<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: 李成斐</title>
    <description>The latest articles on DEV Community by 李成斐 (@_df5259e5cebd3a923371e).</description>
    <link>https://dev.to/_df5259e5cebd3a923371e</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.us-east-2.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F4056295%2Fb992cc3f-574e-4323-b0e8-efdbde9ab1ad.jpg</url>
      <title>DEV Community: 李成斐</title>
      <link>https://dev.to/_df5259e5cebd3a923371e</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/_df5259e5cebd3a923371e"/>
    <language>en</language>
    <item>
      <title>The one-person company workflow: how to track every document you send</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Fri, 28 Aug 2026 12:02:21 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/the-one-person-company-workflow-how-to-track-every-document-you-send-1jmo</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/the-one-person-company-workflow-how-to-track-every-document-you-send-1jmo</guid>
      <description>&lt;h1&gt;
  
  
  The one-person company workflow: how to track every document you send
&lt;/h1&gt;

&lt;p&gt;Running a one-person company means every document you send is a direct extension of your time: proposals, contracts, pricing sheets, follow-ups. And the worst part isn't writing them - it's the silence after.&lt;/p&gt;

&lt;p&gt;You send a proposal on Monday. Wednesday you ping the prospect: "just checking in." They say "still reviewing." You wait. Another week passes.&lt;/p&gt;

&lt;p&gt;Meanwhile, the document sat unread in their inbox the entire time - and you had no way to know.&lt;/p&gt;

&lt;h2&gt;
  
  
  A document workflow for solo founders
&lt;/h2&gt;

&lt;p&gt;The tools solo founders usually rely on (email attachments, Google Drive links, Notion pages) share one flaw: &lt;strong&gt;they treat sending as the end of the process&lt;/strong&gt;. In reality, sending is the beginning of the part that matters - reading.&lt;/p&gt;

&lt;p&gt;A practical workflow with &lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt;:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Send with a tracked link&lt;/strong&gt; - every proposal, contract, and pricing page becomes a tracked document (one paste, no plugin)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Watch the reading signals&lt;/strong&gt; - you see when it's opened, which pages get attention (pricing? terms?), and how long&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Follow up with intent&lt;/strong&gt; - instead of blind "checking in," you follow up &lt;em&gt;because&lt;/em&gt; the pricing page was read twice yesterday&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Close the loop&lt;/strong&gt; - the document's access log becomes part of your deal record: who saw what, when&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Why this matters more for solo founders
&lt;/h2&gt;

&lt;p&gt;In a team, someone might casually mention "oh, they opened the deck last week." When you're alone, there is no such person. The document itself must tell you.&lt;/p&gt;

&lt;p&gt;It also protects you: a tracked link with expiry and watermarking means your pricing sheet doesn't float around forever.&lt;/p&gt;

&lt;h2&gt;
  
  
  The tools
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; - document tracking (free tier)&lt;/li&gt;
&lt;li&gt;A simple CRM or even a spreadsheet - for the follow-up schedule&lt;/li&gt;
&lt;li&gt;Calendar reminders keyed to &lt;em&gt;reading events&lt;/em&gt;, not send dates&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;Send your next proposal with a tracked link. The follow-up conversation writes itself.&lt;/p&gt;

&lt;p&gt;Stop guessing. Know who read it.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>indiehackers</category>
      <category>saas</category>
      <category>founder</category>
    </item>
    <item>
      <title>The proposal you sent is a black box. Here is what document tracking reveals</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:32:01 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/the-proposal-you-sent-is-a-black-box-here-is-what-document-tracking-reveals-1pd5</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/the-proposal-you-sent-is-a-black-box-here-is-what-document-tracking-reveals-1pd5</guid>
      <description>&lt;h1&gt;
  
  
  The proposal you sent is a black box. Here is what document tracking reveals
&lt;/h1&gt;

&lt;p&gt;You send a proposal on Tuesday. On Friday, the prospect says "we're still reviewing." You have no idea whether:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;They opened it at all (or it went to spam)&lt;/li&gt;
&lt;li&gt;They read the pricing page, or skipped straight to the deliverables&lt;/li&gt;
&lt;li&gt;The decision-maker saw it, or only their assistant did&lt;/li&gt;
&lt;li&gt;They forwarded it to a competitor for comparison&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;In B2B sales, follow-up timing is everything. The window right after someone reads your proposal is when they are most engaged - and most likely to make a decision. But if you don't know they read it, you miss that window.&lt;/p&gt;

