Reference · Changelog
Changelog
All notable changes to CloakPipe are documented in this file.
The format is based on Keep a Changelog,
and this project adheres to Semantic Versioning.
CloakPipe is pre-1.0 and its formats carry v1alpha1 versions, so minor releases
may contain breaking changes; these are marked Breaking.
Unreleased
Added
- Agent Release manifests. A new
cloakpipe-releasecrate gives an AI agent release an exact, verifiable identity: anAgentReleasemanifest that only accepts immutable references, a canonical hash (RFC 8785), a material-change diff that lists the assurance suites a change requires, and in-toto export. New commands:cloakpipe release validate | hash | diff | inspect | register. Ledger records and MCP interceptor hops can be bound to a release hash. Ships with a JSON schema, a Python reference implementation of the hash anddocs/AGENT_RELEASE.md. (#12) - Certification. A new
cloakpipe-certcrate makes a deterministic certify/block decision for a release from its evaluation runs and a certification policy (coverage, pass rate, regressions, critical failures, metric thresholds), and signs the result as an in-toto statement in a DSSE envelope that verifies offline. New commands:cloakpipe release keygen,release certify(exit 0 only when certified) andrelease verify-cert. (#13) - Certification GitHub Action. A reusable
certifycomposite action (.github/actions/certify) lets CI block a release that fails its policy. (#13) - Evaluation import.
cloakpipe eval importturns existing test and eval results into evidence for certification: JUnit XML and native JSON (#13), Braintrust experiments and Langfuse dataset runs with a configurable--pass-threshold(#15). Malformed, duplicate or conflicting input is rejected rather than guessed. - Langfuse experiments import.
cloakpipe eval import --langfuse-experiment FILE --langfuse-experiment-items FILEreads the Langfuse experiments API, which replaces dataset runs, with cursor pagination, item-count and duplicate checks, andtools/fetch_langfuse_experiment.shto download every page. (#20) - MCP tool gate.
cloakpipe mcp-proxy --manifest ... --certification ...only forwards atools/callwhen the tool is declared in the release manifest and the release’s certification verifies at the moment of the call (trusted signer, not revoked, unexpired, right environment). Refused calls never reach the tool, return JSON-RPC error-32001and are recorded in the ledger;--gate warnforwards and flags instead. Input the gate cannot read is refused. (#14) - Transparent MCP interceptor.
cloakpipe mcp-proxy --upstream "<cmd>"sits between an agent and an MCP server, pseudonymizes PII in tool-call arguments and rehydrates tokens in tool results, so the tool never sees raw PII. (27889ca) - Evidence ledger and standalone verifier. A hash-chained, Ed25519-signed
evidence ledger that never stores PII, the standalone
cloakpipe-verifyCLI, Merkle inclusion proofs, signed auditor manifests and the CloakLeak PII-leak benchmark. (#8) The MCP server now records a no-PII ledger hop for each masking call whenCLOAKPIPE_LEDGER_DBis set. (9105613) - Real external anchoring.
cloakpipe anchor <bundle>seals a ledger export and anchors it at an RFC 3161 timestamp authority and Sigstore Rekor.cloakpipe-verify anchors|all --tsa-root ... --rekor-key ...checks both fully offline and fails closed on missing trust inputs, back-dating and downgraded bundles. Seedocs/ANCHORING.md. (#16) - Release audit packs.
cloakpipe release audit-packassembles one signed pack per release (manifest, eval runs, certification, governance events and the release-bound ledger slice), andcloakpipe-verify release-packverifies it offline with separate trust lists per role. It also rejects a re-signed false history, such as a promotion before certification. Seedocs/AUDIT_PACK.md. (#17) - Anthropic Messages API in the proxy.
