The Zero-Knowledge AI Privacy Middleware.

Harness the power of Cloud LLMs without leaking a single byte of PII. Local redaction. Offline storage. Automated restoration.

Keystone Terminal

_
The Risk

Sending raw PII, PHI, or API keys directly to Cloud AI breaches GDPR, SOC2, and trust. Every API call is a potential data leak, exposing your users and your company to massive compliance and reputational risk.

The Keystone Solution

A local-first, air-gapped redaction engine that runs entirely on your infrastructure. Keystone acts as a self-hosted privacy firewall, ensuring sensitive data is redacted before it ever leaves your machine. Finally, a true private AI solution where your data stays with you, not a third-party cloud.

Built for Trust and Performance

Keystone is more than a redaction tool; it's a complete privacy framework designed for developers.

Local SQLite Persistence

Zero cloud databases. All API keys, forensic audit logs, and vault mappings are stored locally in a high-performance, embedded SQLite database.

OWASP Compliant Local API

Your self-hosted instance runs a fully OWASP-compliant API. Passed the rigorous ZAP security audit, ensuring zero structural vulnerabilities in your local environment.

Local Automation (n8n)

Build secure AI workflows instantly with our custom, self-hosted n8n nodes for drag-and-drop privacy automation that runs entirely on your infrastructure.

Local Forensic Logging

Every redaction is captured in a local, cryptographically-hashed audit log. Get total traceability for compliance without your log data ever leaving your control.

[100% Transparent]. No Black Boxes. Total Explainability.

Every redaction is forensically logged, hashed, and tracked. You know exactly what sensitive data was captured, which policy triggered it, and when it was mathematically restored. Your compliance team will love this.

T=4ms[POLICY: FINANCIAL]

Ingestion & Policy Match

Sensitive data is identified and mapped to a secure, reversible placeholder.

Detected: "Visa ending in 4242" -> Mapped to [CARD_1] in 4.2ms

T=15ms[NETWORK: OUTBOUND]

Air-Gapped Request to OpenAI

Transmitting zero-knowledge payload. Original data securely stored in local SQLite Vault.

Local Overhead: 15.1ms. Awaiting Model response...

T=68ms[RESTORE: SUCCESS]

Cryptographic Restoration

LLM response received. Vault lock released. Data restored seamlessly.

Network Latency: 49ms | Local Restoration: 3.8ms | Total Overhead: 68.1ms

Built for High-Compliance Teams.

Whether you are protecting patient records or financial data, Keystone unlocks Cloud LLMs without compromising your compliance posture.

Health-Tech & Clinics

Safely summarize patient notes and medical records with Cloud AI. Keystone’s local redaction ensures Zero Protected Health Information (PHI) ever leaves your HIPAA-compliant environment.

Fintech & Accounting

Analyze support tickets and financial reports via LLMs without risking GLBA or PCI-DSS violations. Credit card numbers and bank details are mathematically air-gapped from OpenAI.

Enterprise DevOps & Legal

Process server error logs or massive legal contracts through AI without accidentally leaking raw API keys, passwords, or attorney-client privileged information into the cloud.

Zero-Knowledge Automations. Zero Code Required.

Don't want to build from scratch? Integrate Keystone directly into your existing automation pipelines with our custom, self-hosted n8n nodes.

  • Drop-in Nodes: Instantly add `Keystone Redact` and `Keystone Restore` to any workflow.
  • Compliant by Default: Build GDPR-compliant Gmail-to-OpenAI auto-responders in minutes.

Install in 3 Clicks:

1

Open your n8n dashboard and navigate to Settings.

2

Click on Community Nodes and select 'Install'.

3

Search for n8n-nodes-keystone and click 'I Agree'.

Webhook Trigger

Receives Raw Patient Data

Keystone Redact

Air-gaps PII & Vaults SSN

OpenAI Chat

Analyzes Safe Placeholders

Keystone Restore

Unlocks Vault & Restores Original Data

GDPR & Audit-Ready Logs

Built-in forensic cryptographic hashing provides total traceability for both GDPR and SOC2 compliance audits.

GDPR-Friendly Architecture

Zero personal data leaves your local machine. Fully air-gapped redaction ensures it never hits third-party APIs.

Zero-Knowledge by Design

Open-source transparency. Keystone cannot see, store, or transmit your decrypted Vault mappings.