Skip to main content

🔍 pii-radar

Scan any CSV, JSON, or Parquet file for Personally Identifiable Information — in seconds.

CI Coverage PyPI version Python Discussions License: MIT PRs Welcome


Abstract

Data engineers and ML practitioners routinely work with datasets that silently contain Personally Identifiable Information (PII) — emails, phone numbers, SSNs, credit card numbers, and IP addresses — creating compliance risks under GDPR, CCPA, and HIPAA. pii-radar is a lightweight, zero-dependency-ML CLI tool that scans structured data files for PII using high-precision patterns, Luhn Mod-10 verification, and contextual heuristics, outputting results as rich terminal tables, JSON, or CSV reports. It integrates natively with pre-commit hooks and GitHub Actions to catch PII before it reaches production or version control.


✨ Features

  • 🔎 6 PII types detected — Email, Phone, SSN, Credit Card (Luhn validated), IP Address (IPv4 & IPv6), Date of Birth (Heuristic)
  • 📁 3 file formats — CSV, JSON, Parquet (.parquet, .pq)
  • 📂 Folder scanning — Recursively scan entire directories
  • 🎨 Beautiful terminal output — Rich tables with confidence scores
  • 🤖 CI/CD native — --fail-on-detect exits with code 1 for pipeline gates
  • ⚡ Row sampling — --sample 1000 limit for rapid audit sampling on massive files
  • 🔒 Auto-redaction — --redact creates a sanitized copy of your data
  • 📊 CSV reports — Save all findings to a structured report file
  • ⚡ Fast — Pure regex + algorithmic validation, no heavy ML models

📦 Installation

# Base installation (Lightweight)
pip install pii-radar

# With Parquet support
pip install "pii-radar[parquet]"

Or install from source:

git clone https://github.com/nithin42/pii-radar.git
cd pii-radar
pip install -e ".[dev]"

🚀 Quick Start

# Scan a CSV file
pii-radar scan data/customers.csv

# Fast sampling (scan only first 1,000 rows)
pii-radar scan data/large_file.csv --sample 1000

# Scan a JSON file
pii-radar scan logs/events.json

# Scan an entire directory
pii-radar scan data/

# Get JSON output (great for scripts)
pii-radar scan data.csv --output json

# Only show high-confidence detections
pii-radar scan data.csv --min-confidence 0.9

# Save a report to CSV
pii-radar scan data.csv --report pii_report.csv

# Create a redacted copy
pii-radar scan data.csv --redact data_clean.csv

# Use in CI/CD — fails build if PII found
pii-radar scan data.csv --fail-on-detect

🏗️ Architecture

CLI Interface (cli.py)
   │
   ├─► scan_file / scan_directory (scanner.py)
   │     │
   │     ├─► File Readers (readers.py) — CSV / JSON / Parquet Cell Stream
   │     │
   │     └─► Heuristic Engine (detectors.py)
   │           ├─ Email (RFC-compliant regex)
   │           ├─ SSN (Format + Range Rejection)
   │           ├─ Credit Card (Luhn Mod-10 Checksum)
   │           ├─ Phone (Word-bounded pattern)
   │           ├─ IP Address (IPv4 0-255 Octet Validation)
   │           └─ Date of Birth (Column-Name Heuristic + Format)
   │
   └─► Reporting Layer (reporter.py)
         ├─ Rich Terminal Panel & Table
         ├─ JSON Pipeline Stream
         └─ CSV Compliance Report

📊 Detection Capabilities & Validation

PII Type Verification Strategy Accuracy / False Positive Defense
EMAIL RFC-compliant regex 99% — Word boundary enforced
SSN Format + Area exclusion 98% — Rejects invalid 000, 666, 900+ ranges
CREDIT_CARD Luhn Mod-10 Algorithm 99% — Eliminates random 16-digit number false positives
IP_ADDRESS IPv4 + Octet range check 95% — Rejects 999.x.x.x and version strings
PHONE US/International regex 92% — Enforces strict \b word boundaries
DATE_OF_BIRTH Format + Column Heuristics 95% — Contextual matching (dob, birth, bday)

🧪 Performance Benchmark

Run the reproducible benchmark script locally:

python examples/benchmark.py
  • Dataset: 10,000 rows x 7 columns (70,000 cells)
  • Throughput: ~45,000–60,000 cells/second
  • Memory Overhead: Minimal (generator-based cell streaming)

🔧 CI/CD Integration

GitHub Actions

- name: Scan for PII before merge
  run: |
    pip install pii-radar
    pii-radar scan data/ --fail-on-detect --min-confidence 0.85

Pre-commit Hook

Add to .pre-commit-config.yaml:

- repo: local
  hooks:
    - id: pii-radar
      name: PII Scanner
      entry: pii-radar scan
      args: [--fail-on-detect, --min-confidence, "0.9"]
      language: python
      types: [csv, json]

📁 Project Structure

pii-radar/
├── src/pii_radar/
│   ├── cli.py          ← Click CLI entry point (--sample, --fail-on-detect)
│   ├── scanner.py      ← Core scan orchestration with row limits
│   ├── detectors.py    ← Luhn + IPv4 range + DOB heuristics engine
│   ├── readers.py      ← CSV / JSON / Parquet readers
│   └── reporter.py     ← Rich terminal + JSON + CSV output
├── tests/
│   ├── conftest.py     ← Shared fixtures
│   ├── test_detectors.py
│   ├── test_negative_cases.py  ← False positive & Luhn unit tests
│   ├── test_scanner.py
│   └── test_cli.py
├── examples/
│   ├── sample.csv
│   ├── sample.json
│   └── benchmark.py    ← Performance benchmarking tool
├── .github/workflows/  ← CI/CD matrix (Ubuntu + Windows)
├── pyproject.toml
├── Makefile
└── README.md

📄 License

MIT — see LICENSE.


👤 Author

Nithin · github.com/nithin42 · kumbam.nithingoud@gmail.com

Part of an elite Data Science & Secure Computing portfolio. Focused on data privacy, reproducible ML, and secure systems engineering.

Metadata

Release files for pii-radar 0.5.0

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for pii-radar 0.5.0
File Size Uploaded
pii_radar-0.5.0.tar.gz 21.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for pii-radar 0.5.0
File Interpreter ABI Platform
pii_radar-0.5.0-py3-none-any.whl Python 3 none any Details

Total release size: 38.8 kB

Release files / pii_radar-0.5.0.tar.gz

Download URL pii_radar-0.5.0.tar.gz
Size 21.3 kB
Tags Source
SHA-256 checksum
How to use checksums
67c0ea157c7812823398442b32a14ace2955c87c39e659b6e0a82eecd7cb78a1
BLAKE2b-256 checksum
How to use checksums
ff35537b68f9150fb8047e9623149b813a627c3d912bd58266dcdfda7fed0475
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release files / pii_radar-0.5.0-py3-none-any.whl

Download URL pii_radar-0.5.0-py3-none-any.whl
Size 17.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
537cafd9341a2956a8895aeec8feea8ef0e1ae0f38349b9865bc4079254952ce
BLAKE2b-256 checksum
How to use checksums
18fb2b73a8183e2d3306246f8b6724c0258082783489fd51bc59ea1db0d49734
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Aug 9, 2026.

Transparency log

Release history Release notifications | RSS feed

0.6.0

2 release files

This release

0.5.0 This release

2 release files

0.4.1

2 release files

0.4.0

2 release files

0.3.1

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page