/v1/messages(and the/v1/anthropic/messagesalias) pseudonymize requests to Anthropic and rehydrate responses, including streamed text deltas. (#11) - Nemotron-v2 PII NER backend, opt-in alongside the existing backends. (129fa8f)
- CloakPipe Cloud reporting. A self-hosted proxy with a
[cloud]config section sends heartbeats and no-PII request telemetry to CloakPipe Cloud. (8d03fd4, 56059ea) docker-compose.ymlfor one-command self-hosting. (f0fb7e4)SECURITY.mdwith the vulnerability reporting process. (#18)
Changed
- Breaking: format identifiers moved from the legacy
cloakpipe.devnamespace tocloakpipe.co(for exampleapiVersion: cloakpipe.co/v1alpha1, hash and signing domains, in-toto predicate types and the schema$id). Writers now emitcloakpipe.co/.... Readers and verifiers still accept legacycloakpipe.dev/v1alpha1objects, and every hash and signature issued before the move stays valid. Because theapiVersionand hash domain are part of the release hash, a manifest written in the new namespace has a different release hash than the same manifest in the legacy namespace; update any pinned hashes when you migrate a manifest. (#19) - Evidence bundles are now v4: the signed manifest commits to the chain tip, so a
substituted chain of the same length no longer verifies, and
cloakpipe-verify all --trust-keypins the signer. v3 bundles still verify. (#13) - README rewritten around Evaluate, Certify, Enforce, Prove, with every quick-start
command verified against
main;CONTRIBUTING.mdrefreshed. (#18)
Deprecated
- Langfuse dataset-run import (
--langfuse-run/--langfuse-scores). Langfuse removes those endpoints on Langfuse Cloud on 2026-11-16 (self-hosted: v4); use--langfuse-experimentinstead. (#20)
Removed
- README claims that could not be backed by the code: benchmark, latency and F1
tables, the competitor comparison, Cloud pricing tiers, the crates.io and
Docker Hub badges, and the list of
CLOAKPIPE_*environment variables (most are not read by the CLI). (#18)
Fixed
- Streaming rehydration no longer leaks pseudo-tokens that arrive split across SSE chunks, and a token at the very end of a stream is no longer dropped. Fixes #3. (1e2ea69)
0.10.0 - 2026-06-04
Added
- Multi-stage
Dockerfileand a container config that listens on0.0.0.0:8900and stores state under/data. (#5) - Release workflow that publishes
ghcr.io/rohansx/cloakpipeon each version tag. (#7) - Ready-to-use compliance policy configs:
dpdp,gdpr,hipaa,pci-dssandminimal(TOML). (#5) Cargo.lockis committed for reproducible builds. (#5)
Fixed
- Python SDK health check uses the proxy’s real
/healthroute and default port8900. (#5) - Documentation now matches the binary: real CLI subcommands, a working
build-from-source quick start, the default
127.0.0.1:8900listen address, and the MIT license (previously misstated as Apache-2.0). (#4) - CI is green again (clippy fixes). (#5, #6)
0.9.0 - 2026-03-30
Added
- DistilBERT-PII NER backend (33 entity types, runs on any CPU).
- nvidia/gliner-PII sidecar support.
- Expanded regex detection patterns.
0.8.0 - 2026-03-23
Added
- Format-preserving pseudonymization: phone numbers, emails, Aadhaar and PAN are replaced with fakes of the same format.
- Response scanning: LLM responses are scanned for PII leakage and redacted.
cloakpipe scanto check files and directories for PII before indexing them into a vector database.- LangChain and LlamaIndex packages with drop-in
ChatCloakPipeandCloakPipeLLMwrappers. - Batch detect API in CloakPipe Cloud (
POST /api/detect/batch, up to 100 texts). - Compliance policy files for DPDP 2023, GDPR, HIPAA and PCI-DSS.
0.7.0 - 2026-03-11
Added
- Context-aware pseudonymization: session tracking with coreference resolution
(pronouns, abbreviations, possessives), sensitivity escalation across
sessions, CLI session commands and an MCP
session_contexttool. - GLiNER zero-shot NER backend (
backend = "gliner"): define entity types in plain English, no training, pure ONNX Runtime. - Detection for SSN, Aadhaar, PAN, IPv4, general URLs, natural-language dates,
sk-proj/sk-live/github_patsecrets and INR/USD/EUR amounts. - PII benchmark harness (
cargo run -p cloakpipe-core --example pii_benchmark). - Admin dashboard with privacy chat, detection feed and compliance views.
Fixed
- The phone-number pattern no longer matches IP addresses, years or port numbers.
0.6.0 - 2026-03-09
Added
- Fuzzy entity resolution (Jaro-Winkler similarity, prefix matching and user-defined alias groups), gated by category so a person and a place with the same name are never merged. Works inside the vault with no changes to the detection pipeline.
0.5.0 - 2026-03-09
Added
- Industry profiles (
general,legal,healthcare,fintech) with pre-tuned detection settings. - MCP server with
pseudonymize,rehydrate,detect,vault_statsandconfiguretools.
0.4.0 - 2026-03-06
Added
- ADCPE vector encryption: an orthogonal transform for embedding vectors that preserves cosine similarity, with encrypt/decrypt CLI commands.
0.3.0 - 2026-03-06
Added
- SQLite vault and audit backends with per-value AES-256-GCM encryption.
- ONNX BERT-based NER behind the
nerfeature flag. - Multi-user token scoping.
0.2.0 - 2026-03-06
Added
- CloakTree: vectorless, LLM-driven retrieval for structured documents (PDF and Markdown), with parser, tree indexer, search and CLI subcommands.
0.1.0 - 2026-03-06
Added
- First release: privacy middleware for LLM and RAG pipelines.
Generated from CHANGELOG.md in the open-source repository, the single source of truth for releases.