Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them

Details

External ID
46206591
Source
HN
Company
—
Product
Local Privacy Firewall-blocks PII and secrets before ChatGPT sees them
Website domain
github.com
Launched
Dec. 9, 2025
Cohort
—
Upvotes
111
Upvotes percentile
0.9103053435114504
Tags
—
Fetched at
Sept. 7, 2026, 9:25 p.m.
Updated at
Sept. 7, 2026, 9:25 p.m.

Description

OP here.I built this because I recently caught myself almost pasting a block of logs containing AWS keys into Claude.The Problem: I need the reasoning capabilities of cloud models (GPT/Claude/Gemini), but I can't trust myself not to accidentally leak PII or secrets.The Solution: A Chrome extension that acts as a local middleware. It intercepts the prompt and runs a local BERT model (via a Python FastAPI backend) to scrub names, emails, and keys before the request leaves the browser.A few notes up front (to set expectations clearly):Everything runs 100% locally. Regex detection happens in the extension itself. Advanced detection (NER) uses a small transformer model running on localhost via FastAPI.No data is ever sent to a server. You can verify this in the code + DevTools network panel.This is an early prototype. There will be rough edges. I’m looking for feedback on UX, detection quality, and whether the local-agent approach makes sense.Tech Stack: Manifest V3 Chrome Extension Python FastAPI (Localhost) HuggingFace dslim/bert-base-NER Roadmap / Request for Feedback: Right now, the Python backend adds some friction. I received feedback on Reddit yesterday suggesting I port the inference to transformer.js to run entirely in-browser via WASM.I decided to ship v1 with the Python backend for stability, but I'm actively looking into the ONNX/WASM route for v2 to remove the local server dependency. If anyone has experience running NER models via transformer.js in a Service Worker, I’d love to hear about the performance vs native Python.Repo is MIT licensed.Very open to ideas suggestions or alternative approaches.

Enrichment

Theme
proxy, dns, and networking tools
Vertical
Security
Function
Compliance & governance
Audience
B2B
AI stance
AI feature
Project type
Commercial product
Normalized one-liner
block pii and secrets before sending to ai
Manually corrected
False

Could you build this?

Yes It is a client-side browser extension that intercepts text input fields or paste events and masks regex-matched API keys, tokens, and PII before transmission.

Discussion

20 comments analyzed.

Competitors mentioned: GitGuardian, SecureStore, Pihole, Windsurf

Concerns raised: Agent can circumvent restrictions by running commands that output sensitive data to stdout, Environment variables expose credentials when decrypted into memory, Difficult to audit/inspect sensitive data in terminal/local agent contexts, Browser-level solution is stopgap, not proper service-level protection, Future browser changes may break manual security settings

Feature requests: Terminal/environment variable equivalent for credential protection, Windsurf plugin version, Granular permission controls within projects, Browser extension to load unpacked addons easily

Competitors

Other products that read as similar to this one — 116 launches clear the similarity bar, closest 8 shown.

Attention rank: #11 of 117 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 41 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a compliance & governance tool for Media & entertainment yet.