Skip to content

Palena WebSearch MCPEnterprise web search for AI.

A Go MCP server that searches the open web, strips PII, screens prompt-injection payloads, and hands back LLM-ready markdown with a full audit trail.

Palena

Why Palena exists ​

Foundation models cannot safely ingest raw third-party HTML. It carries PII, prompt-injection payloads, adversarial instructions, tracking artifacts, and noise that blows up token budgets.

Palena is the boundary layer β€” the name means boundary or limit in Hawaiian. It sits between your agent and the open web, enforces the policies your compliance team actually cares about, and returns clean, hashed, audited markdown your model can trust.

What you get ​

  • A single MCP tool (web_search) that orchestrates six stages: search β†’ scrape β†’ PII detection β†’ prompt-injection screening β†’ rerank β†’ markdown formatting.
  • Sidecar architecture β€” SearXNG, Presidio, Playwright, the injection classifier, and the reranker are all separate containers. Swap them, scale them, replace them independently.
  • Config-driven behavior β€” PII mode, injection mode, reranker backend, scraper tiers, domain allow/blocklists, rate limits β€” all declared in palena.yaml, not burned into code.
  • Compliance-first defaults β€” robots.txt enforcement, per-domain rate limits, content hash chains, and audit records that survive a regulator's request.

Who it's for ​

Fintech, healthtech, govtech, and any team whose legal team has concerns about raw web content reaching an LLM prompt. If you've been told "we can't ship unfiltered HTML into a model," Palena is the filter.

Start with Getting Started to bring up the stack, then read Concepts for the full pipeline picture.

Released under the Apache License, Version 2.0.