In-depth architectural comparison of the Privacyscrubber MCP and WhitePact MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Privacyscrubber MCP
Security · Local stdio
Quality: 65/100 (Great) | Auth: API Key required
WhitePact
Security · Local stdio
Quality: 53/100 (Good) | Auth: No auth required
Verdict Summary: Choose Privacyscrubber MCP if you need specialized Security tools running via a local process. Choose WhitePact if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Privacyscrubber MCP when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: API Key required (Freemium).
STEP 0 (Pre-Flight): Non-destructive security inspection of raw prompts or document chunks before sending to LLMs. Evaluates PII, secrets, risk severity (CLEAN, LOW, MODERATE, CRITICAL), and triggered regulatory frameworks (GDPR, HIPAA, SOC 2, PCI DSS) with zero text mutation.
sanitize_text
STEP 1: Call this first. You MUST NOT process raw user data before calling this. Locally scrubs PII, secrets, and credentials (like API keys, passwords, emails, phones, names) from code, logs, or text. Replaces them with safe placeholders (e.g., [EMAIL_1], [API_KEY_1]). Keep your data secure before passing it to any LLM. (For in-code backend services or RAG vector pipelines outside of MCP, use '@privacyscrubber/sdk': npm i @privacyscrubber/sdk)
scrub_text
Alias for 'sanitize_text'. Locally scrubs PII and secrets before LLM ingestion.
reveal_text
STEP 3: Call this last. You MUST pass your final generated response through this tool to restore tokens (e.g., [EMAIL_1]) back with the original private data from the local volatile RAM-only session map before showing it to the user.
Ready-to-Paste Client Configurations
Paste either (or both) of these JSON server blocks into your client config file (e.g. claude_desktop_config.json or ~/.cursor/mcp.json).
Privacyscrubber MCP is categorized under Security and uses a local stdio subprocess. In contrast, WhitePact belongs to Security using local stdio subprocess. Select Privacyscrubber MCP when you need capabilities focused on security and WhitePact when you require tools for security.
Reads a local file, sanitizes its contents using the selected profile, and outputs the safe version for AI analysis. Securely keeps original identifiers in memory.
scrub_file
Alias for 'sanitize_file'. Reads and sanitizes a local file.
audit_directory_for_pii
Scans a local directory for leaks of secrets, keys, and PII. Returns a summary report. Use this tool for Security Auditing.
redact_file
Action/Redact: In-place redaction of a local file. Replaces PII and secrets with tokens and saves the file. By default, creates a .bak backup. Use dry_run=true to test without modifying.
create_default_config
Creates a default 'privacyscrubber.json' configuration file in the active workspace root directory if one does not exist. Includes template structures for custom regex rules and exclusion bypass patterns.
generate_compliance_report
Generates an official Zero-Trust Compliance Audit Certificate (GDPR, HIPAA, EU AI Act, SOC 2) for the current MCP session. Returns cryptographic session hash, masked entities breakdown, and compliance certification.
mark_false_positive
Marks a previously detected token as a false positive. The original plaintext value will be excluded from all future sanitize_text calls in this session. Returns the restored original value and updated ignore list size.
check_status
Returns the current PrivacyScrubber MCP tier, session usage, available profiles, and PRO upgrade instructions. Call this to see your license status or get setup help.
+11 more tools listed on main page
WhitePact Tools (27)
rai_scan
Detect and redact PII + harmful content before it reaches a log
rai_trust_score
Composite AI Trust Score (0-100) across 6 governance dimensions
rai_compliance
NIST AI RMF / EU AI Act / ISO 42001 compliance evaluation
rai_hallucination
Hallucination risk from hedging, consistency, unsupported claims