Skip to content

CLI

Prereqs: Python 3.9+ · Time to first call: ~15 seconds

The zotniq command ships with the SDK. Use it from shell scripts, git hooks, CI jobs, or ad-hoc terminal work.

Install

pip install zotniq
zotniq --version

Commands

zotniq check

Run a preflight decision against text or a file.

zotniq check "my ssn is 123-45-6789"
zotniq check --file input.txt --destination AI_TOOL --mode local
cat input.txt | zotniq check --file -

What you should see:

Decision: ALLOWED_WITH_MASKING
Summary:  Content allowed after masking SSN
Masked:   my ssn is XXX-XX-6789

The command exits 0 because the payload was safe to send after masking. Feed a PHI payload and exit code becomes 1.

Options:

Flag Values Default Purpose
--destination AI_TOOL, VENDOR, CUSTOMER AI_TOOL Target destination
--mode auto, local, cloud auto Preflight mode; auto = cloud if ZOTNIQ_API_KEY set, else local
--file Path or - for stdin (positional text) Read payload from file
--json flag off Machine-readable JSON output
--quiet flag off Suppress human output (still returns exit code)

Exit codes:

  • 0 — ALLOWED or ALLOWED_WITH_MASKING (safe to proceed)
  • 1 — BLOCKED (policy match)
  • 2 — invocation error (bad flags, IO failure, network error, missing key on --mode cloud)

zotniq mask

Format-preserving mask of sensitive substrings. Always local.

zotniq mask "SSN 123-45-6789 and email bob@example.com"
# SSN XXX-XX-6789 and email b***@example.com

zotniq mask --file secrets.txt > redacted.txt

zotniq mask "SSN 123-45-6789" --json
# {"masked": "SSN XXX-XX-6789"}

zotniq --version

zotniq --version
# 0.1.0

zotniq --check-latest

Explicit opt-in check against PyPI.

zotniq --check-latest
# Installed: 0.1.0
# Latest:    0.1.0
# Up to date.

No implicit update check runs on any other invocation. If you want update alerts, wire this into your CI or dependabot instead.

Recipes

Fail a CI job if any preflight blocks

if ! zotniq check --file diff.txt --quiet; then
  echo "Diff contains blocked content — halting deploy"
  exit 1
fi

Mask log lines before shipping to a shared bucket

tail -f app.log | while read line; do
  echo "$(zotniq mask "$line")" >> shipped.log
done

Sanity-check a redaction script

diff <(zotniq mask "$INPUT") "$EXPECTED"