CLI¶
Prereqs: Python 3.9+ · Time to first call: ~15 seconds
The zotniq command ships with the SDK. Use it from shell scripts, git
hooks, CI jobs, or ad-hoc terminal work.
Install¶
Commands¶
zotniq check¶
Run a preflight decision against text or a file.
zotniq check "my ssn is 123-45-6789"
zotniq check --file input.txt --destination AI_TOOL --mode local
cat input.txt | zotniq check --file -
What you should see:
Decision: ALLOWED_WITH_MASKING
Summary: Content allowed after masking SSN
Masked: my ssn is XXX-XX-6789
The command exits 0 because the payload was safe to send after
masking. Feed a PHI payload and exit code becomes 1.
Options:
| Flag | Values | Default | Purpose |
|---|---|---|---|
--destination |
AI_TOOL, VENDOR, CUSTOMER |
AI_TOOL |
Target destination |
--mode |
auto, local, cloud |
auto |
Preflight mode; auto = cloud if ZOTNIQ_API_KEY set, else local |
--file |
Path or - for stdin |
(positional text) | Read payload from file |
--json |
flag | off | Machine-readable JSON output |
--quiet |
flag | off | Suppress human output (still returns exit code) |
Exit codes:
0— ALLOWED or ALLOWED_WITH_MASKING (safe to proceed)1— BLOCKED (policy match)2— invocation error (bad flags, IO failure, network error, missing key on--mode cloud)
zotniq mask¶
Format-preserving mask of sensitive substrings. Always local.
zotniq mask "SSN 123-45-6789 and email [email protected]"
# SSN XXX-XX-6789 and email b***@example.com
zotniq mask --file secrets.txt > redacted.txt
zotniq mask "SSN 123-45-6789" --json
# {"masked": "SSN XXX-XX-6789"}
zotniq --version¶
zotniq --check-latest¶
Explicit opt-in check against PyPI.
No implicit update check runs on any other invocation. If you want update alerts, wire this into your CI or dependabot instead.
Recipes¶
Fail a CI job if any preflight blocks¶
if ! zotniq check --file diff.txt --quiet; then
echo "Diff contains blocked content — halting deploy"
exit 1
fi