In-depth architectural comparison of the Securedact MCP and Privacyscrubber MCP MCP servers. Compare execution transports, security boundaries, tool capabilities, quality scores, and ready-to-paste client installation snippets for Claude, Cursor, Windsurf, and VS Code.
At a Glance & Executive Verdict
Securedact MCP
Security · Local stdio
Quality: 45/100 (Fair) | Auth: No auth required
Privacyscrubber MCP
Security · Local stdio
Quality: 65/100 (Great) | Auth: API Key required
Verdict Summary: Choose Securedact MCP if you need specialized Security tools running via a local process. Choose Privacyscrubber MCP if your workspace requires Security integration with local subprocess execution. Both servers can be configured concurrently in your client's mcpServers manifest.
Which MCP Server Should You Choose?
Choose Securedact MCP when:
You need dedicated capabilities in the Security domain.
You prefer local stdio subprocess transport architecture.
Your security boundary fits: No auth required (Free / Open Source).
Securedact MCP is categorized under Security and uses a local stdio subprocess. In contrast, Privacyscrubber MCP belongs to Security using local stdio subprocess. Select Securedact MCP when you need capabilities focused on security and Privacyscrubber MCP when you require tools for security.
STEP 0 (Pre-Flight): Non-destructive security inspection of raw prompts or document chunks before sending to LLMs. Evaluates PII, secrets, risk severity (CLEAN, LOW, MODERATE, CRITICAL), and triggered regulatory frameworks (GDPR, HIPAA, SOC 2, PCI DSS) with zero text mutation.
sanitize_text
STEP 1: Call this first. You MUST NOT process raw user data before calling this. Locally scrubs PII, secrets, and credentials (like API keys, passwords, emails, phones, names) from code, logs, or text. Replaces them with safe placeholders (e.g., [EMAIL_1], [API_KEY_1]). Keep your data secure before passing it to any LLM. (For in-code backend services or RAG vector pipelines outside of MCP, use '@privacyscrubber/sdk': npm i @privacyscrubber/sdk)
scrub_text
Alias for 'sanitize_text'. Locally scrubs PII and secrets before LLM ingestion.
reveal_text
STEP 3: Call this last. You MUST pass your final generated response through this tool to restore tokens (e.g., [EMAIL_1]) back with the original private data from the local volatile RAM-only session map before showing it to the user.
sanitize_file
Reads a local file, sanitizes its contents using the selected profile, and outputs the safe version for AI analysis. Securely keeps original identifiers in memory.
scrub_file
Alias for 'sanitize_file'. Reads and sanitizes a local file.
audit_directory_for_pii
Scans a local directory for leaks of secrets, keys, and PII. Returns a summary report. Use this tool for Security Auditing.
redact_file
Action/Redact: In-place redaction of a local file. Replaces PII and secrets with tokens and saves the file. By default, creates a .bak backup. Use dry_run=true to test without modifying.
create_default_config
Creates a default 'privacyscrubber.json' configuration file in the active workspace root directory if one does not exist. Includes template structures for custom regex rules and exclusion bypass patterns.
generate_compliance_report
Generates an official Zero-Trust Compliance Audit Certificate (GDPR, HIPAA, EU AI Act, SOC 2) for the current MCP session. Returns cryptographic session hash, masked entities breakdown, and compliance certification.
mark_false_positive
Marks a previously detected token as a false positive. The original plaintext value will be excluded from all future sanitize_text calls in this session. Returns the restored original value and updated ignore list size.
check_status
Returns the current PrivacyScrubber MCP tier, session usage, available profiles, and PRO upgrade instructions. Call this to see your license status or get setup help.