<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: gn000q</title>
    <description>The latest articles on DEV Community by gn000q (@gn000q).</description>
    <link>https://dev.to/gn000q</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fdev-to-uploads.s3.amazonaws.com%2Fuploads%2Fuser%2Fprofile_image%2F3875275%2F46299f1a-5ee6-4734-ab01-1527d3d9735f.png</url>
      <title>DEV Community: gn000q</title>
      <link>https://dev.to/gn000q</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/gn000q"/>
    <language>en</language>
    <item>
      <title>Zero-Allocation PII Redaction in Go: Processing 780MB of Logs in Under 3 Minutes</title>
      <dc:creator>gn000q</dc:creator>
      <pubDate>Tue, 14 Apr 2026 12:10:00 +0000</pubDate>
      <link>https://dev.to/gn000q/zero-allocation-pii-redaction-in-go-processing-780mb-of-logs-in-under-3-minutes-5fgm</link>
      <guid>https://dev.to/gn000q/zero-allocation-pii-redaction-in-go-processing-780mb-of-logs-in-under-3-minutes-5fgm</guid>
      <description>&lt;h1&gt;
  
  
  Zero-Allocation PII Redaction in Go: Processing 780MB of Logs in Under 3 Minutes
&lt;/h1&gt;

&lt;p&gt;Every team feeding logs to LLMs has the same dirty secret: those logs are full of emails, IP addresses, credit card numbers, and government IDs. I know because I built a tool to find them.&lt;/p&gt;

&lt;p&gt;After scanning 10GB of production logs at work, I found &lt;strong&gt;47,000+ PII instances&lt;/strong&gt; — emails, IPs, phone numbers — all sitting in plain text, waiting to be piped into ChatGPT or fine-tuning datasets.&lt;/p&gt;

&lt;p&gt;So I built a local-first PII redaction engine in pure Go. No cloud. No API keys. No telemetry. This post breaks down the engineering decisions that made it fast.&lt;/p&gt;




&lt;h2&gt;
  
  
  The Problem: PII Leaks in AI Pipelines
&lt;/h2&gt;

&lt;p&gt;The AI workflow looks like this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;Production Logs → Pre-processing → LLM API / Fine-tuning
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The gap is between step 1 and step 2. Most teams skip sanitization because:&lt;/p&gt;

&lt;ol&gt;
&lt;li&gt;
&lt;strong&gt;Cloud DLP services&lt;/strong&gt; (Google, AWS Macie) require uploading your data — defeating the purpose&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Python-based tools&lt;/strong&gt; (Presidio, scrubadub) are slow on large log files and need heavy dependencies&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Manual regex&lt;/strong&gt; is fragile and doesn't handle context (is &lt;code&gt;1.2.3.4&lt;/code&gt; an IP or a version number?)&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;I needed something that could:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Process 780MB in &amp;lt; 3 minutes on a single machine&lt;/li&gt;
&lt;li&gt;Run &lt;strong&gt;100% offline&lt;/strong&gt; — no network calls, ever&lt;/li&gt;
&lt;li&gt;Handle 11+ PII types across 7 jurisdictions (GDPR, HIPAA, CCPA, PIPL, APPI, PDPA)&lt;/li&gt;
&lt;li&gt;Produce consistent tokenization for AI training (&lt;code&gt;user@test.com&lt;/code&gt; → &lt;code&gt;[EMAIL_0001]&lt;/code&gt; everywhere)&lt;/li&gt;
&lt;/ul&gt;




&lt;h2&gt;
  
  
  Architecture: Why Go, and Why Zero-Allocation
&lt;/h2&gt;

&lt;p&gt;Go was chosen for one reason: &lt;strong&gt;predictable memory behavior at high throughput&lt;/strong&gt;. No GC pauses, no JIT warmup, no pip dependency hell.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;CLI / GUI Entry&lt;/strong&gt;&lt;br&gt;
→ Fyne GUI (drag &amp;amp; drop) | CLI Mode (batch processing)&lt;br&gt;
→ &lt;strong&gt;Compliance Profiles&lt;/strong&gt; (PIPL / GDPR / CCPA / HIPAA / APPI / PDPA)&lt;br&gt;
→ &lt;strong&gt;Core Engine&lt;/strong&gt; — pure &lt;code&gt;[]byte&lt;/code&gt; pipeline:&lt;br&gt;
  &lt;code&gt;PreFilter → Regex → Validate → Tokenize → Write&lt;/code&gt;&lt;br&gt;
  powered by &lt;code&gt;sync.Pool&lt;/code&gt; · lock-free stats · streaming I/O&lt;/p&gt;

&lt;p&gt;The engine never converts &lt;code&gt;[]byte&lt;/code&gt; to &lt;code&gt;string&lt;/code&gt; in the hot path. Here's why that matters:&lt;/p&gt;
&lt;h3&gt;
  
  
  Trick 1: PreFilter Byte Probes
&lt;/h3&gt;

