Local-first MCP tools for detecting, redacting, restoring, and safely reading sensitive text and files.
Copy the AI prompt to install this server into Claude Code, Cursor, or another agent β or use 1-click editor setup below.
One-click editor setup isnβt available for this listing yet β we donβt have a confirmed install command, and weβd rather show nothing than point your editor at the wrong package or host. Follow the projectβs own setup instructions, linked above.
Inspect callable tools, capabilities, and parameters exposed to AI agents by Securedact MCP.
prepare_for_external_aiMinimal by default
analyze_textMinimal; offsets in `review`; raw values only in enabled debug mode
redact_textMinimal by default; explicit `legacy` mode is sensitive and deprecated
restore_textSingle-use by default; direct mappings require explicit trusted legacy mode
create_safe_copyReturns no mapping or absolute path
securedact_read_fileBlocks protected paths before reading; rejects traversal/symlink/binary; `minimal` by default
The Securedact MCP MCP server provides a local privacy layer for AI workflows. It identifies personal data, GDPR-sensitive information, credentials, API keys, tokens, secrets, and other sensitive content, then evaluates that content against versioned policies. Approved results can be redacted, validated, and returned for downstream use.
The server also provides protected local-file access. Its file-reading tool checks paths before reading, rejects traversal and symlink escapes, blocks protected locations such as .env, and refuses binary files. A safe-copy tool can write approved text or Markdown beneath one configured root without returning a mapping or absolute path.
The project includes a HIPAA Safe Harbor mechanical de-identification aid with an 18-category mapping and US-specific identifier checks. This is a processing aid rather than a compliance certification or replacement for expert determination.
The Securedact MCP MCP server accepts requests from an MCP host over a local stdio process. Detection may use deterministic detectors and contextual detectors, followed by policy evaluation, redaction, and residual-output validation. The normal workflow is prepare_for_external_ai: the host supplies text and a policy, then should forward only sanitized_text when the result status is ok.
Responses default to minimal. Review responses expose locations without raw values, while debug responses can include more sensitive details only when debugging has been enabled before process start. Restoration uses in-memory, opaque sessions with expiration, bounded capacity, concurrency protection, and single-use consumption by default. Sessions disappear when the process exits.
MCP mode is not an automatic prompt interceptor. A host can bypass the workflow or be configured incorrectly, so the server does not by itself guarantee that every prompt, tool call, or file leaves the environment sanitized.
Install Python 3.12 and the package from PyPI:
The setup command checks the package, Python version, dependencies, and local model state. It can offer consent-based model installation and detected Claude Code or Gemini CLI integrations. Manual commands include securedact-mcp install, securedact-mcp models verify, and securedact-mcp to start the stdio server.
Set SECUREDACT_ENABLE_DEBUG_RESPONSES=1 before starting the process to permit debug responses. An MCP request cannot enable debugging. Deterministic-only operation can be demonstrated by setting SECUREDACT_REQUIRE_FLAIR=0.
The Securedact MCP MCP server exposes:
prepare_for_external_ai for the recommended complete preparation flow.analyze_text for lower-level local analysis and review.redact_text for lower-level redaction, with legacy mode deprecated.restore_text for consuming local restoration sessions.create_safe_copy for writing approved .txt or .md content.securedact_read_file for sanitized, guarded local-file reads.The server has no provider client, proxy, website, provider credential handling, or provider-specific forwarding. Local-first processing does not mean every leak is prevented. Sensitive legacy modes require explicit selection, and direct mappings require trusted legacy mode. Debug output should be treated as sensitive.
Factual signals from GitHub, npm, and our automated checks β not a rating.
No reviews yet β be the first to share how this listing worked for you.
Showcase your server listing on GitHub or your project documentation. Embed this dynamic SVG badge to highlight official listing status and live engagement.
[](https://allmcps.com/mcp/securedact-mcp)<a href="https://allmcps.com/mcp/securedact-mcp"><img src="https://allmcps.com/api/badge/securedact-mcp?style=directory" alt="Securedact MCP on AllMCPs" /></a>