Protecto Privacy Gateway for AI Chat runs between your LibreChat instance and whichever model you connected. Sensitive values are masked before the model sees them and unmasked on the way back, using controlled boundary resolution authorized by a per-user Protecto token, so your team works with real data and the model never holds it.
LibreChat is open-source and self-hosted, which keeps your data on your own infrastructure. It does not detect, mask, or redact sensitive data before sending it to a connected model. Protecto closes that gap: it masks PII, PHI, and other sensitive data in every prompt and uploaded document using entity-level detection and reversible tokenization, before LibreChat sends anything to OpenAI, Anthropic, Google, Azure, or Bedrock. The response comes back masked, and Protecto unmasks it before the user sees it. The user works with real data. The model only ever sees masked values.
LibreChat is open source and self-hosted. Teams choose it to get every model provider, OpenAI, Anthropic, Google, Azure, Bedrock, and more, behind one interface, on their own infrastructure, without per-seat SaaS pricing or vendor lock-in. Enterprise auth (SSO, SAML, LDAP, OAuth) ships in the free core.
LibreChat gives you infrastructure control, not content protection. Every prompt, every uploaded document, and every response can still carry names, phone numbers, account numbers, and other sensitive data straight into whichever model you’ve connected.
Self-hosting LibreChat solves where the data lives. It does not solve what the connected LLM sees.
The Gateway is deployed in the request path between LibreChat and your model providers. Inside LibreChat it surfaces as a selectable secure chat mode, so every prompt in that mode routes through the Gateway before it reaches the model.
You don't rebuild PII detection and masking logic for every model you connect to LibreChat. Protecto sits in the request path once and covers every model behind it, including new ones you add later. The Gateway is decoupled from the chat interface itself, so swapping LibreChat for another interface later doesn't mean rebuilding your protection layer. It's infrastructure you point at, not a plugin you're locked into.
Self-hosting LibreChat gives you infrastructure auditability. Protecto adds content-level protection on top of it, so sensitive data never reaches any model, internal or external, in the clear. You get visibility into exactly what was masked, when, and in which conversation, which is the evidence a HIPAA or GDPR review actually asks for.
The LibreChat chat experience doesn't change. You work with real data in the interface you already use. Protecto's masking and unmasking happens behind the scenes, in real time.
Protecto's Gateway for AI Chat works with any model connected to LibreChat, including OpenAI, Anthropic, Google, Azure, and AWS Bedrock. As you add models or providers to your LibreChat instance, they inherit the same protection automatically.
No. Protecto Privacy Gateway for AI Chat is decoupled from the chat interface. LibreChat is the integration available today; the Gateway runs the same way behind any interface that supports it.
No. LibreChat has no built-in data masking. Protecto adds a masking layer inside LibreChat’s secure chat mode.
YES!
No. Masking happens on content moving through the chat path, not on files already sitting in storage. Don’t rely on the Gateway to retroactively clean sensitive files you’ve already uploaded elsewhere.
Combine LibreChat’s native SSO, SAML, and LDAP with Protecto for content-level protection. Infrastructure control alone doesn’t stop sensitive data from reaching the model.
Yes. OpenAI, Anthropic, Google, Azure, and AWS Bedrock, since masking happens before the request leaves LibreChat, independent of provider.
No. Uploaded documents are masked before summarization, and the response is unmasked before the user sees it.
Independently verified controls and pre-built policies for the regulations your data is held to — SaaS, on-prem, or air-gapped.
Audited controls
Certified ISMS
BAA available
EU data ready
India · pre-built
US privacy
Talk to us about adding Protecto to your LibreChat deployment.