
pii-shield v2.2.0
Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️
PII-Shield 🛡️
Zero-code log sanitization sidecar for Kubernetes. Prevents data leaks (GDPR/SOC2) by redacting PII from logs before they leave the pod.
PII-Shield runs in-process — CLI, sidecar, or WASM. There is no hosted API and no server your data is sent to.
Same name, different projects. This is not the PII Shield privacy proxy from the Microsoft developer-community blog (May 2026, vikasgautam18/pii-shield), not the piishield.ai or piishield.com prompt-redaction products, and not the
pii-shieldpackage on PyPI by Intellirim. Our packages arepii-shield-wasion PyPI and@aragossa/pii-shield-wasion npm; in prose we call this project the PII-Shield sidecar.
"Don't let PII poison your AI models." PII-Shield ensures that sensitive data never reaches your training dataset, saving you from GDPR-forced model retraining.
[!WARNING] Upgrading to v2.0.0? We have moved end-user distribution to Helm-based installs and Distroless Native Sidecars. Kustomize is no longer a supported release installation path for production users, though the operator repository still keeps Kustomize scaffolding for local development and manifest generation.
/bin/shaccess inside the PII-Shield sidecar is no longer supported. Read the Migration Guide.
Two Deployment Models
PII-Shield offers two distinct ways to integrate into your stack:
- Kubernetes Operator (Zero-code): Our flagship deployment model. A fully automated K8s Operator that injects a highly-secure Distroless Sidecar into your pods to intercept and sanitize logs on the fly.
- In-Process WASM (For core integrations): For extreme performance, the core engine can be embedded directly via WASM, providing
<1mslatency without network hops.
Project Status & Roadmap
PII-Shield is an actively developed open-source security tool in a production-hardening phase. The v2.x release line ships usable CLI, container, Helm/operator, and WASM SDK artifacts. Core redaction paths are ready for controlled deployments, while some Kubernetes deployment modes and supply-chain guarantees are still being stabilized.
| Component | Status |
|---|---|
| Core scanner | Released / controlled deployments |
| CLI sidecar | Released / controlled deployments |
| Kubernetes operator | Stabilization phase |
| WASM SDKs | Released beta |
| Proxy-Wasm gateway integration | Planned R&D |
| Control Plane UI | Planned R&D |
| eBPF interception | Experimental R&D |
See KNOWN_LIMITATIONS.md for the current production-hardening boundaries.
Why PII-Shield?
Developers often forget to mask sensitive data. Traditional regex filters in Fluentd/Logstash are slow, hard to maintain, and consume expensive CPU on log aggregators.
PII-Shield sits right next to your app container:
- Production-hardening Core Engine: Optimized for Kubernetes sidecars with low memory allocations on hot paths and deterministic regex matching.
- Context-Aware Entropy Analysis: Detected high-entropy secrets even without keys (e.g.
Error: ... 44saCk9...) by analyzing context keywords. - Custom Regex Rules: Deterministic redaction for structured data (UUIDs, IDs) that overrides entropy checks for known patterns.
- Built-in Secret Signatures: Issuer-prefixed credentials — AWS and Google API keys, GitHub, Slack and Stripe tokens, JWTs,
Bearercredentials and PEM private-key blocks — are redacted on their format, so a valid key is caught even when its body is low-entropy or the threshold has been raised. - Regression & Fuzz Coverage: Tested against stress cases including binary garbage, JSON nesting, and multilingual logs.
- Deterministic Hashing: Replaces secrets with unique hashes (e.g.,
[HIDDEN:a1b2c]), allowing QA to correlate errors without seeing the raw data. - Drop-in: No code changes required. Works with any language (Node, Python, Java, Go).
- Whitelist Support: Explicitly allow safe patterns (e.g., git hashes, system IDs) using
PII_SAFE_REGEX_LISTto prevent false positives.
Managing PII-Shield across dozens of clusters?
We are building a hosted Control Plane with centralized rule management, Slack alerting, and redaction analytics.
Integrations
PII-Shield's in-process WASM build ships inside GuardSpine Code, an open-source AI code-governance GitHub Action, which vendors the binary and credits it in its NOTICE.
Performance Considerations
While PII-Shield is highly optimized, deep inspection of complex logs requires careful attention to configuration.
- Text Logs: Extremely fast (>100k lines/s).
- JSON Logs: Zero-allocation parsing (no
encoding/jsonoverhead). The scanner manually parses JSON structures to ensure high throughput (~7MB/s) without memory spikes. - Recommendation: Usage is safe for high throughput. We use recursion safeguards to prevent stack overflows on deeply nested JSON.
Installation
Helm Chart (Kubernetes Operator)
The official and recommended way to deploy PII-Shield in Kubernetes is via our fully-automated Operator:
helm repo add pii-shield https://pii-shield.github.io/pii-shield/
helm repo update
helm install pii-shield-operator pii-shield/pii-shield-operator -n operator-system --create-namespace
This deploys the PII-Shield Operator which automatically injects highly-secure, distroless sidecars into your Pods without requiring any code or Dockerfile changes.
Docker
Get the latest lightweight image from Docker Hub or GHCR:
docker pull thelisdeep/pii-shield:2.2.5
# OR from GitHub Container Registry (Enterprise):
docker pull ghcr.io/pii-shield/pii-shield:2.2.5
Build from Source
You can build the binary directly from the source code:
go build -o pii-shield ./cmd/cleaner/main.go
Configuration
See CONFIGURATION.md for a full list of environment variables, including:
PII_SALT: Custom HMAC salt (Required for production).PII_ADAPTIVE_THRESHOLD: Enable dynamic entropy baselines.PII_DISABLE_BIGRAM_CHECK: Optimize for non-English logs.PII_CUSTOM_REGEX_LIST: Custom regex rules for deterministic redaction.PII_SAFE_REGEX_LIST: Whitelist regex rules to ignore (matches are returned as-is).