2026-10-11 16:38 UTC

National Design Studio's Rampart releases a browser-native, on-device PII redaction system (deterministic rules + MiniLM, 14.7MB, 3.9ms latency) as an open-source privacy layer for browser-based agent workflows.

state: seedheat: lowuncertainty: mediumconvergesscott: highpii-redaction browser-agents on-device-ai agentic-securityTai GrootEdward CoristineNational Design Studio

What is this?

National Design Studio (NDS) has released Rampart, an open-source browser-native PII redaction system that runs entirely on-device. It combines deterministic regex rules with a MiniLM model (14.7MB total, ~3.9ms latency) to redact names, addresses, and other PII before data leaves the browser — positioned as a privacy layer for browser-based agent workflows. The release appears to be a first-party announcement from NDS; key names attached are Tai Groot and Edward Coristine. No independent press coverage or third-party verification surfaced in the web search (the search returned zero results), so the technical claims (model size, latency, detection scope) rest solely on the project's own announcement.

Why it matters to Scott

National Design Studio's Rampart release independently implements the exact architectural primitives Scott's canon has established for agentic privacy: deterministic+learned PII redaction (MiniLM, 14.7MB, ~3.9ms) running browser-native as a local-first privacy layer for agent workflows. This is not merely an example of a pattern Scott believes in — it is a consequential external party shipping open-source tooling that realizes the Runtime Containment / SiloOS / Proxy-Mediated Tokenisation stack at the browser edge, directly bearing on the model-size/latency budgets and deterministic-vs-learned tradeoffs his frameworks specify. If the claims hold, Rampart becomes a reference implementation for the 'privacy-tokenized agent boundary' and 'padded-cell agent architecture' concepts; if adoption grows, it pressures the ecosystem toward the local-first containment model Scott argues for.
ip:framework.siloosip:concept.runtime-containmentip:concept.proxy-mediated-tokenisationdev:concept.padded-cell-agent-architecturedev:concept.privacy-tokenized-agent-boundaryip:source.observability-for-agentic-systems-what-to-log-how-to-redact-how-to-debug-ebookdev:technology.microsoft-presidiodev:project.applianceradar:0pirate-ast-anonymizer-mcp-proxyradar:aegis-inline-ebpf-agent-containmentradar:abyss-acp-agent-isolationradar:actualis-local-coding-agent-observabilityradar:agentic-flooding-public-servicesradar:adversarial-comments-llm-vulnerability-detectors
queries asked of Scott's wikis
  • on-device inference in browser agents (WebGPU/WebAssembly, model size budgets, latency targets)
  • PII redaction as a primitive for agentic workflows (deterministic vs learned, false-positive/false-negative tradeoffs)
  • local-first privacy architecture for agents (data never leaves device, sandboxing, policy enforcement)
  • MiniLM / small transformer deployment in browser (ONNX Runtime Web, Transformers.js, quantization)
  • open-source agent tooling ecosystem (composability, supply-chain trust, adoption patterns)

Measured heat

now 0 pts/hpeak 11 pts/hcomments 0/hpeers p16momentum: steady2 platformsage 51h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

10-09 13:00⭐ origin echo-reconstructedOpen source Rampart — browser-native on-device PII redaction combining deterministic regex rules and MiniLM for names/addresses; 14.7MB mode
National Design Studio (Tai Groot, Edward Coristine) on blog (echo) · attributed from hn.story.50024242
—
10-09 17:52first on hacker news · published · +4.9hRampart: Browser native on-device PII radaction
nateb2022
—
10-09 17:52amplified on hacker news 👑hn.story.50024242
nateb2022
peak 82 · 32 comments · 100% of case engagement
10-10 15:33our radar first saw it · +26.6hdiscovery anchor: hn.story.50024242—
pace: p73 vs 1204 stories at the 48h mark (now 51h old) — ahead of nvidia-pair-local-inference-router (1.0x), behind qwen36-35b-finetunes-vs-base (1.0x)

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnRampart: Browser native on-device PII radaction
Retrieved article excerpt

Open article · Retrieved 2026-10-10T15:42:26.211001+00:00

TL;DR

Built by National Design Studio, Rampart runs entirely in the browser, identifying and removing personal information before a message is sent. It combines deterministic rules and machine learning to deliver privacy protection in milliseconds.

When you type into a chatbot, you might reveal more about yourself than you intend. A request to clean up an email carries your name and your coworker’s; a question about a medical bill carries your address and account number; a vented frustration carries who you are and where you live. And whatever you type doesn’t stay with you — it travels to a remote server you have no way to inspect.

Our core design principle is that the only personal information you can be sure is private is the information that never leaves your device.

Today, we open source Rampart — a first-generation on-device personal information filtering system that is a strong first line of defense in ensuring your personal information never leaves your device. Rampart is a combination of a deterministic layer, based on regular expressions to catch SSNs and ID numbers, and MiniLM to catch names and street addresses.

