Free
$0 forever
For one developer protecting their own credentials
- API keys, AWS keys, JWT and Bearer tokens
- Private keys (PEM), GitHub tokens
- Crypto wallets, IBAN
- macOS, Linux and Windows builds
- No account, no card, no payment step
Local data-loss prevention for AI tools
In one ordinary development session, with full detection on, we logged 669 secrets heading out to an LLM — API keys, database passwords, client emails. Two out of three outbound requests carried something that should never have left the laptop. Nobody was careless. That’s just what happens when you paste a stack trace under pressure.
macOS · Linux · Windows — installs in 2 minutes, no licence needed
Measured in a single real local development session.
Try it right here
Edit the text below — it’s a real-looking prompt with real-looking secrets. Switch protection on and watch what gets stripped before it reaches the model.
Simplified in-browser demonstration. Nothing you type here is sent anywhere — this page has no backend. The real proxy runs on your machine with 50+ patterns and an optional local AI model.
What’s actually at stake
API keys, JWT and Bearer tokens, AWS credentials, SSH and PEM private keys. Pasted inside an error log or a config fragment, they leave in seconds and stay in someone else’s storage.
Card numbers, IBANs, crypto wallet addresses, payment keys. They show up in test data and support tickets far more often than anyone expects.
Names, emails, phone numbers, addresses. Under GDPR this isn’t a slip — it’s a reportable event, and the person who pasted it usually never realises it happened.
Contract text, internal notes, database passwords, infrastructure details. Shared AI chats have already turned up in search results. This isn’t hypothetical.
How it works
LocalGuard is a proxy that runs on your own machine. Your tools talk to it instead of talking to the model directly. It scans, masks, forwards — then restores the real values in the answer that comes back.
Claude Code, Cursor, Copilot, a script, your own integration — anything that speaks HTTP to an LLM API.
Two stages: fast pattern matching, plus an optional local AI model for names, places and context. Under 50 ms.
A key becomes <REDACTED:api_key:1>. The structure survives, so the model still understands what it’s looking at.
Real values are restored on the way back to you. Your workflow doesn’t change; the provider just never saw them.
The app itself
Install it, click Configure next to your agent, and it is protecting. After that you open it when you want to know what was actually leaving — everything below is the shipping app, not a mock-up.
What it catches
Detection is split into two levels. The first works from the moment you install. The second unlocks inside the app when you decide you need it.
No licence, no account, no payment step
Turn it on when you start handling client and financial data
Secrets hidden with base64, zero-width characters or look-alike Unicode are decoded and normalised before scanning — so the tricks that slip past plain-regex DLP still get caught here.
From the same session
Screenshots of a real proxy run — not mock-ups. Click any of them to inspect the full-size image.
Why you can trust it
Scanning happens on your machine. No cloud service, no analytics endpoint, no copy of your traffic anywhere. A privacy tool that phones home is not a privacy tool.
Chosen for speed and memory safety. Under 50 ms added per request, including the optional model — you won’t feel it in your editor.
Not a weekend wrapper around a regex list. The source is closed, but enterprise customers get everything an independent reviewer needs for their own audit.
Works with
Claude Code, Cursor, GitHub Copilot, ChatGPT, your own API integrations, internal scripts. Point the endpoint at the local proxy and you’re done — no plugin, no extension, no changes to how you work.
What it costs
There’s one price and it’s on this page, so you never have to call anyone to hear it. You can ignore the paid tier until you decide you need it.
Against what
Competitor prices as published on their own pricing pages, checked 5 August 2026. Those are team platforms with admin policy and audit trails; LocalGuard Pro protects one machine. If you only ever paste your own keys and tokens, the free level is the honest answer — and it stays free.
$0 forever
For one developer protecting their own credentials
$39 per year
For anyone whose prompts touch client or financial data
Everything in Free, plus
Renews annually, cancel any time. Bound to one machine — install the app first and copy the fingerprint from the License panel.
Talk to us per organisation
For a team that cannot install software on every laptop
Prices in US dollars, charged by Stripe. We make no claim about how much any particular installation will detect — the figures on this page are measurements, not promises.
Questions
Yes. The proxy runs locally, intercepts the HTTP request and strips sensitive values before anything is sent to the provider. There’s no moment where the raw text sits on someone else’s server.
No. Scanning takes under 50 ms per request, including the optional local AI model. In an editor that’s invisible.
Yes — any tool that sends HTTP requests to an LLM API. You point the API endpoint through the local proxy and everything else stays as it was.
Yes, and this is the part people worry about most. Placeholders like <REDACTED:email:1> preserve the semantic structure — the model knows an email was there, it just doesn’t get the address.
No. Everything runs on your machine. No cloud, no telemetry, nothing leaves for analysis. That’s the entire design constraint.
The source is closed. For enterprise customers we work with security experts and provide what’s needed for an independent review.
The numbers on this page come from a session where the person was also careful. Secrets showed up in two out of three requests anyway — because everyone pastes error logs, stack traces and config fragments when they’re in a hurry. Automation catches what attention misses.
For most individual developers, yes — keys, tokens, private keys, wallets and IBANs are covered from the first run. If you also handle passwords, cards, emails, phone numbers or need AI-based name and location detection, you’ll want the extended level, which you can switch on inside the app.
If the machine fingerprint hasn’t changed, open LocalGuard, copy the fingerprint from the License panel and paste it on the recovery page. You get a freshly signed key for that machine, with the original expiry date. If the fingerprint did change — new hardware, major OS update — you need a new licence.
The free and extended levels are built for one person on one machine. For organisations there’s a server deployment: the proxy runs on your infrastructure and covers many employees at once, without installing anything on every workstation. Write to support@localguard.me.
Last thing
Download it, route one endpoint through it, then open the dashboard at the end of an ordinary working day. If the dashboard is empty, you’ve lost two minutes. In every session we’ve measured, it wasn’t empty.
Free stays free. Pro costs $39 a year, against $240 for the nearest tool that publishes a price at all. And Pro only starts to matter once your prompts carry data that isn’t yours.
Running a team? Ask about server deploymentDrag to move around the image