&lt;h2&gt;
  
  
  What tracking changes
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; attaches reading intelligence to every document you share:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Open + per-page reads&lt;/strong&gt; - know exactly which sections got attention (pricing? case studies? terms?)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Time on page&lt;/strong&gt; - a 6-minute read of your pricing page means something very different from a 20-second skim&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Forward detection&lt;/strong&gt; - know when your proposal was shared internally (a good sign) or externally (worth a call)&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Alerts in real time&lt;/strong&gt; - the moment a key page is read, you know it&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  The follow-up script becomes obvious
&lt;/h2&gt;

&lt;p&gt;Instead of "just checking in," you can say:&lt;/p&gt;

&lt;blockquote&gt;
&lt;p&gt;"I noticed you spent time on the pricing section - happy to walk through the numbers if useful."&lt;/p&gt;
&lt;/blockquote&gt;

&lt;p&gt;That's not creepy - that's &lt;em&gt;useful&lt;/em&gt;. It shows attention, saves the prospect effort, and puts you in the follow-up conversation from a position of insight, not guesswork.&lt;/p&gt;

&lt;h2&gt;
  
  
  For teams, not just individuals
&lt;/h2&gt;

&lt;p&gt;Sales managers get visibility too: which reps send tracked links, which deals have engaged stakeholders, which proposals went dark. The pipeline stops being vibes.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; - free tier included. Send a proposal, share the link, and watch the read signals arrive.&lt;/p&gt;

&lt;p&gt;Stop guessing. Know what they read.&lt;/p&gt;

</description>
      <category>sales</category>
      <category>productivity</category>
      <category>saas</category>
      <category>b2b</category>
    </item>
    <item>
      <title>Sending sensitive documents? Here is how to stay in control</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Thu, 27 Aug 2026 13:01:56 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/sending-sensitive-documents-here-is-how-to-stay-in-control-cgj</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/sending-sensitive-documents-here-is-how-to-stay-in-control-cgj</guid>
      <description>&lt;h1&gt;
  
  
  Sending sensitive documents? Here is how to stay in control
&lt;/h1&gt;

&lt;p&gt;When you send a confidential document - an M&amp;amp;A data room, a draft NDA, a term sheet, a due diligence file - you are handing over control. The question is not whether the recipient is trustworthy; it is whether you can &lt;em&gt;know&lt;/em&gt; what happened after send.&lt;/p&gt;

&lt;h2&gt;
  
  
  The gap in "secure sharing"
&lt;/h2&gt;

&lt;p&gt;Most secure sharing tools stop at access control: passwords, expiry links, watermarks. They protect the &lt;em&gt;perimeter&lt;/em&gt;. But they leave you blind to what happens inside:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Did the counterparty's counsel actually open the NDA, or is it still sitting unread?&lt;/li&gt;
&lt;li&gt;Which partner downloaded which file from the data room?&lt;/li&gt;
&lt;li&gt;Did anyone forward your deck to a third party you never authorized?&lt;/li&gt;
&lt;li&gt;After a deal falls through, can you produce an audit trail of who saw what?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;For FA teams, law firms, and sales organizations, these aren't nice-to-haves. They are the difference between "we think the deal is on track" and "we know the other side read the final terms last night."&lt;/p&gt;

&lt;h2&gt;
  
  
  What tracking adds
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; layers &lt;em&gt;visibility&lt;/em&gt; on top of the usual security controls:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Per-page access logs&lt;/strong&gt; - see exactly who opened which pages, when, and for how long&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Download detection&lt;/strong&gt; - know when a document was downloaded, and flag it in real time&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Forward-chain tracking&lt;/strong&gt; - if a link gets shared, you see the chain&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Audit trail&lt;/strong&gt; - a complete record of access, useful for disputes and compliance&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Granular controls&lt;/strong&gt; - password / email-OTP, expiry, dynamic watermarking, and disable download/print/copy per link&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Privacy-respecting by design: visitors are told they are being tracked, and tracking can be switched off per link.&lt;/p&gt;

