PII & Secrets Scanner
Paste any text — a prompt, log line, config, or RAG document — to detect leaked API keys, tokens, private keys, and personal data (emails, phone numbers, SSNs, credit cards, IPs) before it reaches an LLM. Get a redacted copy in one click.
Try a sample
Detected secrets and PII will appear here — grouped by type, with masked examples, fixes, and a redacted copy of your text.
What it detects
Pattern-based detection for the most common ways sensitive data leaks into LLM pipelines. It is a guide, not a guarantee — it can miss obfuscated data and occasionally flag look-alikes, so always review before trusting the output.
Leaked secrets
OpenAI/Google/AWS/GitHub/Slack/Stripe keys, JWTs, private keys, inline credentials, and credentials in URLs.
Personal data
Emails, phone numbers, US SSNs, credit-card numbers (Luhn-checked), and IP addresses.
One-click redaction
Get a sanitized copy with every match replaced by a redaction token, ready to paste safely.