AI Skill Hub 强烈推荐:PrivAiTe 是一款优质的AI工具。AI 综合评分 8.0 分,在同类工具中表现稳健。如果你正在寻找可靠的AI工具解决方案,这是一个值得深入了解的选择。
PrivAiTe 是一款基于 Python 开发的开源工具,专注于 ai-gateway、anonymization、chatgpt-privacy 等核心功能。作为 GitHub 开源项目,它拥有活跃的社区支持和持续的版本迭代,代码完全透明可审计,支持本地部署以保护数据隐私。无论是个人使用还是集成到企业工作流,都能提供稳定可靠的解决方案。
PrivAiTe 是一款基于 Python 开发的开源工具,专注于 ai-gateway、anonymization、chatgpt-privacy 等核心功能。作为 GitHub 开源项目,它拥有活跃的社区支持和持续的版本迭代,代码完全透明可审计,支持本地部署以保护数据隐私。无论是个人使用还是集成到企业工作流,都能提供稳定可靠的解决方案。
# 方式一:pip 安装(推荐)
pip install privaite
# 方式二:虚拟环境安装(推荐生产环境)
python -m venv .venv
source .venv/bin/activate # Windows: .venv\Scripts\activate
pip install privaite
# 方式三:从源码安装(获取最新功能)
git clone https://github.com/crp4222/PrivAiTe
cd PrivAiTe
pip install -e .
# 验证安装
python -c "import privaite; print('安装成功')"
# 命令行使用
privaite --help
# 基本用法
privaite input_file -o output_file
# Python 代码中调用
import privaite
# 示例
result = privaite.process("input")
print(result)
# privaite 配置文件示例(config.yml) app: name: "privaite" debug: false log_level: "INFO" # 运行时指定配置文件 privaite --config config.yml # 或通过环境变量配置 export PRIVAITE_API_KEY="your-key" export PRIVAITE_OUTPUT_DIR="./output"
Self-hosted PII redaction proxy for LLM APIs.
A drop-in LLM proxy that replaces PII before it reaches the provider, including inside tool-call arguments and multimodal content, with zero telemetry.
Told in writing to report its config variables but never their values, Claude Code sent 3 of 4 secrets to its provider anyway: the same secrets also sat in a log file the task had it read. Over that session 23 of 24 planted values reached the provider; through PrivAiTe's agent gateway, 2 of 24. Wire-level captures of real agent sessions, and the two that still get through are documented rather than rounded away: the measurement, what it misses.
You type: "Je m'appelle Marie Dupont, email marie@acme.com"
LLM sees: "Je m'appelle <PERSON_1>, email <EMAIL_ADDRESS_1>"
LLM says: "Bonjour <PERSON_1>, votre email <EMAIL_ADDRESS_1> est noté."
You see: "Bonjour Marie Dupont, votre email marie@acme.com est noté."
PrivAiTe sits between your app and the model provider. It finds names, emails, phones, cards, IBANs, secrets and more, swaps them for stand-ins before anything leaves your machine, and puts the real values back in the reply. Two types are deliberately not put back: both shipped configs mask CREDIT_CARD and redact SECRET (entity overrides), which throws the original away on purpose. Most tools scan only the plain message text; agent traffic hides PII inside tool-call JSON, and that is the gap PrivAiTe closes. Detection runs locally (two engines, Presidio + OpenAI's open privacy-filter model), and the engine runs three ways: standalone proxy, Open WebUI filter, or LiteLLM guardrail.
This is local pseudonymization, not anonymization, and detection is best-effort rather than a guarantee. You remain the data controller. The Threat model spells out exactly what it protects against and what it does not.
Docker (fastest): the detection model is baked in, so it runs offline from the first request.
docker run -d -p 8400:8400 \
-e PRIVAITE_API_KEYS=change-me \
-e OPENAI_API_KEY=sk-... \
ghcr.io/crp4222/privaite
The same image is on Docker Hub too: swap the last line for crp4222/privaite if you prefer pulling from there.
Two keys, two roles: PRIVAITE_API_KEYS is the key your client sends to PrivAiTe (pick any value); OPENAI_API_KEY is your real provider key, which stays in the container and never reaches your client. This exposes gpt-4o-mini and gpt-4o; for any other provider (Ollama, Azure, anything LiteLLM supports), mount a config: configuration.
pip:
```bash pip install privaite
export OPENAI_API_KEY=sk-...
PRIVAITE_API_KEYS=change-me python -m privaite --config privaite.yaml ```
Connect: point any OpenAI-compatible client at http://localhost:8400/v1 with the key change-me. For Open WebUI: Admin → Settings → Connections → OpenAI API, URL http://localhost:8400/v1 (or http://host.docker.internal:8400/v1 if Open WebUI runs in Docker), key = your PRIVAITE_API_KEYS value. Client snippets (curl, Python, Node) are in examples/. Prefer no separate proxy? Use the in-process Open WebUI filter.
