Stop sensitive customer PII, internal API keys, and corporate trade secrets from leaking to external model providers. Reversible surrogate tokenization protects your data with zero prompt degradation and no false-positive business jargon blocking.
Traditional regex filters aggressively block harmless queries and break agent reasoning. TokenShield implements the industry-proven Web Application Firewall learning lifecycle.
Deploy TokenShield as a passive shadow proxy. Telemetry, PII detections, and token appearances are recorded to an encrypted shadow vault without modifying or dropping any prompts.
Our recommendation engine classifies observed detections into Critical Secrets (100% confidence), Structured PII (98%), and automatically flags business jargon as safe allowlists.
Review machine suggestions and promote them to active protection with 1 click. Switch from Observe to Enforce mode safely with complete cryptographic audit logging.
Built from the ground up for high-concurrency multi-agent architectures running across OpenAI, Claude, DeepSeek, and local Ollama clusters.
PII is substituted with cryptographically secure surrogate tokens. The original plaintext is stored in an isolated PostgreSQL vault, never exposed over the wire.
Dual-engine intelligence combines blazing-fast regex pattern matching with state-of-the-art Named Entity Recognition running locally without external cloud telemetry.
Designed to meet strict ISO 27001, NIST 800-53, GDPR, PIPEDA, CCPA, and EU AI Act High-Risk System traceability standards with immutable audit logs.
Asynchronous pipeline interceptor optimized in Cython and asyncpg for high-throughput streaming prompts with negligible TTFT impact.
Drop-in OpenAI proxy format works seamlessly with LangChain, LlamaIndex, PydanticAI, AutoGen, CrewAI, or raw HTTP client requests.
Deploy as a cloud SaaS proxy or self-host as a native container inside your sovereign private network or Podman VM node.
Simply redirect your LLM base URL to TokenShield or install our lightweight client interceptor.
Point your standard OpenAI SDK or environment variable to TokenShield's intelligent gateway:
# Direct proxy endpoint:
export OPENAI_BASE_URL="https://tokenshield.ntrust.ai/v1"
export OPENAI_API_KEY="ts_live_your_tokenshield_key"
# All outgoing prompts will be sanitized before hitting OpenAI!Wrap any LLM client with local client-side scrubbing:
from core.token_shield import TokenShieldEngine
shield = TokenShieldEngine(org_id="my_org", mode="observe")
clean_prompt, tokens = shield.sanitize(user_input)
# Query LLM with clean_prompt, then de-tokenize response:
raw_response = llm.generate(clean_prompt)
user_output = shield.desanitize(raw_response, tokens)Start in passive Observe Mode today. Zero risk, instant payload telemetry, and automated policy recommendations tailored to your organization.