llm-stream-guardrails

Filters PII, secrets and banned content out of an LLM stream — mid-stream, before the reader ever sees it. Type anything below and watch it work.

◆For any input and any chunking, the streamed result is byte-identical to filtering the whole string at once. Drag the chunk size down to 1 character — the output does not change.
Try
1 · Raw — what the model saidunfiltered

    
2 · Filtered — what the user seesprotected

    
3 · Caught

Nothing caught yet.

This page runs the real llm-stream-guardrails package compiled to the browser — the same code published to npm. Nothing you type leaves your device; there is no server and no network call.

What it does not do

Every example above was chosen because it gets caught. That is not the measurement. A detector finds the formats it was written for; it cannot find a shape nobody thought of, a credential invented last month, or a secret the model spelled out in prose. On text nobody here wrote, recall is 47% to 81% — not 100%.

So it is defence in depth, not a compliance control. It makes a leak less likely. It does not make one impossible, and it is not certified against GDPR, HIPAA, PCI-DSS or anything else — those are properties of a system and its operator, never of a dependency.