pii-masker-ai 🔒🤖
Ultra-fast, zero-dependency PII masking and reversible unmasking for AI prompts, LLM agents, and vector databases.
Prevent sensitive customer data (Emails, Phone Numbers, Credit Cards, Citizen IDs, API Keys, Private Keys, IP Addresses) from leaking into external AI models (Claude, OpenAI, Gemini).
⚡ The AI Privacy Problem & Solution
sequenceDiagram
participant User
participant PII_Masker as pii-masker-ai
participant LLM as Claude / OpenAI / Gemini
User->>PII_Masker: "Contact John at john@company.com with phone 0912345678"
Note over PII_Masker: Reversible Masking
PII_Masker->>LLM: "Contact John at <EMAIL_1> with phone <PHONE_1>"
LLM->>PII_Masker: "Scheduled an appointment for <EMAIL_1> via <PHONE_1>."
Note over PII_Masker: Automatic Unmasking
PII_Masker->>User: "Scheduled an appointment for john@company.com via 0912345678."
🌟 Key Features
- Zero dependencies: Written in 100% pure Python standard library. Instant install, zero attack surface.
- Bi-directional Reversible Masking: Masks with sequential placeholders (
<EMAIL_1>,<PHONE_1>) so the LLM retains conversational context, then restores original data upon return. - Permanent Redaction: Supports redacting with fixed tags (
[EMAIL],[API_KEY],[CREDIT_CARD]) for logging and training datasets. - Comprehensive Pattern Suite (v0.2.0):
- Financial: Credit cards (Visa, MasterCard, Amex, Discover, JCB) with Luhn algorithm verification, IBAN bank codes.
- Network: Public IPv4, IPv6 addresses, MAC addresses.
- Secrets & API Keys: JWT tokens, PEM Private Keys (
RSA,EC), OpenAI, Anthropic, GitHub, AWS, Slack, Stripe, Google Cloud. - Global & Regional: Email, US SSN, International phone (E.164), Vietnam Citizen ID (CCCD/CMND), Tax ID, Passports.
- CLI & CI Scanner: Built-in scanner to detect PII leaks in text/code files during pre-commit or CI/CD pipelines.
📦 Installation
pip install pii-masker-ai
🚀 Quickstart (Python API)
1. Reversible Masking with LLMs
from pii_masker import mask_text, unmask_text
# 1. Mask prompt before calling Claude / OpenAI
prompt = "Please send invoice #123 to customer alice@example.com, phone 0912345678."
result = mask_text(prompt, reversible=True)
print(result.masked_text)
# Output: "Please send invoice #123 to customer <EMAIL_1>, phone <PHONE_1>."
# 2. Call your LLM with masked_text...
llm_response = "I have drafted the invoice for <EMAIL_1> and notified <PHONE_1>."
# 3. Restore original customer PII in the response
final_output = unmask_text(llm_response, result.mapping)
print(final_output)
# Output: "I have drafted the invoice for alice@example.com and notified 0912345678."
2. Permanent Redaction (Logging / Storage)
from pii_masker import mask_text
log_entry = "User key was sk-ant-api03-abcdef123456789 on IP 192.168.1.50"
result = mask_text(log_entry, reversible=False)
print(result.masked_text)
# Output: "User key was [API_KEY] on IP [IP_ADDRESS]"
💻 CLI Usage
Masking text
pii-masker mask "My email is support@anthropic.com and phone is 0987654321"
Scanning files for PII leaks (CI/CD friendly)
# Returns exit code 1 if any PII leak is found
pii-masker scan ./data/ --strict
🌍 Supported PII Categories
| Category | Description | Examples |
|---|---|---|
EMAIL |
Standard RFC email addresses | user@example.com |
PHONE |
International & Vietnamese numbers | +84912345678, 0901234567 |
CREDIT_CARD |
Major credit card formats | 4532-xxxx-xxxx-9012 |
IP_ADDRESS |
IPv4 addresses | 192.168.1.1 |
API_KEY |
OpenAI, Anthropic, GitHub, AWS keys | sk-..., sk-ant-..., ghp_..., AKIA... |
GOV_ID |
National IDs (e.g. VN CCCD 12-digit / CMND 9-digit) | 001201012345 |
TAX_ID |
Tax identification numbers | 0123456789-001 |
🤝 Community: Add Your Country's PII Rules!
We are actively expanding localized PII regex rules for more countries! Beginner contributors can easily add new rules in under 15 minutes:
- 🇫🇷 France (NIR / Carte Vitale)
- 🇯🇵 Japan (My Number)
- 🇺🇸 US (SSN, Driver License)
- 🇩🇪 Germany (Steuer-ID)
- 🇬🇧 UK (National Insurance Number)
Check out CONTRIBUTING.md to claim a country module!
📄 License
MIT License © 2026 lui01212
Release files for pii-masker-ai 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| pii_masker_ai-0.2.0.tar.gz | 17.9 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| pii_masker_ai-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 32.9 kB
Release files / pii_masker_ai-0.2.0.tar.gz
| Download URL | pii_masker_ai-0.2.0.tar.gz |
|---|---|
| Size | 17.9 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
731ac1ef1c3da3fdd313542a935417b8d91032f4c46d7e1a04262d3585b8cb9c
|
|
BLAKE2b-256 checksum How to use checksums |
d2e3f78b80f65890e8393ace4a264a5d9ab9348a79651de582e6ed5ad7cfaf69
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / pii_masker_ai-0.2.0-py3-none-any.whl
| Download URL | pii_masker_ai-0.2.0-py3-none-any.whl |
|---|---|
| Size | 15.0 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
f9b0e45f7a4c5b1aefd2f4a7ab172c39f344c9df4187fd5b17434f5b989b4cc0
|
|
BLAKE2b-256 checksum How to use checksums |
bbc66f5dd845298be2e364f10df130325a460bd144486af64e545e0c17f82ce1
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log