Skip to main content

cgh-pii

PII and secret detection for cgh. Once installed, every indexed file is scanned inline for personal data and credentials, and the results land in the finding store:

pip install cgh-pii
cgh index
cgh findings --key pii.       # emails, phones, IBANs, cards per file
cgh findings --severity block # private keys, cloud credentials

Detected keys and their severities:

Key What Severity
pii.email email addresses warn
pii.phone international-format phone numbers warn
pii.iban IBANs, mod-97 validated warn
pii.card payment card numbers, Luhn validated warn
secret.aws_key AWS access key ids block
secret.private_key PEM private key blocks block
secret.assignment password = "..." style hardcoded credentials warn

Two deliberate properties:

  • Finding values never contain the matched data. A finding stores the match count and the first line number, not the email or the IBAN itself: findings feed the full-text index and must not spread what they detect.
  • Validation over recall. Cards must pass Luhn, IBANs must pass mod 97, so a random digit run does not flag a file.

The optional NER tier (person names, locations) installs with pip install "cgh-pii[ner]" and activates with ner = true under [plugin.pii]; it runs deferred, off the indexing hot path.

Redacting a document

Beyond detecting PII, cgh-pii can produce an anonymized copy of a text or markdown file:

cgh pii redact contract.md --only person --out contract.anon.md
cgh pii redact notes.txt --mode pseudonym --in-place
cgh pii redact report.docx --only person --out report.anon.docx

--only limits the categories (person, location, email, phone, iban, card, aws_key, private_key; default: all). --mode placeholder (default) writes numbered tags [PERSON_1], distinct within the document; --mode pseudonym writes a keyed <pii.person:hex>, the same token for the same value across documents when you export a stable CGH_REDACT_SECRET (16+ chars). From code: codegraph.sdk.redact_text(text, only=["person"]).

Two things to know:

  • Names need the NER tier (pip install "cgh-pii[ner]"). The regex tier does not detect person names; requesting person or location without NER fails with a clear message. Once a name is detected, every literal re-occurrence of it is redacted too, since NER can miss repeat mentions.
  • Text, markdown and docx. Word documents are redacted with the docx extra (pip install "cgh-pii[docx]"), body paragraphs and table cells, one shared token map across the whole file. Formatting inside a changed paragraph is flattened (it is the only way to redact PII split across runs, like a bold surname); unchanged paragraphs keep their formatting. A docx needs --out or --in-place. PDF is not supported: real pdf redaction needs an AGPL library; extract the pdf text (see cgh-docs) and redact that.

Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

cgh_pii-0.2.0.tar.gz (14.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

cgh_pii-0.2.0-py3-none-any.whl (13.1 kB view details)

Uploaded Python 3

File details

Details for the file cgh_pii-0.2.0.tar.gz.

File metadata

  • Download URL: cgh_pii-0.2.0.tar.gz
  • Upload date:
  • Size: 14.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for cgh_pii-0.2.0.tar.gz
Algorithm Hash digest
SHA256 9b4286f42bcac7220189aeb2566090a2ae21b6e91ee834fa22c98994ffc105a9
MD5 eb14001ea8cc8c7886e087c534159fca
BLAKE2b-256 1c0db63efc4d0766aefab621153acad62e2e0fe7713f2f00702cab72dcb0b8a1

See more details on using hashes here.

Provenance

The following attestation bundles were made for cgh_pii-0.2.0.tar.gz:

Publisher: release.yml on altikva/cgh

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file cgh_pii-0.2.0-py3-none-any.whl.

File metadata

  • Download URL: cgh_pii-0.2.0-py3-none-any.whl
  • Upload date:
  • Size: 13.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/7.0.0 CPython/3.13.14

File hashes

Hashes for cgh_pii-0.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 c1873daa2da324b727504249c05fe4a24b8f4bad8c63e3dba3f97defe93064ce
MD5 2fc056ed920fb787e347005269cc7e51
BLAKE2b-256 fe7912d589bfe450a21b0ab664fed9db1f7dd826f23b4f91c640548cf207019a

See more details on using hashes here.

Provenance

The following attestation bundles were made for cgh_pii-0.2.0-py3-none-any.whl:

Publisher: release.yml on altikva/cgh

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Release history Release notifications | RSS feed

0.3.1

2 files

0.3.0

2 files

This release

0.2.0 This release

2 files

0.1.1

2 files

0.1.0

2 files

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page