Alexei Rojas Quiroga
← All projects

Personal project

Cerberus

Local DLP firewall that blocks secrets and PII from reaching LLM providers

Status
Live
Role
Solo: architecture, Rust implementation, security design, packaging and release automation
GitHub

Architecture

  • Local Rust proxy, per-request scan
  • Fail-closed on critical findings
  • Signed Ed25519 rule packs (Pro)
  • Zero-leak audit log
  • p99 scan under 1 ms

The agent calls the local proxy, which scans the body with the engine, applies the policy, records an audit event asynchronously, forwards the redacted request upstream and returns the response with a feedback header.

Architecture · 10 nodes · 4 flows
WHAT I BUILTClaude Code · …AI coding agentSends prompts to an LLMRustCommand lineinit, start, scan,mode, mitmWeb UI · CSPLocal dashboardProtected local web UIRust · cerberu…Egress proxyDecode, policy, forwardRust · rustlsOpt-in forwardproxyCONNECT with local CARust · linear …Detection engineScan and redact secretsEd25519 signedRule packsSigned rules, licensingRust · cerberu…Audit writerAsync hash-only auditeventsSQLiteAudit databaseFlags, hashes, countsonlyOpenAI-style A…LLM providerReceives only redactedrequests1request to local base URL2345678
  • Service / compute
  • Data store
  • Client
  • External system
  • Synchronous
  • Async / loop
Scroll sideways to see the full diagram

How it flows, step by step

Click a step to jump to it. Click a component for details.

What it does

A Rust reverse proxy that sits between AI coding agents (Claude Code, Codex, opencode) and LLM APIs. It scans every request in under a millisecond, then blocks, redacts or warns on secrets and personal data, recording only keyed hashes in a local audit store.

The problem

AI coding agents ship code, prompts and context to external APIs. A stray API key, .env dump or PEM key in that payload leaves the machine, and there is no standard control point to stop it.

What I built

  • Modular Rust workspace with separate crates for engine, proxy, store, packs and CLI, with unsafe code forbidden and pedantic clippy denied.
  • Detection on a linear-time regex engine with a 13-rule default pack, ReDoS fuzz tests and a measured p99 scan latency under 1 ms.
  • Zero-leak audit design: raw secrets are never persisted; only per-installation keyed HMAC hashes, flags and counts reach SQLite.
  • Fail-closed by default, signed Ed25519 rule packs verified at boot, and opt-in MITM interception restricted to an allowlist of exact hosts.
  • Control plane with hot-swappable config, a CSP-protected dashboard, admin-token enforcement on non-loopback binds, and a break-glass allow-once command with recorded reason.
  • Distribution via Homebrew, install script, Windows zip, Docker and a Helm chart, with release and version-bump workflows.

Key decisions and why

01

Reverse proxy via *_BASE_URL, MITM only as opt-in

Pointing agents at a local base URL needs no certificate trust and is the least invasive route; TLS interception is available for stubborn clients but off by default and fail-closed.

02

Regex with a linear-time engine

Scanning sits on the request path, so predictable latency and immunity to catastrophic backtracking matter more than exotic pattern features.

03

Store hashes, never values

An audit trail is useful for triage and deduplication without becoming a second place where secrets live. Keyed per-install HMACs prevent cross-install correlation.

04

Fail closed and chain-able

If the engine breaks, blocking is safer than leaking. A chain option lets Cerberus scan plaintext first and hand the sanitized request to another proxy such as a token compressor.

Tech stack

Languages
Rust
Backend
Cargo workspace (multi-crate)regex (linear-time engine)
Data
SQLite
Other
HMAC-SHA256Ed25519 signed rule packs
DevOps
Docker / Docker ComposeHelmGitHub Actions + Homebrew tap
Testing
Fuzz, load and fail-safe tests