&lt;h2&gt;
  
  
  The use cases
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;M&amp;amp;A / FA&lt;/strong&gt;: know which buyer's team actually reviewed the data room before the term sheet&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Legal&lt;/strong&gt;: prove (or disprove) that a counterparty saw the NDA - with timestamps&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Sales&lt;/strong&gt;: know the procurement officer read the proposal - and what they lingered on&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;HR&lt;/strong&gt;: track offer letters and reference checks&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; is live with a free tier. Send a document, share the link, and watch the reading behavior arrive in real time.&lt;/p&gt;

&lt;p&gt;Stay in control. Know what happens after send.&lt;/p&gt;

</description>
      <category>security</category>
      <category>saas</category>
      <category>productivity</category>
      <category>legaltech</category>
    </item>
    <item>
      <title>Sent a pitch deck? Stop guessing whether they read it</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Thu, 27 Aug 2026 12:31:49 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/sent-a-pitch-deck-stop-guessing-whether-they-read-it-34ag</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/sent-a-pitch-deck-stop-guessing-whether-they-read-it-34ag</guid>
      <description>&lt;h1&gt;
  
  
  Sent a pitch deck? Stop guessing whether they read it
&lt;/h1&gt;

&lt;p&gt;Every founder, FA, and salesperson knows the feeling: you send your pitch deck or proposal, and then... nothing. A black box.&lt;/p&gt;

&lt;p&gt;Did they read it? Which pages? For how long? Did they forward it to their partner?&lt;/p&gt;

&lt;p&gt;Email attachments, WeChat files, and cloud links all have the same problem: &lt;strong&gt;zero visibility after send&lt;/strong&gt;.&lt;/p&gt;

&lt;h2&gt;
  
  
  The cost of the black box
&lt;/h2&gt;

&lt;p&gt;For a founder raising a round, this isn't just curiosity - it's strategy:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;You send your deck to 30 investors, 3 reply, and you have &lt;strong&gt;no idea&lt;/strong&gt; which of the other 27 actually read it.&lt;/li&gt;
&lt;li&gt;The "golden follow-up window" (usually within 24 hours of reading) gets wasted because you don't know they read it.&lt;/li&gt;
&lt;li&gt;Your weekly update to the board says "contacted X investors" - a number that is essentially made up.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The same story plays out in B2B sales (did the procurement officer open the proposal?), legal (did the counterparty's counsel actually review the NDA?), and hiring (did the candidate's reference actually read the offer?).&lt;/p&gt;

&lt;h2&gt;
  
  
  The fix: document tracking
&lt;/h2&gt;

&lt;p&gt;&lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;DocTrail&lt;/a&gt; is a document sharing and tracking tool built for this exact problem:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Per-page reading analytics&lt;/strong&gt; - see exactly which pages were read, in what order, and for how long&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Reading completion + heatmaps&lt;/strong&gt; - know if they skimmed or studied&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Forward-chain tracking&lt;/strong&gt; - see if your deck was forwarded, and to whom&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Real-time notifications&lt;/strong&gt; - get pinged the moment someone opens your document&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Security controls&lt;/strong&gt; - password / email-OTP access, NDA prompts, expiry links, dynamic watermarking, and disable download/print/copy&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;It's privacy-respecting by design: visitors are informed before access, and tracking can be disabled per link.&lt;/p&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;DocTrail is live at &lt;a href="https://doctrail.pages.dev" rel="noopener noreferrer"&gt;doctrail.pages.dev&lt;/a&gt;. Free tier included.&lt;/p&gt;

&lt;p&gt;Stop guessing. Know who read it.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>saas</category>
      <category>startup</category>
      <category>tools</category>
    </item>
    <item>
      <title>Why One Person Can Run an AI Company Today</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Sat, 22 Aug 2026 02:17:59 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/why-one-person-can-run-an-ai-company-today-20pk</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/why-one-person-can-run-an-ai-company-today-20pk</guid>
      <description>&lt;h2&gt;
  
  
  Why One Person Can Run an AI Company Today
&lt;/h2&gt;

&lt;p&gt;一、AI CEO（atoma）通过 MCP 连接 8 个业务系统、258 个工具。&lt;/p&gt;

