argus-redact
Encrypt PII, not meaning. Locally.
Decision gist · record as of 2026-08-14
Yes, with conditions. Install if you need reversible, per-message-key pseudonymization for LLM pipelines and can tolerate medium install friction. Actively maintained, Apache-2.0 licensed, no known vulnerabilities. Do not rely on it as a compliance anonymization tool—it is a data minimization aid. Fast mode will miss obfuscated or novel PII variants; NER and LLM modes are statistical. Restore without a guarded anchor is not secure. Best for workflows where you control both redaction and restoration.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Requires Python 3.10 or later.
- The 'auto' mode is computationally expensive (~20s per document) and unsuitable for interactive request paths.
- Medium install friction: compiled wheels available for Python 3.10–3.12 across macOS, Linux, and Windows.
License · maintenance · safety
Apache-2.0 (permissive) — Apache-2.0 (permissive): you can use, modify, and distribute freely in commercial and private projects, provided you include a copy of the license and state material changes.
last release 2026-08-14 (0 days) · last repo commit 2026-08-14 · 10 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 89,615 downloads/mo, #13,644 on PyPI
Alternatives
Verify before relying
pip install argus-redact
from argus_redact import redact
redacted, key = redact(
"My phone is 13812345678 and ID is 110101199003074610",
lang="en"
)
print(redacted)
print(key)- Exact performance and miss rates for English PII detection versus the Chinese benchmarks cited in the description.
- Whether the 'restore' function's guarded mode (default as of v0.8.0) is sufficient for production security in adversarial settings.
- How well NER generalizes to informal, typo-heavy, or minority-language names outside documented language support.
What it is and what it does
argus-redact is a local PII detection and pseudonymization library designed to sit between user input and large language models. It scans text through up to three collaborative layers—fast regex matching, statistical NER, and optional local LLM inference—to identify sensitive data (names, phone numbers, ID numbers, medical terms, and 78 other PII types) and replace them with reversible pseudonyms. Each call generates fresh random keys, so the same original data produces different pseudonyms every time, protecting against fixed-pseudonym deanonymization attacks.
The library preserves semantic meaning: names become codes like 'P-83811', phone numbers show partial digits ('138****5678'), and ID numbers become type-prefixed codes ('ID-03292'). You can restore the original text verbatim using the per-message key, or let the LLM work with pseudonymized data. Three deployment modes trade latency for detection depth: 'fast' (sub-millisecond, regex only), 'ner' (10–100ms, adds entity recognition), and 'auto' (20s, includes local LLM). Chinese receives deepest support; English, Japanese, Korean, German, Ukrainian, and Indonesian add regex plus NER; Brazilian Portuguese is regex-only.
Use it for
- Redact user queries before sending to a third-party LLM API, then restore the response in a guarded round-trip to keep PII local.
- Audit text for privacy risk before it enters a data pipeline, using the risk-scoring API to flag documents with critical or high-severity PII.
- Preprocess customer support tickets or medical notes for internal AI analysis while ensuring sensitive fields never cross the network boundary.
- Generate synthetic training data by redacting real documents and replacing pseudonyms with plausible alternatives, preserving linguistic patterns.
- Implement a privacy gateway that runs 'fast' mode inline for low-latency LLM proxies and 'auto' mode asynchronously in a parallel audit lane.
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, with conditions.
Install if you need reversible, per-message-key pseudonymization for LLM pipelines and can tolerate medium install friction. Actively maintained, Apache-2.0 licensed, no known vulnerabilities. Do not rely on it as a compliance anonymization tool—it is a data minimization aid. Fast mode will miss obfuscated or novel PII variants; NER and LLM modes are statistical. Restore without a guarded anchor is not secure. Best for workflows where you control both redaction and restoration.
Install
argus-redact on PyPI
Before you install
Medium install friction: compiled wheels available for Python 3.10–3.12 across macOS, Linux, and Windows. Depends on pyyaml and requests. Active maintenance with latest release on 2026-08-14.
Requires Python 3.10 or later. The 'auto' mode is computationally expensive (~20s per document) and unsuitable for interactive request paths.
License in practice
Apache-2.0 (permissive): you can use, modify, and distribute freely in commercial and private projects, provided you include a copy of the license and state material changes.