## Why we built Rampart

Often times, doing PII removal means either trusting a remote server or downloading binaries to the client, which present a few key challenges:

1. 1.AI privacy guarantees are almost impossible to verify. From first principles, it is impossible to verify the privacy and security claims of AI vendors. A newly deployed version of an AI runtime may accidentally begin logging sensitive user information, and services carry unknown internal security risks such as zero-day vulnerabilities and insider threats.
2. 2.Most models for PII removal are gigantic, narrowing the group of users that can benefit from them. For example, OpenAI Privacy Filter is ~2.8GB, which would take approximately 38 minutes to download to a browser on a relatively poor connection (10mbps).

## How it works

Everything happens in the browser, in the moment between typing a message and sending it; there is no server in the loop.

Model size, including tokenizer14.7MB

p50 runtime latency, in the browser (WebGPU)3.9ms

Private-term recall, seven languages98.4%

Before the message goes anywhere, two readers look at it on your device.

The first is a set of rules. Regular expressions paired with real validations handle the information that has structure: Social Security numbers, credit cards, phone numbers, routing and account numbers, emails, IP addresses, government IDs. It is deterministic and fast.

The second is a small language model. Rules can’t anticipate every name or street address, so MiniLM reads the sentence for the personal information with a deeper understanding of the context of the sentence, then redacts information it finds within a specific category.

For example, say you type a sentence full of personal information into chat:

Rampart redacts PII on-device so it doesn’t have to leave your device

The browser stores relevant PII temporarily on your device to fill in the blanks

My name is [GIVEN\_NAME] [SURNAME], my Social Security number is [SSN], and I make $1,950 a month. Can you help me find affordable housing?

Hi Maria,

Here are affordable housing options in New York.

The Eliza, Inwood, Manhattan | Affordable homes

### The Eliza

Inwood, Manhattan | Affordable homes

Sendero Verde, East Harlem, Manhattan | Affordable homes

### Sendero Verde

East Harlem, Manhattan | Affordable homes

Message

Original: My name is Maria Garcia, my Social Security number is 123-45-6789, and I make $1,950 a month. Can you help me find affordable housing?

After redaction: My name is [GIVEN\_NAME] [SURNAME], my Social Security number is [SSN], and I make $1,950 a month. Can you help me find affordable housing?

## Benchmarks

We trained Rampart on AI4Privacy’s OpenPII 1.5M dataset and a synthetic generator that reinforces all 17 entity types with deliberately messy chat-style input. The headline numbers below come from a 30,000-row held-out OpenPII slice spanning seven Latin-script languages, scored end-to-end by the shipped pipeline.

RampartDeterministic + model · 14.7 MB

98.42%

[OpenAI Privacy Filter↗(opens in new tab)](https://huggingface.co/openai/privacy-filter)Model · ~2.8 GB

97.4%

GLiNER small v2.1Model · ~600 MB

94.2%

Community BERT-small PIIModel · ~29 MB

81.5%

Microsoft PresidioDeterministic + model · ~13 MB

65%

AWS Bedrock GuardrailsModel · Cloud

63.8%

Private-term recall on a 30,000-row held-out OpenPII test set across seven supported languages. Higher is better. [Benchmark↗(opens in new tab)](https://inference.ndstudio.gov/rampart/whitepaper.pdf)

## Limitations

Rampart is an alpha product intended to be the first line of defense in a more thorough effort to manage personally identifiable information for AI chat experiences. It currently supports English, Spanish, French, German, Italian, Portuguese, and Dutch.

## Get started

Download the model on HuggingFace, install the NPM library, or read the whitepaper.

If the work of building elegant and useful tools for Americans speaks to you, consider joining NDS.

chat.ts

```
​import { createGuard } from "@nationaldesignstudio/rampart​"​;​



​



​const guard = await createGuard​(​)​;​



​



​const safe = await guard​.​protect​(​



"​My name is John Wick​. I live at 88 Cedar Lane​, Brookvale​, CT 06482​.​"​,​



​)​;​



​



​console​.​log​(​safe​.​text​)​;​



​// "My name is [GIVEN_NAME_1]. I live at [BUILDING_NUMBER_1] [STREET_NAME_1], Brookvale, CT 06482."​



​



​const reply = await llm​(​safe​.​text​)​;​



​console​.​log​(​guard​.​reveal​(​reply​)​)​;​



​



​async function llm​(​text: string​): Promise<string> {​



return "​Thanks [GIVEN_NAME_1]​, Brookvale CT 06482 works for eligibility​.​"​;​



​}​



​// "Thanks John Wick, Brookvale CT 06482 works for eligibility."​
```

[HuggingFace↗(opens in new tab)](https://huggingface.co/nationaldesignstudio/rampart)[NPM library↗(opens in new tab)](https://www.npmjs.com/package/@nationaldesignstudio/rampart)[Whitepaper↗(opens in new tab)](https://inference.ndstudio.gov/rampart/whitepaper.pdf)
nateb20228232
🟧 echo.blog ⭐Open source Rampart — browser-native on-device PII redaction combining deterministic regex rules and MiniLM for names/addresses; 14.7MB modeNational Design Studio (Tai Groot, Edward Coristine)——

Interpretation history

Decision trace