&lt;p&gt;二、闭环：产品（虚拟工具包 5 站）→ 流量（dev.to 内容 + 截流 + GEO）→ 转化（PayPal）→ 交付（HMAC 下载）→ 归因追踪。&lt;/p&gt;

&lt;p&gt;三、本文由 AI CEO 一句话自动发布（publish_engine MCP 工具）。&lt;/p&gt;

</description>
      <category>ai</category>
      <category>startup</category>
      <category>automation</category>
      <category>business</category>
    </item>
    <item>
      <title>DocTrail: Know Exactly Who Read Your Documents</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Sat, 22 Aug 2026 00:13:05 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/doctrail-know-exactly-who-read-your-documents-1i5m</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/doctrail-know-exactly-who-read-your-documents-1i5m</guid>
      <description>&lt;h2&gt;
  
  
  DocTrail
&lt;/h2&gt;

&lt;p&gt;Track document opens, read time, and engagement — the DocSend alternative with analytics built in.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Real-time alerts&lt;/strong&gt; when someone opens your doc&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Per-page engagement&lt;/strong&gt; tracking&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Privacy-first&lt;/strong&gt; design&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Perfect for sales decks, proposals, and investor materials.&lt;/p&gt;

</description>
      <category>productivity</category>
      <category>saas</category>
      <category>analytics</category>
    </item>
    <item>
      <title>AI Privacy Gateway: Strip PII from AI Prompts Before They Leave Your Machine</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Fri, 21 Aug 2026 23:12:14 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/ai-privacy-gateway-strip-pii-from-ai-prompts-before-they-leave-your-machine-4d47</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/ai-privacy-gateway-strip-pii-from-ai-prompts-before-they-leave-your-machine-4d47</guid>
      <description>&lt;h1&gt;
  
  
  AI Privacy Gateway
&lt;/h1&gt;

&lt;p&gt;A practical guide to keeping your sensitive data out of AI prompts.&lt;/p&gt;

&lt;h2&gt;
  
  
  Why it matters
&lt;/h2&gt;

&lt;p&gt;Every prompt you send to a cloud LLM contains potentially sensitive information. A privacy gateway sits between you and the model, stripping PII before anything leaves your machine.&lt;/p&gt;

&lt;h2&gt;
  
  
  How it works
&lt;/h2&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Intercept&lt;/strong&gt; — the gateway captures outgoing prompts&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Detect&lt;/strong&gt; — PII detectors identify emails, phones, addresses, keys&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Redact&lt;/strong&gt; — sensitive tokens are replaced with placeholders&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Forward&lt;/strong&gt; — the sanitized prompt goes to the model&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Restore&lt;/strong&gt; — the response is rehydrated with original values&lt;/li&gt;
&lt;/ol&gt;

&lt;h2&gt;
  
  
  Key benefits
&lt;/h2&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Local-first&lt;/strong&gt; — processing happens on your device&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Zero-knowledge&lt;/strong&gt; — providers never see your data&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Drop-in&lt;/strong&gt; — works with any OpenAI-compatible endpoint&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Try it
&lt;/h2&gt;

&lt;p&gt;The full implementation is available as an open-source project with a CLI, a local gateway daemon, and MCP integration for AI agents.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>privacy</category>
      <category>security</category>
      <category>opensource</category>
    </item>
    <item>
      <title>AI Privacy Gateway — strip PII from AI prompts before they leave your machine</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Mon, 17 Aug 2026 13:03:31 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/ai-privacy-gateway-strip-pii-from-ai-prompts-before-they-leave-your-machine-3b59</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/ai-privacy-gateway-strip-pii-from-ai-prompts-before-they-leave-your-machine-3b59</guid>
      <description>&lt;p&gt;Every AI coding assistant (Cursor, Claude Code, Copilot) sends your code to third-party servers. Every time you paste customer data into ChatGPT, that data leaves your machine. Every DeepSeek prompt crosses an international border.&lt;/p&gt;

