Skip to main content
Get StartedOverviewPricingProofsIntegrations

AI tools leak your data. Transmute catches it before it leaves your machine.

Every time you use Claude Code, Cursor, Copilot, or any AI tool, sensitive information can slip into the prompt. API keys, .env files, database credentials, customer records, sent to external servers you don't control. Transmute installs on your machine and catches it automatically, on every call, without anyone remembering to sanitise a prompt.

Detection is pattern-based and scoped to the filter packs you run: a tight net, tuned to your data, not a guarantee that nothing ever slips. What it matches is replaced before the request leaves, and every match is logged as evidence.

No cloud service. One install, every AI tool on that machine is protected. Subscribe to the app from $49.99/mo, or own the source outright with a scoped engagement.

Download Transmute

Available for macOS, Windows, and Linux. Choose Core, Pro, or Max.

Purfect Labs Transmute

The refinement process.

The value is in what you can do with the data. Leave matched sensitive identities out, refine the content moving through AI, and capture what currently goes uncollected for your own pipeline and analysis.

01 · De-identification

Leave the identities out.

Give AI the context it needs without the sensitive values your filters match. Replace names, identifiers, and secrets with placeholders; restore the mapped values in responses. Add human review before release where required.

02 · Transformation engine

Refine what flows through.

Define how data changes as it moves through your AI workflow. Apply configured filters to supported text and attachments, preserve useful context, and inspect the transformed payload before it leaves.

03 · Data pipeline & analytics

Mine what went uncaptured.

Capture AI activity that currently goes uncollected. Retain supported records in your own storage, bring sanitized events together, and build a foundation for mining, workflow analysis, and business insights.

Capture, audit, and federation capabilities depend on your edition and configuration. Broader mining and intelligence analytics are the direction we’re building toward.

Purfect Labs Transmute · Runs on your machine

For developers, dev shops, SaaS teams, and AI enthusiasts. Subscribe to the app, or own the source outright.

Turn raw data
into gold.

Keep your secrets out of the furnace.

Transmute de-identifies matched sensitive information before it reaches AI. Its transformation engine refines what flows through your tools, while its data pipeline captures activity that currently goes uncollected—creating raw material for mining, analytics, and insights.

No hosted service. Source-delivered tiers: no license server, no subscription. You own the source.

Flat, scoped engagements. No per-seat or per-token meter, no usage billing.

Capture needs a security layer

The same AI interactions that can reveal useful patterns may contain customer details, credentials, or internal documents. Transmute puts transformation into the workflow: protect matched sensitive values before model calls, then retain supported activity under your own capture policies.

Cloud credentials
AWS_ACCESS_KEY_ID, GCP service-account JSON
Source-control tokens
ghp_..., GitLab PATs, gho_...
API keys
sk-ant-..., sk-..., internal service tokens
Environment secrets
.env contents read into context by a tool
Database credentials
Postgres / Mongo connection strings
JWTs
eyJ... tokens in headers, args, fixture files
Domain PII
SSNs, patient names, DOBs, card PANs
Tool exfiltration
Tool trying to read ~/.ssh/, ~/.aws/, /etc/shadow

Asking your team to manually sanitize every prompt is asking them to stop shipping.

How we engage

We work with your team, whether that's your CTO, compliance officer, IT director, or department head. If your organization is adopting AI and worried about what's leaking, we deploy with whoever owns that risk. Engineering handles the technical install; leadership gets the compliance evidence. Everyone stays in their lane.

What the model saw
[REDACTED:AWS_KEY_001]
[REDACTED:PHI_NAME_001]
[REDACTED:JWT_001]
...sanitized payload

Redacted tokens. Sanitized payloads. Matched PHI never sent in the clear.

What your developer saw
AKIA2X9...REAL_KEY
Sarah Johnson
eyJhbGci...full_token
...full response

Real values. Full responses. Nothing hidden from the developer.

Belt and suspenders, plugin catches obvious leaks at the agent-loop boundary, gateway scrubs the wire. If one layer misses, the other catches.

Two ways to run Transmute

Subscribe to the app, or scope a source-delivered platform around your data and workflows.

Self-serve: download, subscribe, done. No engagement, no scoping call. Choose Core, Pro, or Max for macOS, Windows, or Linux.

Download without an account. Choose your plan and activate Transmute with your license key.

Transmute Core
$49.99/mo per seat $55.54
per seat · up to 6 seats
Monthly$49.99/mo Save 10%
Yearly$479.90/yr Save 20%
  • ✓Tokenizing proxy for every covered tool
  • ✓Secrets & PII filter packs
  • ✓Codex, OpenAI, Hermes, Claude Code & CLI coverage
  • ✓Local tamper-evident audit log
  • ✓Download without an account
Download Transmute
Transmute Pro
$79.99/mo per seat $94.11
per seat · up to 6 seats
Monthly$79.99/mo Save 15%
Yearly$767.90/yr Save 20%
  • ✓Everything in Core
  • ✓Audit dashboard with per-tool visibility
  • ✓Custom filter packs for your domain
  • ✓Evidence export for SOC 2 / HIPAA programs
  • ✓License panel with self-serve data deletion
Download Transmute
Transmute Max
$99.99/mo per seat $124.99
per seat · up to 6 seats
Monthly$99.99/mo Save 20%
Yearly$959.90/yr Save 20%
  • ✓Everything in Pro
  • ✓IQ beta: AI-assisted detection filters
  • ✓Managed configs (MDM) for fleet rollout
  • ✓Team enforcement policies
  • ✓Priority support
Download Transmute

The Platform · what extends the app

Build the capture and transformation workflow around your team. Bring recorded activity together, inspect what changed, and keep the infrastructure and source under your control.

A pipeline shaped around your work
Adapt capture and transformation to your data and workflows through source-delivered extension points.
Know when the pipeline needs attention
See the health of connected services and recover from failures with managed retries and circuit breakers.
Bring the activity together
Federate sanitized events into your own S3 storage. Explore recorded activity across hosts and teams while raw originals stay on their source machines.
Make transformations accountable
Keep a tamper-evident record of transformations. Review what happened and export evidence for your compliance program.
Process sensitive content on your infrastructure
Run configured detection models in your environment. Add contextual analysis without sending that detection work to a vendor-hosted service.
Preserve useful context
Use supported entity detection and linkage to replace sensitive values while retaining the roles and relationships a model needs.
🔒

Your data never touches our infrastructure

The gateway runs on your network. The audit log writes to your S3 with your encryption keys under your retention policy. There is no Transmute cloud. Captured activity stays in customer-controlled storage. Audit teams query their existing pipeline.

SOC 2 evidence readyHIPAA audit trailYour S3 + your keysAppend-only logCustomer-controlled captureSource code delivered
Intake Portal

Let's Build.

Submit your technical details and we will formulate a production scope, architectural dependencies, and exact model selection profiles.

Prefer a call instead?

Frequently Asked Questions

Everything you need to know about Transmute

Do you have SOC 2?

SOC 2 is not applicable by architecture. We hold no keys, run no servers, process no data. Transmute runs entirely on your infrastructure. See our architecture letter for details.

How much does it cost?

Flat and scoped per engagement, no per-seat or per-token meter. Two PO line items. Custom engagements scoped to your requirements. No subscription, no renewal fees, no hidden costs.

Can we try before buying?

Yes. We run a live demo on YOUR LLM flow, in YOUR environment, with YOUR prompt shapes. It's a working gateway, not a slide deck. You see real redaction on real prompts before committing.