Quickstart
pip install argus-redact
from argus_redact import redact
redacted, key = redact(
"My phone is 13812345678 and ID is 110101199003074610",
lang="en"
)
print(redacted)
print(key)
Verify before relying
- Exact performance and miss rates for English PII detection versus the Chinese benchmarks cited in the description.
- Whether the 'restore' function's guarded mode (default as of v0.8.0) is sufficient for production security in adversarial settings.
- How well NER generalizes to informal, typo-heavy, or minority-language names outside documented language support.
Package facts
| License | Apache-2.0 permissive |
| Python support | Supports the current Python release >=3.10 |
| Install friction | Medium. Platform-specific wheel |
| Runtime dependencies | 2 packagespyyamlrequests |
| Maintenance | Actively maintained 0 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 89,615 / month, #13,644 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 4 - BetaIntended Audience :: DevelopersLicense :: OSI Approved :: Apache Software LicenseProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.13Topic :: SecurityTopic :: Text Processing |
Evidence: argus_redact-0.8.14-cp310-cp310-macosx_10_12_x86_64.whl; argus_redact-0.8.14-cp310-cp310-macosx_11_0_arm64.whl; argus_redact-0.8.14-cp310-cp310-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; argus_redact-0.8.14-cp310-cp310-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; argus_redact-0.8.14-cp310-cp310-musllinux_1_2_aarch64.whl; argus_redact-0.8.14-cp310-cp310-musllinux_1_2_x86_64.whl; argus_redact-0.8.14-cp310-cp310-win_amd64.whl; argus_redact-0.8.14-cp311-cp311-macosx_10_12_x86_64.whl; argus_redact-0.8.14-cp311-cp311-macosx_11_0_arm64.whl; argus_redact-0.8.14-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; argus_redact-0.8.14-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; argus_redact-0.8.14-cp311-cp311-musllinux_1_2_aarch64.whl; argus_redact-0.8.14-cp311-cp311-musllinux_1_2_x86_64.whl; argus_redact-0.8.14-cp311-cp311-win_amd64.whl; argus_redact-0.8.14-cp312-cp312-macosx_10_12_x86_64.whl; argus_redact-0.8.14-cp312-cp312-macosx_11_0_arm64.whl; argus_redact-0.8.14-cp312-cp312-manylinux_2_17_aarch64.manylinux2014_aarch64.whl; argus_redact-0.8.14-cp312-cp312-manylinux_2_17_x86_64.manylinux2014_x86_64.whl; argus_redact-0.8.14-cp312-cp312-musllinux_1_2_aarch64.whl; argus_redact-0.8.14-cp312-cp312-musllinux_1_2_x86_64.whl
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “PII redaction for LLM pipelines”
- argus-redactDetects and redacts personally identifiable information (PII) in text…
- pydantic-ai-shieldsPydantic AI Shields provides guardrail capabilities for Pydantic AI…
- presidio-anonymizerReplaces detected PII text entities with anonymized values using…
Give your agent the search over MCP, or paste the wish link into any chat.
More Text Processing packages
A drop-in replacement for Python's standard `re` module that adds advanced regex features like nested sets, fuzzy matching, lookaround in conditionals, and full Unicode case-folding while maintaining backward compatibility.
pyparsing provides a library for building text parsers directly in Python code using composable grammar classes, handling quoted strings, whitespace variation, and embedded comments without regex or lex/yacc.
Install it if you need to parse text or define grammars programmatically.
fonttools manipulates font files in multiple formats (TrueType, OpenType, AFM, Type 1, Mac-specific) and includes TTX, a tool to convert fonts to and from XML text format.
Install it if you need to read, write, or manipulate fonts programmatically or via the TTX command-line tool.
Docutils converts plaintext documentation in reStructuredText format into multiple output formats including HTML, XML, and LaTeX using a modular processing system.
RapidFuzz provides fast fuzzy string matching using Levenshtein Distance and related metrics, implemented mostly in C++ with Python bindings for rapid similarity scoring and approximate string matching.
Install it if you need fuzzy string matching; it's a solid replacement for FuzzyWuzzy with better licensing and performance.
tinycss2 parses CSS strings into token and block objects, and generates CSS strings from those objects, following the CSS Syntax Level 3 specification without enforcing specific properties or values.
Install it if your project requires CSS tokenization or syntax manipulation.
See also presidio-image-redactor · scrubadub · presidio-analyzer · presidio-anonymizer · openmed · gliner · wetext · deepteam · pydantic-ai-shields · pyarmor.cli.core.alpine