🛡️
PII Masking Studio
by Nimblersoft · ericmaster.ninja
Zero-Trust AI · LOPDP Ecuador · SFD 2026

Zero-Trust PII Masking & Cryptographic Reconstruction

Sanitize personally identifiable information (nombres, cédulas, correos, tarjetas) before sending prompts to external LLMs. Presidio NER replaces sensitive data with salted surrogate tokens, allowing instantaneous client-side restoration.

Presidio Engine (spaCy en + es warm in RAM)
Latency: -- ms
🔒 Entities Detected: 0
💡 Quick-Fill Real-World Presets:
1

Raw Input Text (Original PII)

User prompt containing confidential records & identifiers
Caracteres: 0 Palabras: 0
2

Sanitized Zero-Trust Output

Salted cryptographic surrogate tokens (Safe for LLM egress)
Haga clic en "Enmascarar PII" o seleccione un caso de prueba para generar tokens criptográficos...
Badges: PERSON EMAIL PHONE ID / ORG CREDIT_CARD
3

Stage 3: Downstream LLM Inference & Local Reversible Reconstruction

Demonstrate zero-trust round trip: External model sees tokens only; client restores original data instantly.
Respuesta Generada por el LLM (Tokens Solamente):
Haga clic en "Simular Inferencia LLM" para observar el razonamiento del modelo sobre los tokens enmascarados...
Texto Final Reconstituido en Cliente (100% Cero Fugas):
Haga clic en "Restaurar PII Original" para verificar la desanonimización instantánea en el navegador...

Dynamic Client Integration Snippet

Production-ready code generated live with your active payload and configuration

    
🔐 Salted Deterministic Hashes

Surrogate tokens like [PERSON_3a7f1c08] are generated by taking the first 8 hex characters of a salted SHA-256 hash. Identical entities map to identical tokens across prompts, preserving conversational cohesion for the LLM without leaking raw data.

🇪🇨 Ecuador LOPDP & GDPR Compliance

Conforms to Art. 10 & 37 of Ecuador's Ley Orgánica de Protección de Datos Personales (seguridad y seudonimización) and GDPR Art. 25. Prevents cloud AI providers from logging or training on sensitive citizen and patient identifiers.

⚡ Microsecond Edge Orchestration

Protected by Cloudflare Workers Backend-for-Frontend with strict CORS, rate limiting, and zero exposure of internal microservice secrets in client bundles.