NDS open-sources Rampart, an on-device PII filter for browser chat

NDS, the organisation behind the @nationaldesignstudio npm scope, has open-sourced Rampart, which it describes as a first-generation on-device personal information filtering system and "a strong first line of defense". It runs in the browser and redacts personal information from a chat message in the moment between typing and sending. The source states there is no server in the loop. Rampart is labelled an alpha product.
The announcement opens with the problem: a request to clean up an email carries your name and your coworker's, a question about a medical bill carries your address and account number, and all of it travels to a remote server you cannot inspect. NDS gives two reasons existing approaches fall short. First, AI privacy guarantees are almost impossible to verify: the authors argue that from first principles it is impossible to verify the privacy and security claims of AI vendors, since a newly deployed version of an AI runtime may accidentally begin logging sensitive user information, and services carry unknown risks such as zero-day vulnerabilities and insider threats. Second, most PII removal models are gigantic. As an example, OpenAI Privacy Filter is about 2.8GB, which would take roughly 38 minutes to download to a browser on a relatively poor 10mbps connection.
Rampart uses two readers on the device. The first is a set of regular expressions paired with real validations. It handles information that has structure: Social Security numbers, credit cards, phone numbers, routing and account numbers, emails, IP addresses and government IDs. NDS calls it deterministic and fast. The second is MiniLM, a small language model. Because rules cannot anticipate every name or street address, MiniLM reads the sentence for context and redacts what it finds within a specific category.
The worked example in the post takes "My name is Maria Garcia, my Social Security number is 123-45-6789, and I make $1,950 a month. Can you help me find affordable housing?" and turns it into "My name is [GIVEN_NAME] [SURNAME], my Social Security number is [SSN], and I make $1,950 a month." The chatbot's reply is then filled back in using relevant PII that the browser stores temporarily on the device. The npm library exposes this as createGuard, guard.protect (redacts text and returns numbered placeholders such as [GIVEN_NAME_1]) and guard.reveal (restores the original values in the model's reply). In the code sample, "My name is John Wick. I live at 88 Cedar Lane, Brookvale, CT 06482." becomes "My name is [GIVEN_NAME_1]. I live at [BUILDING_NUMBER_1] [STREET_NAME_1], Brookvale, CT 06482." The city, state and ZIP code stay in the text.
Rampart was trained on AI4Privacy's OpenPII 1.5M dataset plus a synthetic generator that reinforces all 17 entity types with deliberately messy chat-style input. The headline benchmark numbers come from a 30,000-row held-out OpenPII slice spanning seven Latin-script languages, scored end to end by the shipped pipeline. The page shows this as a chart of private-term recall (higher is better); the text itself gives no recall percentages. Supported languages are English, Spanish, French, German, Italian, Portuguese and Dutch. The model is on HuggingFace, the library is on npm, and a whitepaper is available. NDS also uses the post to recruit, inviting readers who want to build elegant and useful tools for Americans to consider joining NDS.
Key facts
- NDS open-sourced Rampart, an alpha-stage, first-generation on-device PII filter that redacts chat messages in the browser before sending, with no server in the loop.
- It pairs regular expressions with validations (SSNs, credit cards, phone, routing and account numbers, emails, IPs, government IDs) with MiniLM for names and street addresses.
- NDS's argument: AI vendor privacy claims cannot be verified, and models like OpenAI Privacy Filter (about 2.8GB, roughly 38 minutes at 10mbps) are too big to download into a browser.
- Trained on AI4Privacy's OpenPII 1.5M plus a synthetic generator covering 17 entity types; supports English, Spanish, French, German, Italian, Portuguese and Dutch.
- Available as a HuggingFace model and an npm library (@nationaldesignstudio/rampart) with createGuard, guard.protect and guard.reveal; a whitepaper is linked.
Why it matters
The post rests on one principle: the only personal information you can be sure is private is the information that never leaves your device. NDS argues that vendor privacy and security claims cannot be verified from outside, and that PII filters are usually either a remote service you must trust or a very large download. Rampart is an attempt to put a filter in front of the send button that runs entirely in the browser. The source gives no size, latency or download time for Rampart itself or for the MiniLM model, so how lightweight it really is stays unstated.
Who it affects
Anyone who types personal details into a chatbot, and developers who build browser chat experiences and could wrap their model calls with the npm library. The language coverage is narrow for now: seven Latin-script languages, namely English, Spanish, French, German, Italian, Portuguese and Dutch.
How to use it
Install the npm library @nationaldesignstudio/rampart, or download the model from HuggingFace; a whitepaper is also linked. In code, call createGuard() once, pass the user's text to guard.protect() and send the returned safe.text to the language model. Then pass the model's reply to guard.reveal() to put the original values back in place of the numbered placeholders. No licence is named in the announcement.
How solid is it
This is a first-party announcement from NDS, the team that built Rampart, so the claims are its own. Training used AI4Privacy's OpenPII 1.5M dataset and a synthetic generator for 17 entity types. The headline numbers come from a 30,000-row held-out OpenPII slice across seven Latin-script languages, scored end to end by the shipped pipeline. The page shows only a recall chart; no numeric benchmark results appear in the text, and no accuracy comparison against OpenAI Privacy Filter is given. The source calls it an alpha product.
Risks and caveats
NDS describes Rampart as the first line of defense in a more thorough effort to manage PII for AI chat, not as a complete solution, and the source does not say the redaction is complete or guaranteed. Coverage is limited to seven languages. What gets redacted depends on the entity categories: in the examples the $1,950 income figure and the city, state and ZIP code were left in the text. The headline benchmark is a held-out slice of OpenPII, the dataset Rampart was trained on, and no recall figures are given in the text. Reveal depends on the browser temporarily storing the relevant PII on the device.
“Our core design principle is that the only personal information you can be sure is private is the information that never leaves your device.”
— NDS, Rampart announcement