01
Reverse proxy via *_BASE_URL, MITM only as opt-in
Pointing agents at a local base URL needs no certificate trust and is the least invasive route; TLS interception is available for stubborn clients but off by default and fail-closed.
Personal project
Local DLP firewall that blocks secrets and PII from reaching LLM providers
The agent calls the local proxy, which scans the body with the engine, applies the policy, records an audit event asynchronously, forwards the redacted request upstream and returns the response with a feedback header.
Click a step to jump to it. Click a component for details.
A Rust reverse proxy that sits between AI coding agents (Claude Code, Codex, opencode) and LLM APIs. It scans every request in under a millisecond, then blocks, redacts or warns on secrets and personal data, recording only keyed hashes in a local audit store.
AI coding agents ship code, prompts and context to external APIs. A stray API key, .env dump or PEM key in that payload leaves the machine, and there is no standard control point to stop it.
01
Pointing agents at a local base URL needs no certificate trust and is the least invasive route; TLS interception is available for stubborn clients but off by default and fail-closed.
02
Scanning sits on the request path, so predictable latency and immunity to catastrophic backtracking matter more than exotic pattern features.
03
An audit trail is useful for triage and deduplication without becoming a second place where secrets live. Keyed per-install HMACs prevent cross-install correlation.
04
If the engine breaks, blocking is safer than leaking. A chain option lets Cerberus scan plaintext first and hand the sanitized request to another proxy such as a token compressor.