Pilotfish is a small proxy that sits between your app and an LLM. It replaces emails, phone numbers, cards and other personal data with placeholders before the prompt leaves your infrastructure, then puts the real values back into the reply.
Your product sends customer messages, tickets or documents to a model. Pilotfish keeps names and contact details out of the provider's logs without changing your prompts.
You need to show that identifiers do not reach a third party. The code is short enough to audit, and nothing is written to disk by default.
Run it as a container inside your network. Your LLM provider key stays with you and is never stored by the proxy.
Same value, same placeholder, so the model can still reason about who is who.
Detects personal data and swaps it for tokens like [EMAIL_1]. The mapping stays on your side.
The model only sees the placeholders and answers as usual. Use any provider.
Placeholders in the answer are swapped back to the real values before your user sees it.
POST /v1/chat redacts, calls the model, and restores the answer. The mapping lives in memory for that single request and is dropped afterwards. Bodies are never logged.
Detection is pattern-based and probabilistic. A value that does not look like a known pattern will pass through. Review it against your own threat model before using it with regulated data.
Names and street addresses are not caught yet. Add an NER detector in pilotfish/core.py.