing client-side, in-memory de-identification protocols across Generative AI, RAG pipelines, and Model Context Protocol (MCP) tool execution surfaces.
Internet-Draft Revision History
The ZTDS protocol evolves through iterative public working revisions, incorporating community feedback, academic peer review, and frontier AI execution surfaces.
draft-sibiryakov-ztds-protocol-02
Major Advancements in Revision 02:
- Model Context Protocol (MCP) Surface 3 Integration: Formally specifies the process-isolated MCP stdio daemon executing over OS pipes (`stdin`/`stdout`) in Cursor IDE, Claude Desktop, Windsurf, Zed, and Claude Code CLI.
- 5 Standard MCP JSON-RPC 2.0 Tools: Added normative tool schemas for
ztds_sanitize,ztds_restore,ztds_audit,ztds_reset_session, andztds_status. - Statutory GDPR Article 28 Exemption: Formally grounded zero-subprocessor exclusion under GDPR Recital 26 and EDPB guidelines, confirming that zero network egress renders DPAs legally moot.
- Normative Cryptographic References: Integrated RFC 8032 (Ed25519 offline token verification) and RFC 9116 (security.txt).
draft-sibiryakov-ztds-protocol-01
Incorporated formal mathematical proofs of Theorem 1 (Entropy Conservation) and Theorem 2 (Deterministic Zeroization). Added clinical entity definitions under HIPAA Safe Harbor 45 CFR § 164.514(b) and biometrics taxonomy.
draft-sibiryakov-ztds-protocol-00
Foundational Internet-Draft submission establishing the 4 Core Invariants: Zero External Egress, Deterministic Reversible Tokenization, In-Memory Isolation, and Continuous Compliance with zero SaaS subprocessors.
The 5 Execution Surfaces of ZTDS
Section 4 of draft-02 defines 5 physical boundaries where data sanitization executes in volatile host RAM prior to network socket serialization.
Client-Side Web Application
Executes in volatile browser heap via V8 / WebWorker / WASM with 0.00 bytes server transmission before network serialization.
Browser DOM Interceptor Extension
Manifest V3 background worker and isolated content scripts intercepting user text areas in ChatGPT, Claude, and Gemini in-place.
Process-Isolated MCP Stdio Server
Model Context Protocol stdio daemon for AI IDEs (Cursor, Windsurf, Claude Desktop, Zed) communicating over local OS JSON-RPC pipes.
Headless Runtime SDK & CLI
Embedded middleware for backend microservices, LangChain/LlamaIndex RAG pipelines, and pre-merge CI/CD invariant gates.
Air-Gapped Enclaves & Service Mesh
Hardware-attested execution inside AWS Nitro Enclaves, SCIF defense facilities, and Proxy-WASM filters (Envoy/Istio).
Automated AST Verification
Every surface implements deterministic self-testing confirming Invariant 1 (Zero-Egress) and Invariant 3 (RAM isolation).
npx ztds-audit --strict
IETF IPR Disclosure & Licensing Covenant
In full accordance with IETF BCP 78 and BCP 79 (RFC 8179), the contributor submits this specification with a formal RAND-Z (Royalty-Free / Zero-Royalty) non-assertion covenant for standard-conforming baseline implementations.
- Patent Application: Israel Patent Office Application IL 331905 (filed 14/09/2026, WIPO DAS Access Code:
B17B, international priority through 14/09/2027 under Paris Convention). - Registered Trademark: ZTDS™ registered under ILPO Order #182655957 (Classes 9 & 42).
- Licensing Terms: RFC specification published under Apache 2.0 and Creative Commons Attribution 4.0 International (CC BY 4.0).