Opt-in gateway mode (off by default): your agent CLI points its base URL at PrivAiTe, which scrubs PII and secrets out of each request (tool-call arguments included) with the same local, benchmarked detection, relays whatever auth the CLI itself sends verbatim upstream, and restores the real values in the response, streaming included. The Claude Code path (Anthropic Messages API) is validated live end to end: running against the real Anthropic API with restore disabled proved the provider only ever received placeholders. Codex support is beta (see below). Any OpenAI-compatible app already works through the standard proxy above; the gateway adds the native protocols these CLIs speak.
gateway:
enabled: true
anthropic:
base_url: "https://api.anthropic.com/v1"
pii:
detection_cache:
enabled: true # recommended for agent sessions, see below
ANTHROPIC_BASE_URL=http://localhost:8400 claude
Enable the detection cache when you use the gateway: agent CLIs resend the whole conversation every turn, and without the cache every turn re-scans the entire history (on a large measured session the per-request scrub peaked at 42 s with Claude Code and 72 s with Codex, against a 1 to 3 s median with the cache on). The threat model spells out the memory tradeoff.
Codex (beta). The gateway also exposes /v1/responses (OpenAI Responses API), which is what Codex speaks. That path passes the same test suite but has had less live validation than Claude Code, so it is labeled beta; setup is in docs/gateway.md.
Four things to know before relying on it:
key=value log lines, and the mechanism is secrets inside log output: they are detected on their own and in .env form, and missed once roughly one preceding line of log-shaped context sits in front of them. Never read this as zero leaks.system field and the Responses instructions field pass through as-is, and Claude Code injects your CLAUDE.md and project context there./v1/messages and /v1/responses accept a request that carries no PRIVAITE_API_KEYS value at all, by design, since the only credential in play is the one your CLI sends upstream. The server also binds 0.0.0.0 by default and applies no rate limit, so an exposed port plus gateway mode is an endpoint anyone who can reach it can drive (on your provider account). Bind it to localhost or keep the port off untrusted networks. Whether your provider's terms of service permit that traffic to transit a local proxy is between you and the provider; this is not a provider-supported integration, and API-key mode is the durable path.Full setup, the flow diagram in detail, scanned surface and limits: docs/gateway.md.
integrations/openwebui/privaite_filter.py, enable, pick preset and languages in its valves. Covers message text, tool calls and multimodal.integrations/litellm/privaite_guardrail.py next to your config.yaml to anonymize requests and restore responses inline, including tool-call arguments, which LiteLLM's built-in Presidio guardrail does not scan.Keeping PII out of LLM calls is a crowded space, and PrivAiTe is not always the right pick. Based on each project's public docs as of June 2026:
Where PrivAiTe differs: it anonymizes PII inside tool-call arguments and multimodal content, not just message text (LangChain's gateway docs, for instance, note that tool-call arguments are not scanned), it restores the original values in the response, and it ships a reproducible benchmark. If your traffic is agentic or multimodal, that gap is the reason this exists.
PrivAiTe 是一个专注于隐私保护的 AI 工具,旨在通过高效的脱敏技术,在利用大语言模型(LLM)的同时保护敏感数据。该项目支持多种预设模式,能够平衡隐私保护强度与识别准确度,为开发者提供安全的数据处理能力。
PrivAiTe 默认通过 Privacy Filter 模型识别并替换个人地址(LOCATION)和个人 URL(URL)。为了降低误报率(False Positives),系统默认���会启用 Presidio 中过于宽泛的识别器(如识别普通的城市名“Paris”或“London”),确保在保护隐私的同时,不会过度干扰数据的语义完整性。
您可以通过 pip 进行本地安装:执行 `pip install -e .` 并下载必要的 spacy 模型。若需使用默认的 onnx 预设,系统会在首次启动代理时自动下载模型。若追求更轻量、更快速且无需下载模型的体验,请在配置中将 `preset` 设置为 "light"。此外,您也可以通过 Docker Compose 实现快速部署:使用 `docker compose up -d` 命令即可完成容器化启动。
项目提供了快速启动指南,帮助开发者通过简单的指令快速接入 PrivAiTe 的隐私保护能力,实现从数据输入到脱敏输出的完整流程。
在使用前,请先通过 `cp` 命令将 `.env.example` 复制为 `.env`,并将示例配置文件复制为正式的 `config/privaite.yaml`。您需要在 `.env` 文件中配置相关的 API keys,并在 `config/privaite.yaml` 中指定您所使用的 LLM providers,以确保服务能够正确连接到后端模型。
PrivAiTe 提供与 OpenAI 兼容的 API 接口,支持多种交互模式。包括支持流式与非流式输出的 `POST /v1/chat/completions` 聊天接口、用于文本补全的 `POST /v1/completions` 接口,以及专门用于处理匿名化 Embedding 的 `POST /v1/embeddings` 接口。此外,您还可以通过 `GET /v1/models` 接口查看当前已配置的模型列表。
一个有用的开源AI工具,保护聊天记录隐私
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
✅ BSD 3-Clause — 宽松协议,可商用修改分发,禁止使用原作者名称进行背书宣传。
总体来看,PrivAiTe 是一款质量优秀的AI工具,在同类工具中具备一定竞争力。AI Skill Hub 将持续追踪其更新动态,建议收藏备用,结合自身场景选择合适时机引入使用。
| 原始名称 | PrivAiTe |
| 原始描述 | 开源AI工具:Drop-in self-hosted LLM proxy that reversibly redacts PII before OpenAI, ChatGPT。⭐9 · Python |
| Topics | ai-gatewayanonymizationchatgpt-privacydata-masking |
| GitHub | https://github.com/crp4222/PrivAiTe |
| License | BSD-3-Clause |
| 语言 | Python |
收录时间:2026-07-02 · 更新时间:2026-07-03 · License:BSD-3-Clause · AI Skill Hub 不对第三方内容的准确性作法律背书。