privacy-gateway
Health Uyari
- License — License: MIT
- Description — Repository has a description
- Active repo — Last push 0 days ago
- Low visibility — Only 6 GitHub stars
Code Gecti
- Code scan — Scanned 12 files during light audit, no dangerous patterns found
Permissions Gecti
- Permissions — No dangerous permissions requested
Bu listing icin henuz AI raporu yok.
Local-first, source-agnostic privacy gateway for reversible PII masking, policy-controlled redaction, and synthetic data.
Privacy Gateway
Keep sensitive data inside your trust boundary.
Local-first PII detection, policy-controlled anonymization, encrypted reversible mappings,
and client-held restoration for applications, APIs, and AI agents.

[!IMPORTANT]
Privacy Gateway reduces exposure; it is not a legal-anonymity guarantee. Read the
threat model and limitations before production use.
Why Privacy Gateway
AI and data pipelines routinely cross trust boundaries. Privacy Gateway places a small,
source-agnostic control plane in front of those boundaries.
- Choose exactly what changes. Every entity type gets its own action, confidence floor,
scope, locale, and reversibility setting; mapping and audit retention are policy-wide. - Fail closed. Required detector failure returns a blocked result; it never quietly sends
the original payload onward. - Keep restoration local. A client-held key can seal a restoration capsule so the gateway
never persists original values. - Audit decisions, not secrets. Query entity type, detector, confidence, action, policy
version, and byte span without storing plaintext values in audit rows. - Plug in anywhere. Supported surfaces include Python, TypeScript, ASGI middleware,
OpenAI/Anthropic-compatible proxies, MCP, webhooks, and CLI workflows. - Generate safer test data. Infer CSV/JSON/JSONL schemas, preserve constraints and
relationships, and receive aggregate quality/privacy reports.
Actions
The built-in entity catalog covers email, phone, payment card, SSN, IP address, API keys,
people, organizations, locations, dates, money, URLs, IBANs, US routing numbers, passports,
driver licenses, and medical licenses.
Quick start
The local build currently requires Python 3.11+ and Node.js 20+.
git clone https://github.com/csnyder256/privacy-gateway.git
cd privacy-gateway
python -m venv .venv
. .venv/bin/activate
pip install -e '.[dev]'
export PRIVACY_GATEWAY_MASTER_KEY="$(privacy-gateway keygen)"
privacy-gateway anonymize 'Email me at [email protected]'
For a client-held restoration flow:
from privacy_gateway.crypto import generate_key
from privacy_gateway.engine import PrivacyEngine
from privacy_gateway.vault import Vault
client_key = generate_key()
gateway = PrivacyEngine(Vault("privacy.db"))
protected = gateway.transform(
"Email me at [email protected]",
restore_key=client_key,
)
original = PrivacyEngine.restore_capsule(
protected.text,
protected.capsule,
client_key,
protected.session_id,
)
Open http://127.0.0.1:8787 after privacy-gateway serve for the guided policy builder.

Trust modes
Read the threat boundaries before selecting a mode. Anonymization
reduces exposure; it does not make arbitrary data automatically safe or legally anonymous.
Storage backends
The vault slots into whatever database you already run. By default it uses a local SQLite file;
point PRIVACY_GATEWAY_DB (or the serve --database flag) at a postgresql:// URL to use
PostgreSQL instead, with pip install 'privacy-gateway[postgres]'. Both backends share the same
encrypted, expiry-enforcing schema, so nothing else changes.
export PRIVACY_GATEWAY_DB="postgresql://user:[email protected]:5432/privacy"
Integrations
Unsupported provider paths, malformed shapes, streaming, redirects, or non-JSON responses block
instead of forwarding the original. Restorable values in tool/side-effect output also block.
Synthetic structured data
privacy-gateway synthesize source.csv synthetic.csv \
--rows 1000 \
--schema-output schema.json \
--report-output report.json
CSV, JSON, and JSONL are supported. Explicit schemas can describe types, nullability, ranges,
categories, locales, primary keys, and multi-table foreign keys. The clean-room generator has no
SDV runtime dependency; see provenance and
limitations.
Docker
export PRIVACY_GATEWAY_MASTER_KEY="$(.venv/bin/privacy-gateway keygen)"
docker compose up --build
curl --fail http://127.0.0.1:8787/v1/health
The Compose service binds to loopback, drops capabilities, uses a read-only root filesystem, and
persists its encrypted SQLite database in a named volume. See operations.
Presets
Start from balanced, strict, healthcare, finance, or devsecops, then override any
rule. Presets are ordinary versioned policies, not hidden behavior.
from privacy_gateway.models import Action, EntityType
from privacy_gateway.policies import policy_from_preset
policy = policy_from_preset("balanced")
email = policy.rule_for(EntityType.EMAIL_ADDRESS)
email.action = Action.REDACT
email.reversible = False
email.minimum_confidence_ppm = 900_000
Repository map
Verification
pytest
ruff check src tests
ruff format --check src tests
npm run check
npm test
npm run build
The local release gate covers the Python and TypeScript suites, Python lint/format,
TypeScript typecheck/build, package build, CLI probes, browser onboarding, and container smoke
tests. This is not a third-party security certification.
Design provenance
Privacy Gateway draws architectural lessons from pii-proxy, Anonproxy, prompt-anonymizer,
Microsoft Presidio, and SDV. See research verification and
provenance for exact revisions and license boundaries. The structured
synthetic-data work is a clean-room implementation; SDV code is not copied or bundled.
Security
Please do not report vulnerabilities in public issues. Follow SECURITY.md.
Start with the threat model, then review
operations and limitations.
License
MIT © Cade Snyder. See LICENSE.
Yorumlar (0)
Yorum birakmak icin giris yap.
Yorum birakSonuc bulunamadi