Runtime control layer for AI.
Every prompt, every tool call, every action. Local by default, cloud when you need it.
Three lines to start.
Local mode ships in the base package. No API key, no signup, no outbound HTTP. Add cloud when you want the semantic pass.
from zotniq import Zotniq
client = Zotniq() # no api_key needed — runs locally
findings = client.detect(
"Contact [email protected] about SSN 123-45-6789"
)
# [Finding(type=EMAIL, ...), Finding(type=SSN, ...)]from zotniq import Zotniq
from zotniq.integrations.openai import wrap_openai
openai_client = wrap_openai(
Zotniq(api_key="zot_sk_..."),
api_key="sk-...",
)
response = openai_client.chat.completions.create(
model="gpt-4",
messages=[{"role": "user", "content": "My SSN is 123-45-6789"}],
)
# SSN masked before OpenAI ever sees the prompt.$ zotniq check "my email is [email protected]"
ALLOWED_WITH_MASKING · 1 finding
masked: "my email is b**@example.com"
$ echo "sk-abc123..." | zotniq check --json | jq .decision
"BLOCKED"Local mode. Zero data leaves your machine.
Set mode="local" and every detection runs on device. No key. No network. No usage limit.
from zotniq import Zotniq
# mode="auto" defaults to local when no api_key is set.
client = Zotniq()
client.mask("call me at 555-0199")
# "call me at XXX-XXX-0199"- ·
zotniq.detectionsubpackage: regex + Luhn + IBAN + SSN + PHI, zero dependencies, importable standalone - ·
Zotniq()sync client andAsyncZotniq()async twin - ·CLI:
zotniq check,zotniq mask - ·Type-safe Pydantic v2 wire types, full error hierarchy, retries, request-id echo
Add an API key when you want cloud detection, org policies, audit log, and the Developer Console.
Plugs into what you already use.
Live today: OpenAI drop-in, Anthropic drop-in, and the REST API. Rolling out through November: LangChain, LlamaIndex, LiteLLM, NVIDIA NeMo Guardrails, and the TypeScript SDK.
Building on something not listed? The REST API works from any language.
curl https://api.zotniq.ai/v1/preflight/text \
-H "X-Zotniq-API-Key: zot_sk_..." \
-d '{"text": "my ssn is 123-45-6789", "destination": "AI_TOOL"}'Every call, visible in your Developer Console.
No black box. Every decision, every finding, every masked span, every SIEM forward, in one console you own.
Paste text, pick a destination, pick a mode. See decision, findings, and masked output. Copy the equivalent Python or cURL snippet in one click.
Name each key. Rotate on click. Revoke on click. See last-used and per-key usage without touching the CLI.
30-day retention. Filter by request ID, user, model, decision. Download the whole feed as JSONL.
Register on_decision endpoints. Wire up Splunk, Datadog, generic webhook, or local file. Monitor delivery health.
Read the team policy the way your engineers do. Download, version-track, upload. No drift between UI and code.
Zotniq detects the client version on every call. See what is deprecated, what upgraded, and the exact upgrade command.
Console panels roll out through October. API keys and playground are live today.
Built for real production.
AsyncZotniq is a full twin of the sync client. Use it inside FastAPI, Starlette, Django-async, or any asyncio loop.
Every wire type is Pydantic v2. Full mypy support. IDE autocomplete for Decision, Finding, Destination, and the full error hierarchy.
The on_decision hook fires per call. Splunk, Datadog, generic webhook, or local file forwarders bundled. Decision metadata only, never raw content.
local for privacy, cloud for the semantic pass, cloud_with_fallback for resilience. Set per client, override per call.
How it works.
Zotniq is a control layer, not a monitor. Deterministic detection runs on device for common PII, credentials, and PHI. Cloud mode adds a server-side semantic classification pass for the cases you cannot pattern-match. Every decision is logged, every rule is inspectable, nothing is hidden.
Shipping this to production?
The developer story sits on top of the same platform your security team already evaluates. Here is where teams take it next.