Redactly

A document viewer that hands an AI agent five real WebMCP tools — read, verify, request an unmask, challenge a redaction, read the audit trail — while keeping every sensitive value on the server side of a policy boundary.

Synthetic fixtures only

Documents

Open one to register its tools

Loading…

How the boundary works

Original text is stored AES-GCM encrypted and is only ever decrypted inside the policy service. The masked view an agent reads contains placeholder ids minted per browser session, so a reference from one session means nothing in another. A reveal needs a human decision and is delivered at most once — a second attempt on the same approval returns already_consumed, because once a value is in an agent's context there is no way to take it back.

The incident report fixture contains text written to look like an instruction to the reading agent. Following it changes nothing: an agent has no capability to approve its own request.