Skip to main content

maskflow-llamaindex

MaskFlow for LlamaIndex: keep PII out of your RAG pipeline. Three pieces:

  • MaskflowNodePostprocessor — a drop-in for llama_index.core.postprocessor.PIINodePostprocessor that masks PII in retrieved nodes before the response synthesizer. No LLM call, no HuggingFace model; MaskFlow's local engine, so Indian identifiers (Aadhaar, PAN, GSTIN, UPI, IFSC, ABHA, Indian names / addresses) are covered alongside the generic PII.
  • MaskflowIngestionTransform — a TransformComponent that masks node text at ingestion, so raw PII is never embedded or written to the vector store.
  • unmask_response / MaskflowQueryEngine — restore the originals in the synthesized answer from the per-node maps.

MIT, no gates, no telemetry.

Install

pip install maskflow-llamaindex

Pulls llama-index-core. The first detection run downloads a small spaCy model for the name/address recognizers; pass patterns_only=True to skip it.

Query-time masking (index already built)

from maskflow_llamaindex import MaskflowNodePostprocessor, unmask_response

query_engine = index.as_query_engine(node_postprocessors=[MaskflowNodePostprocessor()])
response = query_engine.query("What is Ramesh's PAN?")

# the synthesizer LLM saw "<PAN_1>"; restore the real value for the caller:
answer = unmask_response(str(response), response.source_nodes)

Or wrap the engine so you never forget the unmask step:

from maskflow_llamaindex import MaskflowQueryEngine

engine = MaskflowQueryEngine(
    index.as_query_engine(node_postprocessors=[MaskflowNodePostprocessor()])
)
print(engine.query("What is Ramesh's PAN?"))  # already restored, streaming too

By default one MaskFlow session is shared across every node in a call, so <PERSON_NAME_1> is the same person in every retrieved chunk. PIINodePostprocessor numbers each node independently.

Ingestion-time masking (PII never reaches the store)

from llama_index.core.ingestion import IngestionPipeline
from llama_index.core.node_parser import SentenceSplitter
from maskflow_llamaindex import MaskflowIngestionTransform

pipeline = IngestionPipeline(
    transformations=[
        SentenceSplitter(),
        MaskflowIngestionTransform(),  # default strategy: redact
        embed_model,
    ]
)
nodes = pipeline.run(documents=docs)

The default strategy="redact" ([REDACTED_PAN]) is not reversible — there is no mapping, so nothing sensitive is stored. Other strategies: surrogate (a plausible fake value) and replace (<PAN_1> tokens). store_mapping=True writes a reverse map into node metadata; that then lands in the vector store, so it warns.

Migrating from PIINodePostprocessor

# from llama_index.core.postprocessor import PIINodePostprocessor
from maskflow_llamaindex import MaskflowNodePostprocessor as PIINodePostprocessor

mask_pii(text) -> (str, dict), _postprocess_nodes, the __pii_node_info__ metadata key, and the embed/LLM metadata exclusions are all the same. MaskflowNodePostprocessor does not take an llm= argument (it needs none); it adds strategy, min_confidence, patterns_only, consistent_across_nodes, and mask_query.

PII safety

Query-time maps live only for the query, travelling with response.source_nodes; nothing is logged. The ingestion transform's default is non-reversible, so it stores no map at all. See docs/llamaindex.md in the MaskFlow repo for the design notes.

Metadata

Release files for maskflow-llamaindex 0.1.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for maskflow-llamaindex 0.1.0
File Size Uploaded
maskflow_llamaindex-0.1.0.tar.gz 11.8 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for maskflow-llamaindex 0.1.0
File Interpreter ABI Platform
maskflow_llamaindex-0.1.0-py3-none-any.whl Python 3 none any Details

Total release size: 22.6 kB

Release files / maskflow_llamaindex-0.1.0.tar.gz

Download URL maskflow_llamaindex-0.1.0.tar.gz
Size 11.8 kB
Tags Source
SHA-256 checksum
How to use checksums
43e12ac5713bf7311dd8854afcb81232115c9f44218a9e2070b13a25b8d75aa9
BLAKE2b-256 checksum
How to use checksums
1509ae8d961ec4523a15c0889178d8a86a893c72452947162592792d99ed0917
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.

Transparency log

Release files / maskflow_llamaindex-0.1.0-py3-none-any.whl

Download URL maskflow_llamaindex-0.1.0-py3-none-any.whl
Size 10.8 kB
Tags Python 3
SHA-256 checksum
How to use checksums
328dfd15c5ad45beb51c1b1b3807a62347103c89b522b91347fa4f0d299f4139
BLAKE2b-256 checksum
How to use checksums
c81daff21d9dfb6139274563bd5a113f69e4114a743196e937657c824fc7c184
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 6, 2026.

Transparency log

Release history Release notifications | RSS feed

0.1.1

2 release files

This release

0.1.0 This release

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page