Load
Paste text, choose a synthetic demo or read a supported evidence file locally.
LOCAL-FIRST PENTEST PRIVACY
TargetVeil detects personal data, client infrastructure and secrets inside pentest prompts and text exports. Paste evidence or load a local file; sanitization runs in your browser with no prompt-processing backend, uploads or prompt storage.
01 / INPUT
02 / REVIEW
| Type | Detected value | Replacement | Detector / confidence | Why it was hidden |
|---|
Automated detection cannot guarantee that every sensitive value is found. Review the sanitized prompt before sending it to a third-party service.
PRIVACY MODEL
Paste text, choose a synthetic demo or read a supported evidence file locally.
Detectors run locally with JavaScript inside your browser.
Inspect every detection and its explanation before copying.
Reloading or clearing the page removes the prompt and mapping.
ABOUT TARGETVEIL
TargetVeil is an open-source pentest prompt sanitizer. It helps authorized security professionals remove personally identifiable information, client infrastructure and authentication secrets before pasting technical evidence into a public large language model.
Unlike a generic PII scrubber, TargetVeil understands security assessment data. It recognizes HTTP authorization headers, cookies, API keys, JWTs, database credentials, password hashes, cloud resource identifiers, IP addresses, domains, Active Directory objects and engagement-specific scope values while preserving the technical structure an AI needs for useful analysis.
Deterministic pseudonyms preserve relationships between repeated hosts, accounts and network ranges. A target domain hierarchy remains a hierarchy, and repeated values receive the same safe identity during the current session. Seventeen focused profiles cover web testing, network traffic, Active Directory, exploitation, vulnerability scanners, cloud and Kubernetes evidence, OSINT and security logs.
The browser application has no prompt-processing backend and does not write prompts to browser storage. A narrowly scoped Cloudflare Web Analytics beacon measures aggregate site usage; TargetVeil does not pass prompt, evidence, scope or sanitized-output values to it. Country-specific identifier packs supplement global detectors without making one country the product's focus.
Focused rules for web, network, AD, exploitation, vulnerability scanning, cloud, OSINT and SIEM workflows reduce irrelevant detections.
Global security-data detection plus identifier packs for the EU, Greece, US, UK, Canada, Australia, India and Brazil.
Load a local JSON file containing client names, project codes, domains and explicit allowlist values.
See the matched value, replacement, detector category and privacy reason before copying anything.
Read supported text exports up to 10 MB and download the sanitized result without uploading either file.
Try one declared-canary synthetic example for every profile without exposing real engagement data.
FREQUENTLY ASKED QUESTIONS
No. Detection and replacement run in your browser. The application has no prompt-processing API, and prompt, evidence, scope and sanitized-output values are not submitted to the website analytics service.
Yes. The hosted site uses Cloudflare Web Analytics for aggregate page-view and performance measurements. The sanitizer does not send form fields, imported evidence, engagement scope or output values to analytics. The local and offline workflow remains available for higher-assurance use.
No automated detector can guarantee complete coverage. TargetVeil adds scope-specific values, a verification pass and a mandatory preview, but the pentester must still review the result and follow the engagement's data-handling rules.
TargetVeil includes profiles for Burp and raw HTTP, Nmap, Nuclei, ffuf, sqlmap, Gobuster, Nikto, WPScan, BloodHound, NetExec, Impacket, Mimikatz, Metasploit, Wireshark, tcpdump, Nessus, OpenVAS, AWS, Azure, GCP, Kubernetes, OSINT and SIEM logs.
Yes. After the static application is cached, it can run offline. For high-sensitivity engagements, clone the repository and serve the same files locally while disconnected from the network.
The browser reads text, log, JSON, XML, CSV, HAR, Nessus, Nmap, Markdown and YAML exports up to 10 MB. Binary files, PDFs, Office documents and images are not processed in version 0.2.
CREATOR
Cybersecurity practitioner focused on offensive security, web application pentesting, practical research and AI-assisted security automation.