Stop your AI app from leaking data.
Three small tools for teams building on Claude: one before the model, one in your data, one after the model. Try each one below. Everything runs in your browser and nothing is sent anywhere.
Customer dana.reyes@northwind.example says checkout fails Retrying with key sk-ant-api03-Zk3vQ9xT2mLp8RwYc5HnJd7A from 10.4.2.19 Card 4242 4242 4242 4242 declined for +1 415-555-0134 Deploy token ghp_a1B2c3D4e5F6g7H8i9J0k1L2m3N4o5P6q7R8 pushed to main
- Open source
- MIT licence, code on GitHub
- Runs on your machine
- No LeakyByte server in the path
- No runtime dependencies
- In the proxy and command line tool
- Tested
- 14 automated tests, run with npm test
Swap secrets for placeholders before a prompt leaves.
1. Your app sends
Edit this text5 sensitive values found
2. Claude receives
Placeholders onlyCustomer Dana Reyes (, ) says checkout fails. Card on file: . Server logs show our key leaking in the stack trace.
3. Your app gets back
Simulated reply, restoredModel saw: Thanks. I'll email ‹EMAIL_1› and rotate ‹ANTHROPIC_KEY_1› right away.
One request, three places to leak
Data leaves an AI app before the model sees it, from the files you hand it, and in what it says back. Each product covers one of those, and they share one detection engine.
Before the model
Veil
A proxy for the Claude API. It swaps API keys and personal data for placeholders on the way out and restores them in the reply.
Setup guide and examples
In your data
Canary
Mint fake keys that look real and plant them in configs, docs and prompts. If one shows up in a log or an output, you know where it leaked from.
Setup guide and examples
After the model
Plug
Scans model output for ways data escapes: image links that carry data in the URL, invisible text, and secrets. It blocks them before your app renders the reply.
Setup guide and examples
Get started in two minutes
You need Node 22.18 or newer. There is no build step and no runtime dependencies for the proxy and CLI.
1. Run the proxy
git clone https://github.com/tcvdh/leakybyte.git
cd leakybyte
npm install
npm run proxy
# LeakyByte proxy on http://127.0.0.1:87872. Point your app at it
Change the base URL. Nothing else in your code changes.
import Anthropic from "@anthropic-ai/sdk";
const client = new Anthropic({
baseURL: "http://127.0.0.1:8787", // Veil proxy
});
// Everything else stays the same.
const msg = await client.messages.create({ ... });import anthropic
client = anthropic.Anthropic(base_url="http://127.0.0.1:8787")Or try it with curl
curl -i http://127.0.0.1:8787/v1/messages \
-H "x-api-key: $ANTHROPIC_API_KEY" \
-H "anthropic-version: 2023-06-01" \
-H "content-type: application/json" \
-d '{"model":"claude-sonnet-5-5","max_tokens":200,
"messages":[{"role":"user","content":"Email dana@acme.io about the outage"}]}'
# The reply has your real address back in it, and the response
# includes the header: x-leakybyte-redacted: 1What Veil detects
- API keys
- Anthropic, AWS, GitHub, generic sk- keys
- Tokens
- JWTs
- Contact details
- Emails, phone numbers
- Financial
- Card numbers (Luhn-checked)
- Identity and network
- US SSNs, IPv4 addresses
Settings
| Variable | Default | What it does |
|---|---|---|
| PORT | 8787 | Port the proxy listens on (127.0.0.1 only). |
| LEAKYBYTE_UPSTREAM | https://api.anthropic.com | Where redacted requests are forwarded. |
| LEAKYBYTE_AUDIT | leakybyte-audit.jsonl | Audit log path. One JSON line per request: time, model, counts per kind. Never the values. |
| LEAKYBYTE_CANARY_KEY | none | Secret string for the Canary CLI. Only you should know it. |
Canary and Plug from the command line
Both run as a CLI today. Pipe any text into them: logs, a model reply, a file. Exit code 2 means a canary was found, so you can use it in CI.
$ npm run lb canary mint prod aws
AKIAPRODC3EDOIU4P2TK
$ echo "env: AWS_ACCESS_KEY_ID=AKIAPRODC3EDOIU4P2TK" | npm run lb canary check
LEAK: aws canary "PROD" at char 28
$ echo 'hi ' | npm run lb plug
hi 
URL: evil.example carries data in the query string
$ npm test
ℹ pass 14 ℹ fail 0Where we are
LeakyByte is early. All three tools work today, in the browser and from a command line. Veil also runs as a local proxy with an audit log. The tests run the proxy against a mock Claude server. We build with Claude Code.
Next
- Run Plug and Canary checks inside the proxy, including on streamed replies
- Detect names and addresses, with Claude as an optional classifier
- A hosted version and a dashboard for the audit log
- Custom detectors per team
- Wider testing against the live Claude API
Questions
- Where does my data go?
- The demos on this page run in your browser and send nothing anywhere. The proxy runs on your machine and forwards redacted requests to the Claude API (or whatever LEAKYBYTE_UPSTREAM points to). Your Anthropic key is passed through and never stored. There is no LeakyByte server in the path.
- What does it not catch?
- Detection is pattern-based. It finds keys, tokens, emails, phone numbers, card numbers, US SSNs and IPv4 addresses. It does not find names, street addresses or free-text personal details. A secret split across two separate text blocks is not matched either.
- Does streaming and tool use work?
- Yes. Veil restores placeholders in streamed text and in streamed tool-call JSON, including when a placeholder is split across chunks. The test suite covers this against a mock Claude server. It has not yet been validated at scale against the live API.
- Is Plug a guarantee?
- No. It blocks the common ways model output carries data out (image and link URLs, hidden characters, secrets). Treat it as one layer, and also set a strict content security policy where you render model output.
- Is this ready for production?
- Not yet. It is early software that runs locally. There is no hosted version, dashboard or access control yet.
Shipping on Claude? Help us shape this.
Tell us what your app sends to the model and what worries you about it. We reply to every message.
Email hello@leakybyte.xyz