&lt;p&gt;I wanted a dead-simple fix: a local proxy that strips PII from AI API calls before they leave my machine. No SaaS dependency. No "sign up for enterprise." Just &lt;code&gt;docker run&lt;/code&gt; and forget it.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;AI Privacy Gateway&lt;/strong&gt; is a transparent HTTP reverse proxy that does exactly that:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;30-second deploy:&lt;/strong&gt; &lt;code&gt;docker run -d -p 9999:9999 ghcr.io/gunxueqiu6/ai-privacy-gateway:lite&lt;/code&gt; — then change your AI client's base URL to &lt;code&gt;http://localhost:9999&lt;/code&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;26 entity types auto-detected (v2.0.3):&lt;/strong&gt; phone numbers, email addresses, China ID cards (18-digit), bank cards (Luhn-validated), API keys (20+ known formats: OpenAI &lt;code&gt;sk-&lt;/code&gt;, AWS &lt;code&gt;AKIA&lt;/code&gt;, GitHub &lt;code&gt;ghp_&lt;/code&gt;, Stripe &lt;code&gt;sk_live_&lt;/code&gt;, etc.), China Unified Social Credit Codes, passports and HK/Macau/Taiwan permits, IPs, URLs, dates, amounts, postcodes, plate numbers, coordinates, MACs, person names (Chinese + English via optional spaCy NER), and custom regex patterns&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;&amp;lt;1ms latency overhead (self-measured):&lt;/strong&gt; a compiled union regex pattern makes one pass per request; optional NER fallback adds ~2–5ms for fuzzy entities&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;SSE streaming support:&lt;/strong&gt; sliding-window buffer resolves entity boundaries across chunk boundaries — no buffering delay, no missed PII&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;AES-256-GCM encrypted vault:&lt;/strong&gt; optional persistent mapping storage for round-trip reconstruction; stateless mode available&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Works with any OpenAI-compatible API:&lt;/strong&gt; ChatGPT, Claude, DeepSeek, Cursor, Copilot, Open WebUI — anything that can change its base URL&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PolyForm Shield:&lt;/strong&gt; free for noncommercial use, source available, zero telemetry, fully local&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;Why I built it:&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I work with customer data — phone numbers, emails, transaction records. Every week I'd catch myself pasting something containing PII into an AI tool. The existing options were all wrong for my use case:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;LLM Guard&lt;/strong&gt; (MIT): Python SDK with transformer deps — slow install, ~5ms latency, no SSE streaming&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Presidio&lt;/strong&gt; (MIT): Microsoft's analyzer — Docker Compose + NLP models + PostgreSQL, no Chinese NER out of the box, no proxy mode&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Nightfall / Private AI&lt;/strong&gt; (commercial): cloud-hosted, enterprise-priced, your data hits their servers&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;PasteGuard&lt;/strong&gt; (MIT): browser extension only — misses API tools like Cursor or Claude Code&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;None of them let me change one URL and be done.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Architecture (simplified):&lt;/strong&gt;&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;[AI Client] --raw request--&amp;gt; [Privacy Gateway :9999] --masked request--&amp;gt; [AI API]
                              |
                              +-- [Regex Engine: 26 patterns, &amp;lt;1ms]
                              +-- [spaCy NER: names, locations, orgs (optional)]
                              +-- [AES-256-GCM Vault: optional mapping storage]
                              +-- [Audit Log: JSON/Syslog]
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The proxy intercepts requests to &lt;code&gt;/v1/chat/completions&lt;/code&gt;, scans the JSON body for PII patterns, replaces matches with typed placeholders (&lt;code&gt;[PHONE_abc123]&lt;/code&gt;, &lt;code&gt;[EMAIL_xyz789]&lt;/code&gt;), then forwards the sanitized request upstream. The AI provider gets semantic context — but never raw sensitive values.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Tech stack:&lt;/strong&gt; Python 3.11+ / FastAPI, compiled regex engine, spaCy (zh_core_web_sm + en_core_web_sm), SQLite encrypted vault (AES-256-GCM), SSE sliding-window buffer, pub/sub audit bus, optional load balancer for multiple upstreams.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Current status:&lt;/strong&gt; v2.0.3. Tests with adversarial fuzzing; benchmark suite in CI (self-measured on our test corpus).&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Honest limitations:&lt;/strong&gt;&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;Regex misses unconventional PII formats — transparent about ~95% recall for structured types on our test corpus, not 100%&lt;/li&gt;
&lt;li&gt;NER recall for Chinese names is imperfect — catches common names, misses uncommon ones&lt;/li&gt;
&lt;li&gt;False positives on things like long order numbers triggering bank-card patterns — a &lt;code&gt;--strict&lt;/code&gt; flag helps&lt;/li&gt;
&lt;li&gt;Single-process Python server — scale behind nginx for high throughput&lt;/li&gt;
&lt;li&gt;Masking is not a silver bullet: if the model already knows a person from context, placeholders can still be connected — redaction mode (&lt;code&gt;[REDACTED]&lt;/code&gt;, irreversible) exists for higher-stakes data&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;&lt;strong&gt;What I want feedback on:&lt;/strong&gt;&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Does the proxy-vs-SDK tradeoff make sense for your team?&lt;/li&gt;
&lt;li&gt;Which PII types are missing for your use case?&lt;/li&gt;
&lt;li&gt;Would you use a managed enterprise version (self-hosted, RBAC, audit export, SLA)?&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;GitHub: &lt;a href="https://github.com/gunxueqiu6/ai-privacy-gateway" rel="noopener noreferrer"&gt;https://github.com/gunxueqiu6/ai-privacy-gateway&lt;/a&gt;&lt;br&gt;
Website/Demo: &lt;a href="https://privacygw.pages.dev" rel="noopener noreferrer"&gt;https://privacygw.pages.dev&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Happy to answer technical questions about the regex engine, streaming buffer, or vault design.&lt;/p&gt;

