Secret redaction for AI coding tools

You've already sent it.

AI coding agents resend your whole conversation on every request, secrets included. LocalGuard is a desktop app that replaces API keys, passwords, card numbers and personal data with placeholders before a request leaves your computer, and restores them in the reply.

For developers who run Claude Code, Codex, OpenCode or another AI agent on macOS, Linux or Windows.

macOS · Linux · Windows · installs in about 2 minutes · no licence needed to download

POST api.anthropic.com/v1/messagesillustration
Without LocalGuard
Authorization: Bearer sk-live-4f8a2c91e0b7

Leaves your computer as written.

With LocalGuard
Authorization: Bearer <REDACTED:api_key:9d41c0e7a3b25f18c4e60d927b1a8e53>

The provider sees the placeholder. The reply comes back with the real value restored.

Fake key, made-up hash. Placeholder format as in the app.
01Evidence

This is what one session looked like.

669 detections in one real LocalGuard run. The same key resent in a later turn counts again, so this counts events, not distinct secrets.

Requests
138
Carried a detection
67%
Scanned
109 MB

One run on one machine. Your numbers will differ.

LocalGuard Home with Protection ON for Claude Code, Codex and OpenCode: totals hidden today and the latest hidden items by tool and provider
Real screenshot of version 0.10.3 after a short test runCounted per request: a value resent in a later turn counts again
02What leaves

Once it is in the model, it is out of your hands.

Access

API keys, AWS keys, GitHub tokens, JWTs, private keys. Whoever holds them signs in as you.

Money

Card numbers, IBANs, crypto wallet addresses, payment tokens.

Clients

Emails, phone numbers, names and places that were never yours to share.

Business

The prompt that explains how you work. Competitors and attackers can read the same text.

A key pasted once keeps travelling: the agent resends the conversation with every later request.

03How it works

A proxy on your machine. Nothing ships to our cloud, and there is no cloud scan.

Your computer
Your AI tool Claude Code, Codex, OpenCode sk-live-4f8a2c91e0b7
real key
LocalGuard scans, swaps, restores
<REDACTED:api_key:9d41c0e7a3b25f18c4e60d927b1a8e53>
Model provider sees placeholders only
  1. Sit in the middle

    LocalGuard runs in your menu bar. AI tools talk to model providers through it.

  2. Scan and replace

    Secrets become placeholders before the request leaves. It all happens on your device, in under 50 ms.

  3. Restore on the way back

    Responses come back with the real values in place, so your workflow does not change.

No detector catches everything. Patterns match known formats, an on-device model finds names and places, and the app logs every redaction so you can check what it did.

Written in Rust · zero telemetry · no cloud scanning

04The app

What you see after you install it.

Real screenshots from version 0.10.3. Nothing here is a mock-up.

Activity Every redaction: which tool sent it, to which provider, what type it was, and whether a pattern or the on-device model found it. Values are shown masked.
LocalGuard Activity log with 513 events: time, tool and provider, type, action Hidden, masked value, and detected by pattern or by on-device AI
AI tools Connect and Disconnect per tool. When a tool cannot be routed through LocalGuard, the app says why instead of pretending.
LocalGuard AI tools: Codex connected with Show the change and Disconnect buttons, Cursor marked automatic connection unavailable, DeepSeek Harness not connected
Connectors The local port each provider listens on. Switch any one off, or add your own under Settings, Advanced.
LocalGuard Settings, Advanced, Connectors: openai, anthropic, deepseek and other providers, each with a local port, an on/off switch and a delete button
05Try it

Same prompt, two outcomes.

Edit the text. It all runs in your browser, and nothing you type is sent anywhere.

Without LocalGuard: every highlighted value leaves your computer as written.
Your prompt
What the provider receives

              
Simulation with fake values. The app scans with 32+ patterns plus an on-device model for names and places; this page uses a shorter list.
06Price

See your leaks for free. Stop them for $5.

LocalGuard · one computer
$5first month

Then $49 a year plus tax, about 94 cents a week. Cancel any time.Or pay $49 for the year at once and skip the first month.

  • API keys, tokens, private keys, AWS keys
  • Passwords, including in URLs
  • Cards, IBAN, crypto wallets
  • Emails and phone numbers
  • On-device AI for names and places
  • Answers come back with the real values
  • Move to a new computer any time
Start for $5

Stripe · tax calculated at checkout · $5 today, $49 after 30 days, then yearly.

Before you subscribe
Free download

The app shows which secrets your AI tools send, which tool sent them, to which provider and when. It does not block or replace anything until you subscribe.

Download

Turn protection on from the app whenever you are ready.

Teams, self-hosted and CLI installs: support@localguard.me.

07Tools

24 AI tools connect in one click.

33 tool families audited, listed alphabetically below. Connect and Disconnect buttons mean no config files to edit by hand.

  • Aider
  • Claude Code
  • Cline
  • Codex
  • CommandCode
  • Continue
  • Crush
  • DeepSeek Harness
  • Gemini CLI
  • Goose
  • Hermes
  • Kilo Code
  • Letta
  • MimoCode
  • omp
  • OpenClaw
  • OpenCode
  • OpenHands
  • Pi
  • ProtoAgent
  • Qwen Code
  • shell-gpt
  • Strix
  • Zed

Coverage depends on the tool's local mode and provider. For example, Codex supports API-key and ChatGPT-plan login; Gemini CLI requires API-key login. The app explains the supported mode for every tool. Restart the tool after connecting.

Disconnect restores the original routing settings and preserves your credentials, models and later edits. Project settings, shell variables and cloud execution can use separate routes.

Why 9 audited families have no automatic connection
  • agy (Antigravity): no supported local model address override confirmed.
  • CodeGPT: no verified external settings writer for the editor extension.
  • Cursor: model requests pass through Cursor's servers.
  • Kiro / Amazon Q: no verified local model address override for cloud features.
  • Lemonade: runs models locally and serves other clients; local inference needs no cloud proxy.
  • Roo Code: no verified external settings writer for its private editor storage.
  • Warp: cloud inference cannot reach LocalGuard on your computer.
  • Windsurf / Devin: no verified local model address override for cloud features.
  • ZCode: custom addresses exist in its interface, but no verified external-write format.

See connection modes and setup instructions →

Menu bar app for macOS, Linux, and Windows. Written in Rust. Scans stay on your machine.

08Questions

Questions worth answering

No. Scanning runs on your machine. There is no cloud scanning and no telemetry.
LocalGuard runs in detect-only mode: it shows which secrets your AI tools sent, to which provider and when, and redacts nothing. Turn protection on from the app when you are ready.
$5 for the first month, then $49 a year, plus applicable tax, charged automatically. Cancel any time from the app; protection stays on until the end of the paid period. One computer at a time: activating on a new one moves the subscription.
Redaction is local and built to stay under 50 ms. Your tools keep talking to the same providers.
24 local integrations, including Claude Code, Codex, OpenCode, Pi, Hermes, Goose, OpenClaw and MimoCode. The app detects installed tools and connects supported local modes in one click. Each tool explains its provider and login limitations. Cloud features, project overrides and custom settings can use separate routes. See the full alphabetical catalog.
Because ordinary sessions still leak. Detect-only shows you what left. Protection stops it before it leaves.

Stop the next leak before it leaves.

The download is free: until you subscribe, LocalGuard shows what leaks and redacts nothing.