Runtime control layer for AI.

Every prompt, every tool call, every action. Local by default, cloud when you need it.

pip install zotniq
PyPIPython 3.9+Async twinType-safeCLISIEM-ready

Three lines to start.

Local mode ships in the base package. No API key, no signup, no outbound HTTP. Add cloud when you want the semantic pass.

Detect · local, no key
from zotniq import Zotniq

client = Zotniq()  # no api_key needed — runs locally
findings = client.detect(
    "Contact [email protected] about SSN 123-45-6789"
)
# [Finding(type=EMAIL, ...), Finding(type=SSN, ...)]
Wrap OpenAI
from zotniq import Zotniq
from zotniq.integrations.openai import wrap_openai

openai_client = wrap_openai(
    Zotniq(api_key="zot_sk_..."),
    api_key="sk-...",
)
response = openai_client.chat.completions.create(
    model="gpt-4",
    messages=[{"role": "user", "content": "My SSN is 123-45-6789"}],
)
# SSN masked before OpenAI ever sees the prompt.
CLI
$ zotniq check "my email is [email protected]"
ALLOWED_WITH_MASKING · 1 finding
masked: "my email is b**@example.com"

$ echo "sk-abc123..." | zotniq check --json | jq .decision
"BLOCKED"

Local mode. Zero data leaves your machine.

Set mode="local" and every detection runs on device. No key. No network. No usage limit.

Local mode
from zotniq import Zotniq

# mode="auto" defaults to local when no api_key is set.
client = Zotniq()
client.mask("call me at 555-0199")
# "call me at XXX-XXX-0199"
What ships in the free tier
  • ·zotniq.detection subpackage: regex + Luhn + IBAN + SSN + PHI, zero dependencies, importable standalone
  • ·Zotniq() sync client and AsyncZotniq() async twin
  • ·CLI: zotniq check, zotniq mask
  • ·Type-safe Pydantic v2 wire types, full error hierarchy, retries, request-id echo

Add an API key when you want cloud detection, org policies, audit log, and the Developer Console.

Plugs into what you already use.

Live today: OpenAI drop-in, Anthropic drop-in, and the REST API. Rolling out through November: LangChain, LlamaIndex, LiteLLM, NVIDIA NeMo Guardrails, and the TypeScript SDK.

OpenAI
Live
REST API
Live
Anthropic
Live
LangChain
Ships November
LlamaIndex
Ships November
LiteLLM
Ships November
NVIDIA NeMo Guardrails
Ships November
TypeScript SDK
Ships November

Building on something not listed? The REST API works from any language.

cURL
curl https://api.zotniq.ai/v1/preflight/text \
  -H "X-Zotniq-API-Key: zot_sk_..." \
  -d '{"text": "my ssn is 123-45-6789", "destination": "AI_TOOL"}'

Every call, visible in your Developer Console.

No black box. Every decision, every finding, every masked span, every SIEM forward, in one console you own.

Live playground

Paste text, pick a destination, pick a mode. See decision, findings, and masked output. Copy the equivalent Python or cURL snippet in one click.

API keys, done right

Name each key. Rotate on click. Revoke on click. See last-used and per-key usage without touching the CLI.

Full request logs

30-day retention. Filter by request ID, user, model, decision. Download the whole feed as JSONL.

Webhooks and SIEM

Register on_decision endpoints. Wire up Splunk, Datadog, generic webhook, or local file. Monitor delivery health.

Rules as YAML

Read the team policy the way your engineers do. Download, version-track, upload. No drift between UI and code.

SDK version helper

Zotniq detects the client version on every call. See what is deprecated, what upgraded, and the exact upgrade command.

Console panels roll out through October. API keys and playground are live today.

Built for real production.

Async-native

AsyncZotniq is a full twin of the sync client. Use it inside FastAPI, Starlette, Django-async, or any asyncio loop.

Type-safe

Every wire type is Pydantic v2. Full mypy support. IDE autocomplete for Decision, Finding, Destination, and the full error hierarchy.

SIEM-ready

The on_decision hook fires per call. Splunk, Datadog, generic webhook, or local file forwarders bundled. Decision metadata only, never raw content.

Mode-flexible

local for privacy, cloud for the semantic pass, cloud_with_fallback for resilience. Set per client, override per call.

How it works.

Zotniq is a control layer, not a monitor. Deterministic detection runs on device for common PII, credentials, and PHI. Cloud mode adds a server-side semantic classification pass for the cases you cannot pattern-match. Every decision is logged, every rule is inspectable, nothing is hidden.

Runtime control layer for AI. In one line.

pip install zotniq