cd /news/ai-safety/before-an-llm-request-leaves-your-ap… · home › topics › ai-safety › article
[ARTICLE · art-143707] src=dev.to ↗ pub= topic=ai-safety verified=true sentiment=· neutral

Before an LLM request leaves your app, inspect what it contains

A developer has released Sether, an MIT-licensed open-source library that detects sensitive values in outbound text and replaces them with stable tokens before the prompt is sent to an LLM, keeping the token mapping inside the application so recognized values can be restored in the response. The project's founder frames the core question as "what actually left the application?" and notes the library is not a guarantee of full detection or regulatory compliance, with evaluation needed around detector selection, token-mapping ownership and lifetime, and values split across streaming chunks.

by read1 min views1 publishedOct 2, 2026

A support message can contain two different things: the task you want an AI model to perform, and details the model does not need to perform it.

“Draft a reply about a delayed delivery” is the task. A customer's email address in that same message may be unnecessary context.

I am building Sether around that boundary. It is an open-source library that replaces detected sensitive values with stable tokens before text goes to an LLM. Your application keeps the mapping and can restore recognized tokens in the response.

The useful question is not “did we add a privacy tool?” It is “what actually left the application?”

A practical evaluation has four parts:

Streaming adds another case: a value may be split across chunks. Include that in your tests rather than relying only on complete strings.

The token mapping also deserves attention. Decide which request or user owns it, who can read it, and how long it should exist. Redacting the outbound prompt is only one part of the application's data flow; logs, traces, attachments and downstream tools need their own review.

Sether is not a promise that every sensitive value will be detected, and installing it does not establish regulatory compliance. Detector selection, configuration and workflow evaluation matter.

The released library is MIT licensed. The hosted gateway is not part of this release.

Source and installation instructions: [https://github.com/raeven-co/sether](https://github.com/raeven-co/sether)

If you build AI support or internal-assistant workflows, which test would you want a redaction library to pass before you put it between your app and a model?

Disclosure: I am Sether's founder. This article was prepared with AI assistance using the project's documentation.

── more in #ai-safety 4 stories · sorted by recency
── more on @sether 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/before-an-llm-reques…] indexed:0 read:1min 2026-10-02 · —