Tools/PII & Secrets
Live Tool · Open Source

PII & Secrets Scanner

Paste any text — a prompt, log line, config, or RAG document — to detect leaked API keys, tokens, private keys, and personal data (emails, phone numbers, SSNs, credit cards, IPs) before it reaches an LLM. Get a redacted copy in one click.

100% client-side · nothing is uploaded
0 chars

Try a sample

Detected secrets and PII will appear here — grouped by type, with masked examples, fixes, and a redacted copy of your text.

What it detects

Pattern-based detection for the most common ways sensitive data leaks into LLM pipelines. It is a guide, not a guarantee — it can miss obfuscated data and occasionally flag look-alikes, so always review before trusting the output.

Leaked secrets

OpenAI/Google/AWS/GitHub/Slack/Stripe keys, JWTs, private keys, inline credentials, and credentials in URLs.

Personal data

Emails, phone numbers, US SSNs, credit-card numbers (Luhn-checked), and IP addresses.

One-click redaction

Get a sanitized copy with every match replaced by a redaction token, ready to paste safely.