🛡️ Zero-Trust · Runs 100% in your browser

Mask sensitive data.
Send it to AI. Restore it in one click.

TokenShield is a single offline HTML file that de-identifies personal and business data before it ever reaches ChatGPT or Claude — then restores the AI's reply back to the original wording, with nothing ever leaving your device.

Try the App → See it in action ↓
5
Region rule presets
2
Personas: Personal / Business
0
Bytes ever leave your device

Four core features, try them yourself

Each demo below is pre-loaded with realistic sample data. Click the buttons to see exactly what TokenShield does — no data leaves this page, and nothing here touches the real app's engine.

1
Region-aware rule presets
Switch the active region below, then run the scan — only that region's format is detected, on top of the always-on Global baseline (email, IP, credit card).
Sample text (same for every region)
De-identified result
Session Vault
2
Persona-aware Hard Block
Personal and Business modes lock different keyword sets. Switch persona, then scan the matching sample note to see the copy button get force-locked.
Sample note
Copy button state
Simulating on-device AI semantic analysis...
3
Custom dictionary & manual masking
Regex can't catch everything — an informal nickname or an unlisted project codename needs a custom dictionary entry or a manual selection.
Sample text
"Sam" and "Project Falcon" have no fixed format — regex alone can't find them. A custom dictionary entry fixes that.
De-identified result
Session Vault
4
Restore, in one click
This is what you'd paste back after the AI replies — every {{TAG_N}} token is matched back to the original value automatically.
Simulated AI reply (tokens intact)
Restored result
5
Custom protection rules: merge vs. replace
Beyond the built-in library, you can import your own regex rules — merged alongside the built-ins, or swapped in to replace them entirely. Try both modes below.
Your custom rule (CSV row)
Sample text
De-identified result
The real tool also supports auto-loading a config file from the same folder and exporting your rules as a file — both require local file-system access, so they can't be simulated in this hosted demo. See the technical docs for details.

Three ways to run it, for any network environment

From a quick online sandbox to a fully air-gapped closed network, pick the deployment that matches your organization's security requirements.

Evaluation only

Online Sandbox

Try the feature set quickly via GitHub Pages — all processing runs locally in your browser and nothing is uploaded. For production use, download the offline version so you can verify exactly what code is running.

Recommended

Offline Single File

Download TokenShield.html and double-click it. No install, no server, everyday use with real documents.

Air-gapped

No Internet / Closed Network

Keep TokenShield.html and style.css in the same folder for government machines and closed intranets.

Try the Full Online Sandbox
Or download the offline version from GitHub (oas114/TokenShield)