PII detection, redaction, and database discovery

Find and redact PII across text and databases.

Submit text from logs, code repositories, documents, and backups through the REST API, or scan PostgreSQL and Oracle databases to locate PII and generate actionable JSON and HTML reports.

Request a Call
22 Supported PII fields
2 Database scanners
JSON + HTML Exposure reports
PII Cloak detect, redact, and protect visual
Core capabilities

One service for runtime protection and data discovery.

PII Cloak combines deterministic regex detection for structured identifiers with a transformer-based PII model for entities that depend on language and context.

Text Detection & Redaction API

Send strings from application and data sources to receive detected entities, confidence scores, and redacted text for downstream use.

PostgreSQL & Oracle Scans

Inspect database samples to identify tables and columns likely to contain personal, identity, financial, or credential data.

Actionable Exposure Reports

Generate machine-readable JSON and review-ready HTML reports for engineering, data, architecture, and privacy teams.

Data sources supported

Submit extracted text as strings or use the PostgreSQL and Oracle database scanners.

  • Logs Application, service, and audit log text
  • Code repositories Source, configuration, and embedded text
  • Databases PostgreSQL and Oracle sampled columns
  • Documents Extracted document content submitted as text
  • Backups Exported or restored content submitted for scanning
Coverage

Practical PII coverage across text and databases.

Use structured rules and contextual detection to classify 22 commonly encountered personal, contact, location, identity, financial, credential, and database fields.

Personal, Contact & Location

Names Email Address Phone Number Date of Birth Building Number Street Address City ZIP / Postal Code Address / Location Fields

Identity & Tax

Aadhaar PAN GSTIN Voter ID Passport Number Social Security Number ID Card Number

Financial, Account & Credentials

Account Number Credit Card Number UPI ID IFSC Code Password Database Username / User ID Columns

Structured identifiers such as Aadhaar, PAN, GSTIN, IFSC, UPI, passport, voter ID, email, and SSN use regex-based detection. Contextual entities are detected with a transformer-based PII model.

Industries

Built for teams handling sensitive customer data every day.

Financial Services

Detect sensitive information in transactions, onboarding documents, customer chats, and operational exports.

AI and LLM Applications

Remove personal data before prompts, training samples, or conversation logs reach model providers.

SaaS Platforms

Protect user-generated content, uploaded files, tickets, and application logs across product surfaces.

Legal Services

Detect and redact client, case, contract, and discovery data before documents move through review tools or AI workflows.

HR Services

Protect employee, candidate, payroll, and benefits information across HR platforms, support requests, and internal reports.

Government & Citizen Services

Protect Aadhaar, PAN, voter ID, passport, tax, contact, and address data across applications, records, and citizen service workflows.

Private deployment architecture

Run PII detection entirely inside your network.

Deploy the stateless service as a single Docker container within your client VPN or internal network. Requests remain under your infrastructure, access, and security controls.

PII Cloak stateless deployment inside a client VPN, showing API gateway, in-memory processing, PII detection, response generation, and JSON response stages
Reference architecture for a stateless, containerized PII detection service deployed within a client-controlled private network.

Controlled Network Boundary

  • Runs inside the client VPN or internal network
  • HTTPS communication using TLS 1.2 or later
  • API key authentication, rate limiting, and request validation
  • Supports web, mobile, backend, SDK, cURL, and Postman clients

In-Memory Processing Pipeline

  • Normalizes and chunks request text in memory
  • Runs locally without an internet dependency
  • Returns entity types, confidence scores, and detection summaries
  • Can include redacted text in the JSON response

Privacy by Design

  • No database or file storage
  • No request, response, or payload content logs
  • No request caching or usage telemetry
  • Data is discarded immediately after the response
  • The service provider cannot see or access processed data
Database scanning

Locate likely PII columns in production data estates.

Scan representative database samples, classify likely PII exposure, and share findings in formats suited to both automation and technical review.

PostgreSQL

Scan schemas and sampled column values to identify where personal, identity, address, financial, and account data is likely stored.

Oracle Database

Apply the same PII detection coverage to sampled Oracle data and produce table and column-level findings for remediation planning.

Extensible Connectors

Add connectors for MySQL and other databases using the existing scan and reporting workflow as requirements expand.

Build versus deploy

Why use PII Cloak?

Open-source frameworks provide building blocks. Cloud APIs provide managed endpoints. Compliance platforms provide dashboards. PII Cloak provides a working detection, redaction, and database discovery service ready to deploy.

Technical comparison of open-source frameworks, generic cloud APIs, and PII Cloak
Decision area Open-source frameworks Generic cloud APIs PII Cloak
Time to first result Days of setup, configuration, and integration. Hours of account, security, and SDK setup. Minutes to pull, run, and call the API.
Indian identifiers Custom recognizers and production tuning may be required. Coverage varies by provider, service, and region. Aadhaar, PAN, GSTIN, IFSC, UPI, voter ID, and passport coverage is built in.
Database scanning Extraction, database connectors, and reports are separate engineering work. Discovery is typically tied to the provider's own data services. PostgreSQL and Oracle scanning with table and column findings plus JSON and HTML reports.
Detection approach Your team selects, combines, and tunes rules and models. Provider-managed detection with limited model control. Hybrid regex and transformer detection tuned for Indian and global PII.
Data residency Can stay in your infrastructure; your team owns hardening and controls. Data is sent to a provider endpoint under its regional controls. Runs inside your network with in-memory processing and no content storage or logs.
Ongoing maintenance 5X more in total ownership cost when engineering, infrastructure, tuning, and upgrades are included. The provider maintains detection; your team owns integrations and vendor lifecycle. Detection rules, models, connectors, reports, and service maintenance are handled for you.
Production effort Multiple team-weeks to assemble and productionize. Multiple integration cycles across security and data services. A pre-integrated service that most teams can deploy the same day.

The takeaway: PII Cloak packages the detection stack, private deployment controls, database connectors, and reporting that teams otherwise assemble themselves, creating a 5-10X faster path to production.

API

Start with a simple request.

Integrate detection at runtime

Send raw text to the API and receive detected entities with types, scores, and matched values. Use the redacted output to protect logs, support workflows, application data, and AI inputs.



          
Expected API Response

        
Technical evaluation

Need to map PII in PostgreSQL or Oracle, or protect application text?

Contact Us