PII Detector Server
Self-hosted PII detection and anonymization, with a point-and-click portal
What you get
Guided HTTPS setup wizard on the AMI - no user-data passwords
Portal, CSV upload, S3-backed batch queue, and a REST API - pick replace, mask, redact, hash, or encrypt per entity type
Runs entirely inside your VPC - text never leaves your AWS account
About this product
This product provides a self-hosted PII detection and anonymization server packaged as an Amazon Machine Image (AMI) for AWS EC2, built on Microsoft Presidio. It detects around 18 personally identifiable information (PII) entity types by default - names, emails, phone numbers, SSNs, credit cards, IBANs, IP addresses, and more - and applies a configurable action per entity type: replace, mask, redact, hash, or encrypt. English only.
The AMI launches with a guided browser setup wizard over HTTPS (port 443). You confirm ownership with the EC2 instance ID, create an administrator account, and pick a certificate option. No SSH or user-data editing is required for credentials. After setup, sign in to a point-and-click portal - paste text, choose which entity types to look for and what to do with each, and see the anonymized result alongside every detected span and its confidence score. The same functionality is available as a REST API (POST /redact), authenticated with API tokens issued from /admin - no need to share one password with every script or CI job. HTTP Basic auth with any account also works. If you encrypt, POST /decrypt with the caller-supplied key and the rewrites array from the anonymize response.
For bulk work there are two more tools alongside the single-text portal. CSV conversion: upload a spreadsheet, and the server reads the header and tells you which columns actually contain PII so you can tick the ones to process; every other column is copied through unchanged. You get a download of the converted file, statistics on what was found by entity type and by column, and the exact configuration used so the same run can be reproduced against the API. Batch processing: attach one of your own S3 buckets during setup, and the instance mounts it as a folder you can browse in the browser. Queue up CSV and text files and each one gets a redacted copy written back beside it. Files never leave your bucket, and the bucket is optional - leave it empty and the rest of the product works unchanged.
CPU only - Presidio's default detection pipeline has no GPU benefit, so there is no GPU instance tier to pay for. Nothing is downloaded at boot; the detector is already on the AMI.
This listing is the AMI path. For a SageMaker real-time or batch endpoint with the same detector, use the PII Detector Model.
Common uses include redacting PII from support tickets, logs, and data exports before they reach a data warehouse or an LLM, and compliance workflows where sending customer text to a third-party PII API is not an option.
Names, emails, credit cards, SSNs, IBANs, IP addresses, and URLs are the strongest categories out of the box; organization, location, and date/time detection use general-purpose NLP and are noisier. Full postal-address detection is not a built-in capability. Phone recall on mixed international formats is weaker than on US-format numbers.
How it ships
- EC2 AMIEC2 AMI
PII Detector Server AMI
Listing coming soon
Categories and keywords
- Categories
- SecurityNatural Language ProcessingText
- Keywords
- PIIdata privacyanonymizationredactioncomplianceself-hosted