Skip to main content

In-VPC PostgreSQL masking and anonymization engine

Project description

PrivaCI

One command. Sanitized staging data. No data leaves your VPC.

PrivaCI is a stateless batch engine that reads from a PostgreSQL source (typically a production replica), masks PII with a three-tier pipeline, and writes realistic synthetic data to a staging database with referential integrity preserved.

Prerequisites

  • Python 3.12+, or the official container image (ghcr.io/boundarylogic/privaci)
  • A PostgreSQL source (typically a production replica) and an empty target database

Quickstart

Fastest path — self-contained evaluation stack (~60 s):

export ANONYMIZATION_SALT="$(openssl rand -hex 32)"
make eval-up

See the quickstart for the full walkthrough.

Your own databases:

pip install -e .
privaci gen-salt > .privaci-salt && chmod 600 .privaci-salt
export ANONYMIZATION_SALT=$(cat .privaci-salt)
export SOURCE_DB_URL=postgresql://user:pass@source-host:5432/app
export TARGET_DB_URL=postgresql://user:pass@target-host:5432/staging

privaci init --source "$SOURCE_DB_URL" --output mask-rules.yaml
privaci plan --config mask-rules.yaml --source "$SOURCE_DB_URL"
privaci validate && privaci dry-run && privaci run && privaci verify

Browse the docs site locally: pip install -e ".[dev]" && make docs-serve

Documentation

Start with the documentation site or quickstart. Key pages:

Using PrivaCI

Developing PrivaCI

License

The engine is licensed under the Elastic License 2.0. Optional paid features ship as a separate plugin layer via the plugin contracts.

Commercial

Optional paid capabilities — signed compliance reports, schema-drift detection, FK-aware subsetting, JSONB path masking, and more — ship as a separate plugin layer on top of this engine, still entirely in your VPC. Learn more at BoundaryLogic.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

privaci-1.2.0.tar.gz (147.6 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

privaci-1.2.0-py3-none-any.whl (205.2 kB view details)

Uploaded Python 3

File details

Details for the file privaci-1.2.0.tar.gz.

File metadata

  • Download URL: privaci-1.2.0.tar.gz
  • Upload date:
  • Size: 147.6 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for privaci-1.2.0.tar.gz
Algorithm Hash digest
SHA256 c8a522a699646a48175c4c77b8cc568e49761eec4a28e84279135d8d5ea7098d
MD5 4bd2eb375fca0d8aa09f311c9a6247c4
BLAKE2b-256 f4b946d91621d930c957764c96f3826661f5f1d8097f9bd39f3b7657b3bf1bcc

See more details on using hashes here.

Provenance

The following attestation bundles were made for privaci-1.2.0.tar.gz:

Publisher: publish-pypi.yml on BoundaryLogic/privaci

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file privaci-1.2.0-py3-none-any.whl.

File metadata

  • Download URL: privaci-1.2.0-py3-none-any.whl
  • Upload date:
  • Size: 205.2 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.12

File hashes

Hashes for privaci-1.2.0-py3-none-any.whl
Algorithm Hash digest
SHA256 494c7dc3e3b31a4c65ca69cba33da53d900769c7cfe4fe7857fb04347bb89d29
MD5 dd80a5fa54d92e92555490d388ab5bf8
BLAKE2b-256 680c868340acdb5c87a8bad300e236ae0d8f0a184f443438ea4d3795e56c80c1

See more details on using hashes here.

Provenance

The following attestation bundles were made for privaci-1.2.0-py3-none-any.whl:

Publisher: publish-pypi.yml on BoundaryLogic/privaci

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page