
Zero-code K8s sidecar for log sanitization. Detects secrets via Entropy Analysis, preserves JSON integrity, and redacts PII deterministically. 🛡️
Zero-code log sanitization sidecar for Kubernetes. Prevents data leaks (GDPR/SOC2) by redacting PII from logs before they leave the pod.
PII-Shield runs in-process — CLI, sidecar, or WASM. There is no hosted API and no server your data is sent to.
Same name, different projects. This is not the PII Shield privacy proxy from the Microsoft developer-community blog (May 2026, vikasgautam18/pii-shield), not the piishield.ai or piishield.com prompt-redaction products, and not the
pii-shieldpackage on PyPI by Intellirim. Our packages arepii-shield-wasion PyPI and@aragossa/pii-shield-wasion npm; in prose we call this project the PII-Shield sidecar.
"Don't let PII poison your AI models." PII-Shield ensures that sensitive data never reaches your training dataset, saving you from GDPR-forced model retraining.
[!WARNING] Upgrading to v2.0.0? We have moved end-user distribution to Helm-based installs and Distroless Native Sidecars. Kustomize is no longer a supported release installation path for production users, though the operator repository still keeps Kustomize scaffolding for local development and manifest generation.
/bin/shaccess inside the PII-Shield sidecar is no longer supported. Read the Migration Guide.
PII-Shield offers two distinct ways to integrate into your stack:
<1ms latency without network hops.PII-Shield is an actively developed open-source security tool in a production-hardening phase. The v2.x release line ships usable CLI, container, Helm/operator, and WASM SDK artifacts. Core redaction paths are ready for controlled deployments, while some Kubernetes deployment modes and supply-chain guarantees are still being stabilized.
| Component | Status |
|---|---|
| Core scanner | Released / controlled deployments |
| CLI sidecar | Released / controlled deployments |
| Kubernetes operator | Stabilization phase |
| WASM SDKs | Released beta |
| Proxy-Wasm gateway integration | Planned R&D |
| Control Plane UI | Planned R&D |
| eBPF interception | Experimental R&D |
See KNOWN_LIMITATIONS.md for the current production-hardening boundaries.
Developers often forget to mask sensitive data. Traditional regex filters in Fluentd/Logstash are slow, hard to maintain, and consume expensive CPU on log aggregators.
PII-Shield sits right next to your app container:
Error: ... 44saCk9...) by analyzing context keywords.Bearer credentials and PEM private-key blocks — are redacted on their format, so a valid key is caught even when its body is low-entropy or the threshold has been raised.+, North American (555) 234-5678 forms and digits under a phone-named key (phone, mobile, wa_id, ...) are hidden even though digits alone never score as a secret.[HIDDEN:a1b2c]), allowing QA to correlate errors without seeing the raw data.PII_SAFE_REGEX_LIST to prevent false positives.We are building a hosted Control Plane with centralized rule management, Slack alerting, and redaction analytics.
PII-Shield's in-process WASM build ships inside GuardSpine Code, an open-source AI code-governance GitHub Action, which vendors the binary and credits it in its NOTICE.
While PII-Shield is highly optimized, deep inspection of complex logs requires careful attention to configuration.
encoding/json overhead). The scanner manually parses JSON structures to ensure high throughput (~7MB/s) without memory spikes.The official and recommended way to deploy PII-Shield in Kubernetes is via our fully-automated Operator:
helm repo add pii-shield https://pii-shield.github.io/pii-shield/
helm repo update
helm install pii-shield-operator pii-shield/pii-shield-operator -n operator-system --create-namespace
This deploys the PII-Shield Operator which automatically injects highly-secure, distroless sidecars into your Pods without requiring any code or Dockerfile changes.
Get the latest lightweight image from Docker Hub or GHCR:
docker pull thelisdeep/pii-shield:2.2.6
# OR from GitHub Container Registry (Enterprise):
docker pull ghcr.io/pii-shield/pii-shield:2.2.6
You can build the binary directly from the source code:
go build -o pii-shield ./cmd/cleaner/main.go
See CONFIGURATION.md for a full list of environment variables, including:
PII_SALT: Custom HMAC salt (Required for production).PII_ADAPTIVE_THRESHOLD: Enable dynamic entropy baselines.PII_DISABLE_BIGRAM_CHECK: Optimize for non-English logs.PII_CUSTOM_REGEX_LIST: Custom regex rules for deterministic redaction.PII_SAFE_REGEX_LIST: Whitelist regex rules to ignore (matches are returned as-is).