A high-performance, enterprise-grade HTTP/HTTPS Data Loss Prevention (DLP) proxy designed to sanitize sensitive information before it reaches external LLM endpoints.
📘 Documentation
Full documentation is available at https://fabriziosalmi.github.io/aidlp/ (or locally via
npm run docs:dev).
The AI DLP Proxy acts as a secure gateway, intercepting traffic to LLM providers (like OpenAI, Anthropic) and redacting sensitive data in real-time using a hybrid approach of static rules and Machine Learning models.
mitmproxy core.en_core_web_sm for speed) ensures minimal latency impact./metrics) and structured JSON logging for integration with Grafana/Loki.The system is built on top of mitmproxy's robust core, extended with a custom Python addon (DLPAddon).
POST requests.DLPEngine.
terms.txt for known secrets.[REDACTED].Clone the repository:
git clone https://github.com/fabriziosalmi/aidlp.git
cd aidlp
Create a virtual environment:
python3 -m venv venv
source venv/bin/activate
Install dependencies:
pip install -r requirements.txt
python -m spacy download en_core_web_lg
Start the proxy:
export PYTHONPATH=$PYTHONPATH:$(pwd)
python src/cli.py start --port 8080
Build and Run:
docker-compose up --build -d
Verify:
curl -x http://localhost:8080 http://httpbin.org/ip
The proxy is configured via config.yaml and terms.txt.
config.yamlproxy:
port: 8080
metrics_port: 9090
ssl_bump: true
dlp:
static_terms_file: "terms.txt"
ml_enabled: true
ml_threshold: 0.5
nlp_model: "en_core_web_lg" # or "en_core_web_sm" for speed
entities: ["PERSON", "PHONE_NUMBER"] # Optional: filter specific entities
secrets_provider:
type: "file" # or "vault"
vault:
url: "http://localhost:8200"
path: "aidlp/terms"
terms.txtAdd one sensitive term per line. The proxy reloads this file automatically on restart (dynamic reload planned).
super_secret_token
internal_db_password
Configure your HTTP client or environment to use the proxy.
Example (cURL):
curl -x http://localhost:8080 \
-X POST http://httpbin.org/post \
-d "My password is super_secret_token"
Output:
{
"data": "My password is [REDACTED]"
}
Prometheus metrics are available at http://localhost:9090/metrics.
dlp_requests_total: Total requests processed.dlp_redacted_total: Requests containing sensitive data.dlp_pii_detected_total: Count of PII entities by type (e.g., EMAIL, PHONE_NUMBER).dlp_token_usage_total: Estimated token usage (input/output).dlp_latency_seconds: Histogram of processing time.dlp_active_connections: Current active connections.Logs are output in structured JSON format to stdout, suitable for ingestion by Fluentd/Logstash.
port or metrics_port in config.yaml.mitmproxy CA.~/.mitmproxy/mitmproxy-ca-cert.pem into your system or browser trust store. For curl, use -k (insecure) for testing.Strategies for deploying AI DLP Proxy in production environments.
For a complete stack including Prometheus and Grafana (optional), use Docker Compose.
version: '3.8'
services:
aidlp:
build: .
ports:
- "8080:8080"
- "9090:9090"
volumes:
- ./config.yaml:/app/config.yaml
- ./terms.txt:/app/terms.txt
# Persist CA certs to avoid regeneration
- ./certs:/root/.mitmproxy
environment:
- VAULT_TOKEN=${VAULT_TOKEN}
Deploy the proxy as a sidecar container in the same Pod as your application.
Deploy as a standalone Service/Deployment.
Recommended: Centralized Gateway for initial rollout to simplify certificate management.
Securely manage your static sensitive terms using HashiCorp Vault.
Enable KV Secrets Engine:
vault secrets enable -path=aidlp kv-v2
Write Secrets:
vault kv put aidlp/terms data='["secret_project_x", "api_key_123"]'
Configure Policy:
Create a policy aidlp-policy.hcl:
path "aidlp/data/terms" {
capabilities = ["read"]
}
Update Config:
In config.yaml:
dlp:
secrets_provider:
type: "vault"
vault:
url: "http://vault:8200"
path: "aidlp/terms"
Content type
Image
Digest
sha256:acd9f8260…
Size
179.1 MB
Last updated
26 days ago
docker pull fabriziosalmi/aidlp