Stage 1 Observe ➔ Stage 2 AI Learning ➔ Stage 3 Staged Enforcement

The Intelligent WAF for
Enterprise LLMs & AI Agents

Stop sensitive customer PII, internal API keys, and corporate trade secrets from leaking to external model providers. Reversible surrogate tokenization protects your data with zero prompt degradation and no false-positive business jargon blocking.

tokenshield-waf-inspector v2.2.0
INSPECTOR ACTIVE
RAW PROMPT (CLIENT / AGENT)3 SENSITIVE ENTITIES DETECTED
“Run valuation for client Sarah Connor (SSN: 456-78-9012, key: sk_live_9981298492) on Compute Environment for 500 K Q3 product showcase.”
Threat Risk: HighBusiness Jargon Shielded & Preserved
SCRUBBED PROMPT (SENT TO OPENAI / ANTHROPIC)SURROGATE ENCRYPTED
“Run valuation for client [SYN_NAME_89B2] (SSN: [MASK_SSN_****], key: [SEC_TOK_4A19]) on Compute Environment for 500 K Q3 product showcase.”
Zero Context LossResponse Auto-Detokenized

The Standard 3-Step WAF Model

Security That Doesn't Break Your Agents

Traditional regex filters aggressively block harmless queries and break agent reasoning. TokenShield implements the industry-proven Web Application Firewall learning lifecycle.

01

Observe Mode (Passive Audit)

Deploy TokenShield as a passive shadow proxy. Telemetry, PII detections, and token appearances are recorded to an encrypted shadow vault without modifying or dropping any prompts.

  • Zero agent disruption
  • Full payload visibility
  • Baseline traffic profiling
02

AI Policy Recommendation

Our recommendation engine classifies observed detections into Critical Secrets (100% confidence), Structured PII (98%), and automatically flags business jargon as safe allowlists.

  • Confidence scoring tiers
  • False-positive shielding
  • Auto-generated rule proposals
03

1-Click Staged Enforcement

Review machine suggestions and promote them to active protection with 1 click. Switch from Observe to Enforce mode safely with complete cryptographic audit logging.

  • 1-Click batch promotion
  • Reversible surrogate keys
  • ISO 27001 audit ledger

Architectural Superiority

Engineered for Autonomous Swarms

Built from the ground up for high-concurrency multi-agent architectures running across OpenAI, Claude, DeepSeek, and local Ollama clusters.

Zero-Trust AES-256 Vault

PII is substituted with cryptographically secure surrogate tokens. The original plaintext is stored in an isolated PostgreSQL vault, never exposed over the wire.

GLiNER & Presidio NLP

Dual-engine intelligence combines blazing-fast regex pattern matching with state-of-the-art Named Entity Recognition running locally without external cloud telemetry.

Regulatory Compliance Ready

Designed to meet strict ISO 27001, NIST 800-53, GDPR, PIPEDA, CCPA, and EU AI Act High-Risk System traceability standards with immutable audit logs.

Sub-Millisecond Overhead

Asynchronous pipeline interceptor optimized in Cython and asyncpg for high-throughput streaming prompts with negligible TTFT impact.

Universal LLM Compatibility

Drop-in OpenAI proxy format works seamlessly with LangChain, LlamaIndex, PydanticAI, AutoGen, CrewAI, or raw HTTP client requests.

Air-Gapped & On-Prem

Deploy as a cloud SaaS proxy or self-host as a native container inside your sovereign private network or Podman VM node.

Zero Code Modification

Two Minutes to Active Protection

Simply redirect your LLM base URL to TokenShield or install our lightweight client interceptor.

METHOD 1: REVERSE PROXY URL (DROP-IN)

Point your standard OpenAI SDK or environment variable to TokenShield's intelligent gateway:

# Direct proxy endpoint:
export OPENAI_BASE_URL="https://tokenshield.ntrust.ai/v1"
export OPENAI_API_KEY="ts_live_your_tokenshield_key"

# All outgoing prompts will be sanitized before hitting OpenAI!
METHOD 2: CLIENT INTERCEPTOR (PYTHON)

Wrap any LLM client with local client-side scrubbing:

from core.token_shield import TokenShieldEngine

shield = TokenShieldEngine(org_id="my_org", mode="observe")
clean_prompt, tokens = shield.sanitize(user_input)

# Query LLM with clean_prompt, then de-tokenize response:
raw_response = llm.generate(clean_prompt)
user_output = shield.desanitize(raw_response, tokens)

Ready to Safeguard Your Enterprise AI?

Start in passive Observe Mode today. Zero risk, instant payload telemetry, and automated policy recommendations tailored to your organization.