</description>
      <category>security</category>
      <category>ai</category>
      <category>privacy</category>
      <category>opensource</category>
    </item>
    <item>
      <title>MatrixGrow Publish OK 151931</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Mon, 17 Aug 2026 07:19:26 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-publish-ok-151931-5934</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-publish-ok-151931-5934</guid>
      <description>&lt;h1&gt;
  
  
  MatrixGrow Publish OK 151931
&lt;/h1&gt;

&lt;p&gt;Automated test - publish channel verified.&lt;/p&gt;

&lt;h2&gt;
  
  
  Content
&lt;/h2&gt;

&lt;p&gt;End to end publish works.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>automation</category>
    </item>
    <item>
      <title>MatrixGrow Publish Test 151854</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Mon, 17 Aug 2026 07:18:48 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-publish-test-151854-fkm</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-publish-test-151854-fkm</guid>
      <description>&lt;h1&gt;
  
  
  MatrixGrow Publish Test 151854
&lt;/h1&gt;

&lt;p&gt;Automated test via MatrixGrow API - unique title check.&lt;/p&gt;

&lt;h2&gt;
  
  
  Content
&lt;/h2&gt;

&lt;p&gt;Verifying the publish channel works end to end.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>automation</category>
    </item>
    <item>
      <title>MatrixGrow Channel Verification</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Mon, 17 Aug 2026 07:17:24 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-channel-verification-og</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-channel-verification-og</guid>
      <description>&lt;h1&gt;
  
  
  MatrixGrow Channel Verification
&lt;/h1&gt;

&lt;p&gt;This is an automated test post from the MatrixGrow content distribution pipeline.&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Testing API publish channel&lt;/li&gt;
&lt;li&gt;Will be deleted after verification&lt;/li&gt;
&lt;/ul&gt;

&lt;h2&gt;
  
  
  Why MatrixGrow
&lt;/h2&gt;

&lt;p&gt;MatrixGrow is an AI content distribution engine supporting 28+ platforms.&lt;/p&gt;

</description>
      <category>ai</category>
      <category>automation</category>
      <category>devtools</category>
    </item>
    <item>
      <title>MatrixGrow API Test</title>
      <dc:creator>李成斐</dc:creator>
      <pubDate>Mon, 17 Aug 2026 07:15:36 +0000</pubDate>
      <link>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-api-test-2a</link>
      <guid>https://dev.to/_df5259e5cebd3a923371e/matrixgrow-api-test-2a</guid>
      <description>&lt;h1&gt;
  
  
  MatrixGrow Channel Verification&lt;code&gt;n&lt;/code&gt;nAutomated test via MatrixGrow API.
&lt;/h1&gt;

</description>
    </item>
  </channel>
</rss>
