Skip to content

feat(callbacks): In-memory Zero-Trust Data Sanitization (ZTDS) callback (IETF draft-02) #40984

Description

@moxno

Submission checklist

  • This is a feature request, not a bug report or usage question.
  • I added a clear and descriptive title that summarizes the feature request.
  • I used the GitHub search to find a similar feature request and didn't find it.
  • I checked the LangChain documentation and API reference to see if this feature already exists.
  • This is not related to the langchain-community package.

Package (Required)

  • langchain
  • langchain-openai
  • langchain-anthropic
  • langchain-classic
  • langchain-core
  • langchain-model-profiles
  • langchain-tests
  • langchain-text-splitters
  • langchain-chroma
  • langchain-deepseek
  • langchain-exa
  • langchain-fireworks
  • langchain-groq
  • langchain-huggingface
  • langchain-mistralai
  • langchain-nomic
  • langchain-ollama
  • langchain-openrouter
  • langchain-perplexity
  • langchain-qdrant
  • langchain-typesafe
  • langchain-xai
  • Other / not sure / general

Feature Description

Add ZTDSSanitizingCallbackHandler to langchain-core callbacks. It enforces Zero-Trust Data Sanitization (ZTDS) in-memory before prompts leave the client perimeter over WAN sockets, conformant with IETF Standards Track draft-sibiryakov-ztds-protocol-02.

Use Case

Production LangChain pipelines often handle sensitive customer PII, HIPAA PHI, database credentials, and API secrets. Sending cleartext directly to LLM providers or routing through cloud-based proxy sanitizers introduces network egress risks and subprocessor compliance liabilities (GDPR Art. 28 DPAs). An in-memory, zero-network-egress callback eliminates cloud leakage directly in volatile RAM before socket transmission.

Proposed Solution

Implement ZTDSSanitizingCallbackHandler as a standard LangChain BaseCallbackHandler in langchain-core:

  • on_llm_start: sanitizes prompt text, replacing sensitive entities with deterministic bracketed surrogates ([EMAIL_TOKEN_1], [API_SECRET_TOKEN_1]).
  • on_llm_end: restores cleartext entities on completion return.
  • on_llm_error: guarantees Theorem 2 RAM zeroization so no state leaks on exception paths.

Full implementation and unit test suite are already prepared and validated in PR #40856.

Alternatives Considered

No response

Additional Context

Social handles (optional)

LinkedIn: https://www.linkedin.com/in/ilya-sibiryakov/

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    core`langchain-core` package issues & PRsexternalfeature requestRequest for an enhancement / additional functionality

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions