Listing Thumbnail

    Data Guard - PII, PHI, and Secret Redaction MCP Server

     Info
    Deployed on AWS
    An MCP server that finds and redacts sensitive data before your agent leaks it: PII, PHI, credentials, and API keys in text, JSON, YAML, and CSV. Deterministic detection with no ML model. Runs in your account on Bedrock AgentCore Runtime.

    Overview

    Data Guard is a deterministic security gateway that automatically intercepts and sanitizes sensitive data before it reaches AI models, logs, support tickets, or third-party APIs. Deployed as a stateless container inside your own AWS environment, it ensures confidential information never leaves your security boundary.

    Data Guard provides five core tools:

    list_detectors: Discovers available entity types, compliance policy packs, and redaction strategies.

    scan_data: Locates sensitive values in a document and returns masked previews without altering the original input.

    redact_data: Sanitizes sensitive information according to your selected policy and generates a secure audit receipt.

    restore_data: Reverses AES-GCM encrypted redactions using your encryption key to recover the original values.

    check_policy: Evaluates a document against compliance frameworks to issue a pass or fail result.

    Detection relies on exact rules rather than statistical models. It validates payment cards, bank accounts, healthcare identifiers, credentials, and national identity numbers across ten countries using mathematical check digits and prefix matching. It uncovers sensitive terms hidden in free-text chat logs and support tickets, and selectively redacts structured formats like JSON, YAML, and CSV without breaking their schema.

    Data Guard offers seven redaction strategies, including masking, reversible encryption, removal, labeling, and deterministic hashing for joinable analytics. Built-in policy packs cover HIPAA Safe Harbor, PCI-DSS, GDPR pseudonymization, and secrets scrubbing. Every operation produces an audit receipt containing entity counts, triggered rules, and input hashes without ever exposing raw values.

    Highlights

    • Deterministic detection you can audit: check digits, issuer prefixes, and field-name rules across 63 entity types covering PII, PHI, payment data, and credentials. No ML model, so every finding names the rule that produced it.
    • Structure-aware redaction with seven strategies, including deterministic keyed tokens that keep redacted data joinable and reversible AES-GCM encryption. JSON, NDJSON, YAML, and CSV still parse afterwards.
    • Compliance packs for HIPAA Safe Harbor, PCI-DSS, and GDPR, with an audit receipt on every call that contains counts and no sensitive values.

    Details

    Delivery method

    Type

    Supported services

    Delivery option
    Amazon Bedrock AgentCore Runtime

    Latest version

    Operating system
    Linux

    Deployed on AWS
    New

    Introducing multi-product solutions

    You can now purchase comprehensive solutions tailored to use cases and industries.

    Multi-product solutions

    Features and programs

    Financing for AWS Marketplace purchases

    AWS Marketplace now accepts line of credit payments through the PNC Vendor Finance program. This program is available to select AWS customers in the US, excluding NV, NC, ND, TN, & VT.
    Financing for AWS Marketplace purchases

    Pricing

    Data Guard - PII, PHI, and Secret Redaction MCP Server

     Info
    Pricing is based on a fixed subscription cost. You pay the same amount each billing period for unlimited usage of the product. Pricing is prorated, so you're only charged for the number of days you've been subscribed. Subscriptions have no end date and may be canceled any time.
    Additional AWS infrastructure costs may apply. Use the AWS Pricing Calculator  to estimate your infrastructure costs.

    Fixed subscription cost

     Info
    Monthly subscription
    $29.00/month

    Vendor refund policy

    Subscriptions can be cancelled at any time in AWS Marketplace and will not renew for the following month. For any billing question, Email: contact@infoinlet.com  and we will work with you and AWS to resolve it.

    How can we make this page better?

    Tell us how we can improve this page, or report an issue with this product.
    Tell us how we can improve this page, or report an issue with this product.

    Legal

    Vendor terms and conditions

    Upon subscribing to this product, you must acknowledge and agree to the terms and conditions outlined in the vendor's End User License Agreement (EULA) .

    Content disclaimer

    Vendors are responsible for their product descriptions and other product content. AWS does not warrant that vendors' product descriptions or other product content are accurate, complete, reliable, current, or error-free.

    Usage information

     Info

    Delivery details

    Amazon Bedrock AgentCore Runtime

    Supported services: Learn more 
    • Amazon Bedrock AgentCore
    Container image

    Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.

    Version release notes

    Initial release. Detects and redacts PII, PHI, and secrets in text, JSON, NDJSON, YAML, and CSV, with policy packs for HIPAA Safe Harbor, PCI-DSS, and GDPR.0.1.0

    Additional details

    Usage instructions

    Deploy this MCP server on Amazon Bedrock AgentCore Runtime, then call it from your agent over POST /mcp (tools/list, tools/call). Tools: list_detectors, scan_data, redact_data, restore_data, check_policy. Pass data inline (text or base64_data) or by path / s3:// URI. Start with scan_data to see what is present without changing anything, then redact_data with a policy: default, hipaa_safe_harbor, pci_dss, gdpr_basic, secrets_only, or strict_all. The hash and encrypt strategies need a key, supplied per call or via DG_TOKEN_KEY.

    Support

    Vendor support

    Please reach out to us by email for any queries. We look forward to helping you with any questions you may have. Email: contact@infoinlet.com 

    AWS infrastructure support

    AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.

    Similar products

    Customer reviews

    Ratings and reviews

     Info
    0 ratings
    5 star
    4 star
    3 star
    2 star
    1 star
    0%
    0%
    0%
    0%
    0%
    0 reviews
    No customer reviews yet
    Be the first to review this product . We've partnered with PeerSpot to gather customer feedback. You can share your experience by writing or recording a review, or scheduling a call with a PeerSpot analyst.