# Securedact MCP [Health: Active]

**Category:** 🔒 Security  
**Repository:** https://github.com/GigantesHJI/securedact-mcp  
**GitHub Stars:** 2  
**Views:** 1  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/securedact-mcp

## Description
Local-first privacy MCP server for sensitive AI workflows

## Tools
Capabilities this server exposes over MCP:

- **prepare_for_external_ai** — Minimal by default
- **analyze_text** — Minimal; offsets in `review`; raw values only in enabled debug mode
- **redact_text** — Minimal by default; explicit `legacy` mode is sensitive and deprecated
- **restore_text** — Single-use by default; direct mappings require explicit trusted legacy mode
- **create_safe_copy** — Returns no mapping or absolute path
- **securedact_read_file** — Blocks protected paths before reading; rejects traversal/symlink/binary; `minimal` by default

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "securedact-mcp": {
    "command": "npx",
    "args": ["-y","securedact-mcp"]
  }
}
```

## Documentation

## What the Securedact MCP MCP server does

The Securedact MCP MCP server provides a local privacy layer for AI workflows. It identifies personal data, GDPR-sensitive information, credentials, API keys, tokens, secrets, and other sensitive content, then evaluates that content against versioned policies. Approved results can be redacted, validated, and returned for downstream use.

The server also provides protected local-file access. Its file-reading tool checks paths before reading, rejects traversal and symlink escapes, blocks protected locations such as `.env`, and refuses binary files. A safe-copy tool can write approved text or Markdown beneath one configured root without returning a mapping or absolute path.

The project includes a HIPAA Safe Harbor mechanical de-identification aid with an 18-category mapping and US-specific identifier checks. This is a processing aid rather than a compliance certification or replacement for expert determination.

## How it works

The Securedact MCP MCP server accepts requests from an MCP host over a local stdio process. Detection may use deterministic detectors and contextual detectors, followed by policy evaluation, redaction, and residual-output validation. The normal workflow is `prepare_for_external_ai`: the host supplies text and a policy, then should forward only `sanitized_text` when the result status is `ok`.

Responses default to `minimal`. Review responses expose locations without raw values, while debug responses can include more sensitive details only when debugging has been enabled before process start. Restoration uses in-memory, opaque sessions with expiration, bounded capacity, concurrency protection, and single-use consumption by default. Sessions disappear when the process exits.

MCP mode is not an automatic prompt interceptor. A host can bypass the workflow or be configured incorrectly, so the server does not by itself guarantee that every prompt, tool call, or file leaves the environment sanitized.

## Setup and configuration

Install Python 3.12 and the package from PyPI:

```bash
python3.12 -m pip install "securedact-mcp[ml]"
securedact-mcp setup
```

The setup command checks the package, Python version, dependencies, and local model state. It can offer consent-based model installation and detected Claude Code or Gemini CLI integrations. Manual commands include `securedact-mcp install`, `securedact-mcp models verify`, and `securedact-mcp` to start the stdio server.

Set `SECUREDACT_ENABLE_DEBUG_RESPONSES=1` before starting the process to permit debug responses. An MCP request cannot enable debugging. Deterministic-only operation can be demonstrated by setting `SECUREDACT_REQUIRE_FLAIR=0`.

## Tools and capabilities

The Securedact MCP MCP server exposes:

- `prepare_for_external_ai` for the recommended complete preparation flow.
- `analyze_text` for lower-level local analysis and review.
- `redact_text` for lower-level redaction, with legacy mode deprecated.
- `restore_text` for consuming local restoration sessions.
- `create_safe_copy` for writing approved `.txt` or `.md` content.
- `securedact_read_file` for sanitized, guarded local-file reads.

## Limitations and notes

The server has no provider client, proxy, website, provider credential handling, or provider-specific forwarding. Local-first processing does not mean every leak is prevented. Sensitive legacy modes require explicit selection, and direct mappings require trusted legacy mode. Debug output should be treated as sensitive.

_Full upstream README: https://allmcps.com/mcp/securedact-mcp/readme_

