Airlock π β Let Cloud AI Work With Private Data Without Seeing It
Weβre building Airlock during MLH Hacktoberfest Hack Day β Coimbatore 2026.
The idea is simple:
Use powerful cloud AI without sending your private data to the cloud.
The problem
People paste sensitive information into AI tools every day:
- Customer names and emails
- Phone numbers
- API keys and passwords
- Financial information
- Internal project names
- Medical information
- Internal URLs and IP addresses
Traditional regex-based scanners can catch things like emails and API keys.
But they struggle with context.
For example:
The Henderson account is about to churn.
Their CFO Priya says the βΉ40L renewal is off
unless Project Falcon ships.
There may be no obvious secret or regex pattern here, but this still contains highly sensitive information.
Using another cloud AI to detect that information would defeat the purpose β the private data would already have left the machine.
Our solution: Airlock
Airlock is a local privacy gateway between your private data and cloud AI.
Private Prompt
β
AIRLOCK
β
Rules + Local Gemma 4
β
Risk Detection
β
Pseudonymization
β
Sanitized Prompt
β
Cloud AI
β
Answer with placeholders
β
Local Rehydration
β
Real Answer
The important part is that Gemma runs locally.
It sees the original private text and identifies sensitive information. The cloud model only receives the sanitized version.
Why use both rules and Gemma?
We use a two-tier approach.
Tier 1 β Deterministic rules
Handles things that can be detected reliably:
API keys
Emails
Credit cards
JWTs
Phone numbers
IP addresses
Tier 2 β Local Gemma 4
Handles information where context matters:
PERSON
ORG
PROJECT
FINANCIAL
MEDICAL
INTERNAL_URL
...
This gives us a combination of predictable rules and contextual detection.
Context-preserving placeholders
We don't simply replace everything with [REDACTED].
Instead:
Priya's email is priya@example.com
becomes:
[PERSON_1]'s email is [EMAIL_1]
This allows the cloud model to understand what kind of information it's dealing with while never receiving the original values.
When the cloud responds, Airlock locally restores safe placeholders:
[PERSON_1] β Priya
Secrets such as API keys, passwords, JWTs and card numbers are never rehydrated.
The interesting part
Our demo has a simple experiment.
First, we turn Wi-Fi off.
We paste a sensitive prompt and scan it.
Gemma still detects contextual information because it is running locally.
Then we turn Wi-Fi back on and send the sanitized prompt to the cloud.
The UI shows:
What you wrote:
Priya is working on Project Falcon.
What the cloud saw:
[PERSON_1] is working on [PROJECT_1].
The cloud gets the useful context.
It doesn't get the original identity.
Tech Stack
- Gemma 4 E2B IT β local contextual detection
- Foundry Local SDK + ONNX/WebGPU β local model execution
- FastAPI β backend
- Next.js β frontend
- Deterministic rules + risk scoring
- Cloud AI API β actual AI task
We're deliberately keeping our claims realistic.
Airlock isn't perfect detection or guaranteed anonymity. It's a local privacy-assistance layer designed to reduce sensitive-data exposure when using cloud AI.
What's next?
After the MVP, we'd like to explore:
- Browser extension
- Screenshot scanning
- Better evaluation
- Organisation-level policies
- Additional local models
- Audit and monitoring features
We're building Airlock as an open-source project for MLH Hacktoberfest Hack Day β Coimbatore 2026.
GitHub: https://github.com/vishalm342/Supes_MLH_Hack
Demo vedio: https://drive.google.com/file/d/1CzCj1M9mn1w5L0F8qau-raYzPtm6vTbs/view?usp=sharing
Gemma decides what's private on your machine. The cloud only ever sees placeholders.
That's Airlock. π
Top comments (0)