Kong publishes the AI PII Anonymizer service as public Docker images. Each image includes a built-in NLP model and is tagged using the version-lang_code format. For example:
-
ai-pii-service:v0.2.2-en: English model, version 0.2.2
-
ai-pii-service:v0.2.2-it: Italian model, version 0.2.2
-
ai-pii-service:v0.2.2-fr: French model, version 0.2.2
All models are bundled into a single image per version, tagged using the format v<version>. For example: v0.2.2
If you need to add or modify models, edit the configuration file at ai_pii_service/nlp_engine_conf.yml.
-
POST /llm/v1/sanitize: Sanitize specified types of PII information, including credentials, and custom patterns
-
POST /llm/v1/sanitize_credentials: Only for sanitizing credentials
See the AI PII Sanitizer OpenAPI specification for complete details.
You can anonymize data in requests using the following redact modes:
-
placeholder: Replaces sensitive data with a fixed placeholder pattern, PLACEHOLDER{i}, where i is a sequence number. Identical original values receive the same placeholder.
For example, the location New York City might be replaced with LOCATION.
-
synthetic: Redact the sensitive data with a word in the same type.
For example, the name John might be replaced with Amir.
- Custom patterns are replaced with
CUSTOM{i}.
- Credentials are replaced with a string of
# characters matching the original length.
You can define an array of custom patterns on a per-request basis.
Currently, only regex patterns are supported, and all fields are required: name, regex, and score.
The name must be unique for each pattern.
You can use the following fields in the anonymize array:
-
general: Anonymizes general PII entities such as person names, locations, and organizations.
-
phone: Anonymizes phone numbers (for example, mobile, landline).
-
email: Anonymizes email addresses.
-
creditcard: Anonymizes credit card numbers.
-
crypto: Anonymizes cryptocurrency addresses.
-
date: Anonymizes dates and timestamps.
-
ip: Anonymizes IP addresses (both IPv4 and IPv6).
-
nrp: Anonymizes a person’s nationality, religious, or political group.
-
ssn: Anonymizes Social Security Numbers (SSN) and other related identifiers like ITIN, NIF, ABN, and more.
-
domain: Anonymizes domain names. It was deprecated, use url instead.
-
url: Anonymizes web URLs.
-
medical: Anonymizes medical identifiers (for example, medical license numbers, NHS numbers, medicare numbers).
-
driverlicense: Anonymizes driver’s license numbers.
-
passport: Anonymizes passport numbers.
-
bank: Anonymizes bank account numbers and related banking identifiers (for example, VAT codes, IBAN).
-
nationalid: Anonymizes various national identification numbers (for example, Aadhaar, PESEL, NRIC, social security, or voter IDs).
-
custom: Anonymizes user-defined custom PII patterns using regular expressions only when custom patterns are provided.
-
credentials: Anonymizes the credentials, similar to /sanitize_credentials.
-
all: Includes all the fields above, including custom ones.
Kong distributes these images publicly on Docker Hub, under the kong/ai-pii-service repository. No authentication is required to pull them.
To pull an image:
docker pull kong/ai-pii-service:TAG
Replace TAG with the appropriate version and language code, such as:
docker pull kong/ai-pii-service:v0.2.2-en
To run the image directly, without a Dockerfile:
docker run -d kong/ai-pii-service:v0.2.2-en
Alternatively, to use an image in a Dockerfile, reference it as follows:
FROM kong/ai-pii-service:v0.2.2-en
The following language-specific images are currently available:
-
-en (English)
-
-es (Spanish)
-
-fr (French)
-
-de (German)
-
-it (Italian)
-
-ja (Japanese)
-
-ko (Korean)
-
-nl (Dutch)
-
-pt (Portuguese)
-
-th (Thai)
-
-tr (Turkish)
The PII Anonymizer service loads one NLP model by default. Ensure at least 600MB of free memory is available when running the container. If a user specifies a model that isn’t bundled with the deployed image, it will be downloaded at startup from the spaCy models repository.
This service takes the following optional environment variables at startup:
-
GUNICORN_WORKERS: Specifies the number of Gunicorn processes to run
-
PII_SERVICE_ENGINE_CONF: Specifies the natural language processing (NLP) engine configuration file
-
GUNICORN_LOG_LEVEL: Specifies log level