API keys
Stripe, OpenAI, AWS, GitHub — straight from your .env.
Happening in your terminal right now
Claude Code, Codex, Gemini CLI and other AI agents read your .env, configs and logs on their own. Every secret in that context gets shipped to an LLM. LocalGuard stops it on your machine.
One ordinary coding session. Real numbers.
Nobody was careless. Careful people still leak.
What's slipping out
Stripe, OpenAI, AWS, GitHub — straight from your .env.
Session tokens and JWTs hiding in logs and stack traces.
DB connection strings and hard-coded credentials.
Test fixtures that turned out not to be test data.
Emails and phone numbers from real customer records.
Internal hosts, endpoints and business logic.
How it works
STRIPE_KEY=sk_live_51Hq…x9Kz DB_URL=postgres://admin:Pr0d#2026@db OWNER=[email protected]
→ sent to the AI provider as-is
STRIPE_KEY=[SECRET_1] DB_URL=postgres://admin:[SECRET_2]@db OWNER=[EMAIL_1]
→ the model never sees the real values
Lightweight desktop app built in Rust. Lives in your menu bar.
Pick your AI tool, hit Connect, restart it. Done.
Secrets are replaced before sending — real values are restored in the replies.
Works where you already work
Pricing
Free
$5 first month
then $49/year + VAT · per computer
FAQ
No. Everything is scanned on your own computer. No cloud processing, no telemetry.
You don't have to paste anything. AI agents read files, logs and terminal output by themselves — keys in .env, configs and stack traces land in the context automatically.
The free version runs in detect-only mode: you see every leak, but nothing is blocked.
No. Each scan takes under 50 ms.
macOS (Apple Silicon), Windows x64 and Linux x64 (.AppImage and .deb).
$5 for the first month, then $49/year + VAT, one subscription per computer.
Takes 2 minutes to set up. Your next prompt is already on its way.
Get LocalGuard — $5