Technology · Agentic → Guardrails · Open Source · wiki:deep

Presidio

Presidio is an open-source PII / PHI de-identification SDK: context-aware detection plus anonymization for text, images (OCR + DICOM), and structured/semi-structured data. It is a library / pluggable pipeline, not a managed SaaS. Modules ship as separate packages — presidio-analyzer, presidio-anonymizer, presidio-image-redactor, presidio-structured — plus a meta-package presidio. Recognizers combine NER (spaCy / Stanza / transformers / Flair), regex, checksums, and custom logic. Home moved from microsoft/presidio to Data Privacy Stack (data-privacy-stack/presidio); docs redirect from microsoft.github.io.

Why it matters here

Agentic OS installs observe email, documents, and tool I/O. Before those strings hit an LLM, a log sink, or a shared corpus, PII must be detected and transformed under policy. Presidio is the mature open baseline for that job: analyzer → operators (replace, mask, encrypt, hash, keep, surrogates) → optional deanonymize. It sits on the observe / gate path with LLM Guard-style scanners and GLiNER as a stronger zero-shot NER backend — not as the ledger or authority layer.

How it works

Text enters the AnalyzerEngine, which runs registered recognizers (built-in entity types plus custom ones) and returns scored spans with entity types and offsets. The AnonymizerEngine applies per-type operators (replace, mask, encrypt, hash, custom lambda, AHDS surrogate, keep). Image redaction OCRs pixels then reuses text analysis; structured mode walks tables/columns. Deploy as pip libraries, Docker HTTP services, Spark/Fabric notebooks, or Kubernetes samples.

  1. pip install presidio-analyzer presidio-anonymizer (and a spaCy model).
  2. AnalyzerEngine.analyze(text, language=…) → RecognizerResult list.
  3. AnonymizerEngine.anonymize(text, analyzer_results, operators=…).
  4. Optionally deanonymize encrypted spans with the matching key.

Related: gliner · llm-guard · guardrails-ai · nemo-guardrails · topics/13-governance-policy

Flow

When to reach for it

  • Use when: you need a self-hosted, customizable PII pipeline (recognizers + operators) for text/images/tables before LLM/RAG/log sinks.
  • Skip when: you only need zero-shot open NER without an anonymizer stack (gliner alone), or a commercial DLP SaaS with managed accuracy SLAs.
  • Prefer instead: pair Presidio pattern recognizers with gliner / nvidia/gliner-PII for names and open types; use guardrails-ai / nemo-guardrails when the gate is broader than PII.

Limits

  • No completeness guarantee — project warning: automated detection will miss entities; stack additional controls.
  • Not an official Microsoft product — MIT OSS; Azure Language / AHDS are separate commercial services.
  • Accuracy vs SaaS — FAQ: managed PII APIs often beat default Presidio coverage; Presidio wins on customizability.
  • Hash salt — recent breaking change: hash operator uses random salt by default (referential integrity needs explicit salt).
  • Not the ledger / not HITL — redaction ≠ approval authority.

What we checked

Claims below are backed by science sources on disk.

SDK modules / goals

data-privacy-stack/presidio README · STRONG

“Context aware, pluggable and customizable PII de-identification service for text and images.”

Library vs SaaS / FAQ

Presidio FAQ (docs) · MODERATE

“Presidio is a library or SDK rather than a service. It is meant to be customized to the user's or organization's specific needs.”

Peer NER / combo stacks

GLiNER as NER peer (contrast) · MODERATE

“GLiNER is a framework for training and deploying small Named Entity Recognition (NER) models with zero-shot capabilities.”
Research inventory

9 tags · 40 out · 41 in · 3 artifacts · 0 gaps · 0 corpus docs

Catalog tags

landscape.layer
Agentic
landscape.subcategory
Guardrails
license_tag
Open Source
maps.dm
present
maps.features
11
one_liner
PII detect + anonymize SDK (text/image/structured)
review.depth
science
slug
presidio
title
Presidio

Artifacts

  • dm_map · present · technologies/presidio/document-management.md
  • features_map · present · technologies/presidio/features.md
  • readme · present · technologies/presidio/README.md

Out · alternative_to

Out · dm_axis

Out · maps_to

In · alternative_to

In · dm_axis

In · in_stack

In · maps_to