Overview
Data Guard is an MCP server that finds and redacts PII, PHI, and secrets before they reach an LLM prompt, a log, a support ticket, or a third-party service.
- scan_data: find sensitive values without changing anything
- redact_data: redact by policy and return an audit receipt
- restore_data: reverse an encrypted redaction with your key
- check_policy: pass or fail a document against a compliance pack
- list_detectors: list entity types, policy packs, and strategies
Detection is deterministic, with no ML model: check digits, issuer prefixes, field-name rules, and curated word lists, so every finding names the rule behind it. JSON, NDJSON, YAML, and CSV are redacted value by value and still parse afterwards.
Seven redaction strategies, including masking, keyed hashing that keeps data joinable, and reversible AES-GCM encryption. Policy packs for HIPAA Safe Harbor, PCI-DSS, GDPR, and secrets scrubbing. Every call returns an audit receipt with counts and hashes, never raw values.
It runs as a stateless container on Amazon Bedrock AgentCore Runtime in your own AWS account and sends nothing to us. Set DG_AUDIT_LOG to keep every receipt as a log line in your account.
Want to try it first? This listing has no free trial, but the same engine is available as the Data Guard API listing on AWS Marketplace, which includes one. We suggest sample data for that evaluation, as the API runs in our account rather than yours: https://aws.amazon.com/marketplace/pp/prodview-i4qrny5rdr3o2
Highlights
- Deterministic detection you can audit: check digits, issuer prefixes, and field-name rules across 63 entity types covering PII, PHI, payment data, and credentials. No ML model, so every finding names the rule that produced it.
- Structure-aware redaction with seven strategies, including deterministic keyed tokens that keep redacted data joinable and reversible AES-GCM encryption. JSON, NDJSON, YAML, and CSV still parse afterwards.
- Compliance packs for HIPAA Safe Harbor, PCI-DSS, and GDPR, with an audit receipt on every call that contains counts and no sensitive values.
Details
Introducing multi-product solutions
You can now purchase comprehensive solutions tailored to use cases and industries.
Features and programs
Financing for AWS Marketplace purchases
Pricing
- Monthly subscription
- $29.00/month
Vendor refund policy
Subscriptions can be cancelled at any time in AWS Marketplace and will not renew for the following month. For any billing question, Email: contact@infoinlet.com and we will work with you and AWS to resolve it.
How can we make this page better?
Legal
Vendor terms and conditions
Content disclaimer
Delivery details
Amazon Bedrock AgentCore Runtime
- Amazon Bedrock AgentCore
Container image
Containers are lightweight, portable execution environments that wrap server application software in a filesystem that includes everything it needs to run. Container applications run on supported container runtimes and orchestration services, such as Amazon Elastic Container Service (Amazon ECS) or Amazon Elastic Kubernetes Service (Amazon EKS). Both eliminate the need for you to install and operate your own container orchestration software by managing and scheduling containers on a scalable cluster of virtual machines.
Version release notes
Initial release. Detects and redacts PII, PHI, and secrets in text, JSON, NDJSON, YAML, and CSV, with policy packs for HIPAA Safe Harbor, PCI-DSS, and GDPR.0.1.0
Additional details
Usage instructions
Data Guard is an MCP server that finds and redacts PII, PHI and secrets in text, JSON, NDJSON, YAML and CSV. It runs in your own AWS account on Amazon Bedrock AgentCore Runtime, so your data stays there.
-
Deploy on AgentCore Runtime with the container image from your fulfillment page. Create an execution role that AgentCore can assume, with ECR pull and CloudWatch Logs permissions, then create an agent runtime with server protocol MCP. Wait for status READY.
-
Call it from your agent over MCP streamable HTTP, POST /mcp, using tools/list and tools/call. The runtime endpoint uses AWS SigV4 (service bedrock-agentcore) unless you configure a JWT authorizer.
-
Tools list_detectors entity types, policy packs, strategies scan_data find sensitive values, change nothing redact_data rewrite them, with an audit receipt restore_data reverse an encrypted redaction check_policy pass or fail against a compliance pack
Pass the document as exactly one of text, base64_data, or path. Start with scan_data, then redact_data with a policy: default, hipaa_safe_harbor, pci_dss, gdpr_basic, secrets_only, strict_all. The hash and encrypt strategies, and gdpr_basic, need a key: pass key on the call or set DG_TOKEN_KEY on the runtime.
-
Optional environment variables DG_TOKEN_KEY default key for hash and encrypt DG_AUDIT_LOG stderr for one audit line per call, counts only DG_MAX_INPUT_BYTES input limit, default 16777216 (16 MiB)
Support: contact@infoinlet.com
Detailed usage instructions are available at https://github.com/infoinlet-com/aws-marketplace-resources/blob/main/mcp/container/data_guard.md
Support
Vendor support
Please reach out to us by email for any queries. We look forward to helping you with any questions you may have. Email: contact@infoinlet.com
AWS infrastructure support
AWS Support is a one-on-one, fast-response support channel that is staffed 24x7x365 with experienced and technical support engineers. The service helps customers of all sizes and technical abilities to successfully utilize the products and features provided by Amazon Web Services.