Protecto + LibreChat

Use LibreChat Without Sending Sensitive Values to LLMs

Protecto Privacy Gateway for AI Chat runs between your LibreChat instance and whichever model you connected. Sensitive values are masked before the model sees them and unmasked on the way back, using controlled boundary resolution authorized by a per-user Protecto token, so your team works with real data and the model never holds it.

The Gateway is not a LibreChat feature. It sits behind the chat interface, so the interface stays yours to change.
PROTECTO + LIBRECHAT – PRODUCT TOUR

Does LibreChat mask sensitive data by default? No.

LibreChat is open-source and self-hosted, which keeps your data on your own infrastructure. It does not detect, mask, or redact sensitive data before sending it to a connected model. Protecto closes that gap: it masks PII, PHI, and other sensitive data in every prompt and uploaded document using entity-level detection and reversible tokenization, before LibreChat sends anything to OpenAI, Anthropic, Google, Azure, or Bedrock. The response comes back masked, and Protecto unmasks it before the user sees it. The user works with real data. The model only ever sees masked values.

Why teams run LibreChat

Infrastructure control, on your own terms

LibreChat is open source and self-hosted. Teams choose it to get every model provider, OpenAI, Anthropic, Google, Azure, Bedrock, and more, behind one interface, on their own infrastructure, without per-seat SaaS pricing or vendor lock-in. Enterprise auth (SSO, SAML, LDAP, OAuth) ships in the free core.

 

The Gap

What's the gap between self-hosting and data protection?

LibreChat gives you infrastructure control, not content protection. Every prompt, every uploaded document, and every response can still carry names, phone numbers, account numbers, and other sensitive data straight into whichever model you’ve connected.

Self-hosting LibreChat solves where the data lives. It does not solve what the connected LLM sees.

How it works

How the Gateway works with LibreChat

The Gateway is deployed in the request path between LibreChat and your model providers. Inside LibreChat it surfaces as a selectable secure chat mode, so every prompt in that mode routes through the Gateway before it reaches the model.

01
You type a prompt containing sensitive data, same as always.
02
Protecto detects and masks the sensitive entities before the prompt leaves LibreChat.
03
The model, whether that's OpenAI, Anthropic, Google, or another connected provider, only ever sees masked values.
04
The model's response comes back with masked data intact.
05
Protecto unmasks the response before you see it. You read your original data. The model never did.
In a document
Upload a file and ask the model to summarize it. Protecto masks the sensitive content in the document before it's sent for summarization. You see the summary with real names, numbers, and details. The model generated it from masked values only.
You can inspect every step. Protecto shows the masked prompt, the specific values it identified and masked, and the unmasked response, side by side with the original.
Librechat

Why this matters

For engineering and platform teams

You don't rebuild PII detection and masking logic for every model you connect to LibreChat. Protecto sits in the request path once and covers every model behind it, including new ones you add later. The Gateway is decoupled from the chat interface itself, so swapping LibreChat for another interface later doesn't mean rebuilding your protection layer. It's infrastructure you point at, not a plugin you're locked into.

For security and compliance teams

Self-hosting LibreChat gives you infrastructure auditability. Protecto adds content-level protection on top of it, so sensitive data never reaches any model, internal or external, in the clear. You get visibility into exactly what was masked, when, and in which conversation, which is the evidence a HIPAA or GDPR review actually asks for.

For end users

The LibreChat chat experience doesn't change. You work with real data in the interface you already use. Protecto's masking and unmasking happens behind the scenes, in real time.

Model support

Protecto's Gateway for AI Chat works with any model connected to LibreChat, including OpenAI, Anthropic, Google, Azure, and AWS Bedrock. As you add models or providers to your LibreChat instance, they inherit the same protection automatically.

Openai, Chatgpt
Google Gemini Ai
Anthropic Claude
Deepseek
Grok By Xai
& more...

FAQ

Common Questions

Is this a LibreChat plugin?

No. Protecto Privacy Gateway for AI Chat is decoupled from the chat interface. LibreChat is the integration available today; the Gateway runs the same way behind any interface that supports it.

No. LibreChat has no built-in data masking. Protecto adds a masking layer inside LibreChat’s secure chat mode.

YES!

No. Masking happens on content moving through the chat path, not on files already sitting in storage. Don’t rely on the Gateway to retroactively clean sensitive files you’ve already uploaded elsewhere.

Combine LibreChat’s native SSO, SAML, and LDAP with Protecto for content-level protection. Infrastructure control alone doesn’t stop sensitive data from reaching the model.

Yes. OpenAI, Anthropic, Google, Azure, and AWS Bedrock, since masking happens before the request leaves LibreChat, independent of provider.

No. Uploaded documents are masked before summarization, and the response is unmasked before the user sees it.

Security & compliance

Certified, audited, and enterprise-ready

Independently verified controls and pre-built policies for the regulations your data is held to — SaaS, on-prem, or air-gapped.

SOC 2 Type II

Audited controls

ISO 27001

Certified ISMS

HIPAA

BAA available

GDPR

EU data ready

DPDP

India · pre-built

CCPA / CPRA

US privacy

Get started

Talk to us about adding Protecto to your LibreChat deployment.

Protecto Privacy Gateway for AI Chat is LIVE!
See how it works