&lt;p&gt;Before running regex (expensive), every line passes through a cheap byte probe:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="k"&gt;type&lt;/span&gt; &lt;span class="n"&gt;Pattern&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;ID&lt;/span&gt;        &lt;span class="kt"&gt;string&lt;/span&gt;
    &lt;span class="n"&gt;Name&lt;/span&gt;      &lt;span class="kt"&gt;string&lt;/span&gt;
    &lt;span class="n"&gt;Regex&lt;/span&gt;     &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;regexp&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Regexp&lt;/span&gt;
    &lt;span class="n"&gt;PreFilter&lt;/span&gt; &lt;span class="k"&gt;func&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;line&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt;  &lt;span class="c"&gt;// ← fast reject&lt;/span&gt;
    &lt;span class="n"&gt;Validate&lt;/span&gt;  &lt;span class="k"&gt;func&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;match&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt; &lt;span class="c"&gt;// ← context-aware&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;For example, the email pattern's PreFilter just checks if the line contains &lt;code&gt;@&lt;/code&gt;:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="n"&gt;PreFilter&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="k"&gt;func&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;line&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;bytes&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;ContainsRune&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;line&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="sc"&gt;'@'&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Result&lt;/strong&gt;: ~80% of lines are skipped before regex runs. On a 780MB server log, this saves ~45 seconds.&lt;/p&gt;

&lt;h3&gt;
  
  
  Trick 2: sync.Pool Buffer Reuse
&lt;/h3&gt;

&lt;p&gt;Every output line needs a buffer. Allocating and GC'ing millions of buffers kills throughput:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="k"&gt;var&lt;/span&gt; &lt;span class="n"&gt;bufPool&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;sync&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Pool&lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;New&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="k"&gt;func&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt; &lt;span class="k"&gt;interface&lt;/span&gt;&lt;span class="p"&gt;{}&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;b&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="nb"&gt;make&lt;/span&gt;&lt;span class="p"&gt;([]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="m"&gt;4096&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;b&lt;/span&gt;
    &lt;span class="p"&gt;},&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="c"&gt;// In hot loop:&lt;/span&gt;
&lt;span class="n"&gt;bp&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="n"&gt;bufPool&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Get&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="n"&gt;buf&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;bp&lt;/span&gt;&lt;span class="p"&gt;)[&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt;&lt;span class="m"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt; &lt;span class="c"&gt;// reset length, keep capacity&lt;/span&gt;
&lt;span class="c"&gt;// ... write to buf ...&lt;/span&gt;
&lt;span class="n"&gt;bufPool&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Put&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;bp&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="c"&gt;// return to pool&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;&lt;strong&gt;Result&lt;/strong&gt;: heap allocations drop from millions to ~50. GC pressure essentially zero.&lt;/p&gt;

&lt;h3&gt;
  
  
  Trick 3: Context-Aware Validation
&lt;/h3&gt;

&lt;p&gt;The regex for IPv4 (&lt;code&gt;\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b&lt;/code&gt;) matches version numbers like &lt;code&gt;1.2.3.4&lt;/code&gt; and file paths like &lt;code&gt;data.2024.01.15&lt;/code&gt;. The Validate callback handles this:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="n"&gt;Validate&lt;/span&gt;&lt;span class="o"&gt;:&lt;/span&gt; &lt;span class="k"&gt;func&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;match&lt;/span&gt; &lt;span class="p"&gt;[]&lt;/span&gt;&lt;span class="kt"&gt;byte&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kt"&gt;bool&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="c"&gt;// Reject if preceded by "version", "v", "=" etc.&lt;/span&gt;
    &lt;span class="c"&gt;// Reject if all octets &amp;gt; 255&lt;/span&gt;
    &lt;span class="c"&gt;// Reject if it looks like a date pattern&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;isLikelyIP&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;match&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;This eliminated &lt;strong&gt;94% of false positives&lt;/strong&gt; in our production logs without sacrificing recall.&lt;/p&gt;

&lt;h3&gt;
  
  
  Trick 4: RWMutex Tokenization
&lt;/h3&gt;

&lt;p&gt;For AI training data, you need consistent tokens: the same email should always map to &lt;code&gt;[EMAIL_0001]&lt;/code&gt;. The tokenizer uses a read-write split:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight go"&gt;&lt;code&gt;&lt;span class="k"&gt;type&lt;/span&gt; &lt;span class="n"&gt;Tokenizer&lt;/span&gt; &lt;span class="k"&gt;struct&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;mu&lt;/span&gt;     &lt;span class="n"&gt;sync&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;RWMutex&lt;/span&gt;
    &lt;span class="n"&gt;tokens&lt;/span&gt; &lt;span class="k"&gt;map&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="kt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="kt"&gt;string&lt;/span&gt;
    &lt;span class="n"&gt;counts&lt;/span&gt; &lt;span class="k"&gt;map&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="kt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;

&lt;span class="k"&gt;func&lt;/span&gt; &lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;t&lt;/span&gt; &lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;Tokenizer&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="n"&gt;GetToken&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;typ&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;value&lt;/span&gt; &lt;span class="kt"&gt;string&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="kt"&gt;string&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
    &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mu&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;RLock&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="k"&gt;if&lt;/span&gt; &lt;span class="n"&gt;tok&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;ok&lt;/span&gt; &lt;span class="o"&gt;:=&lt;/span&gt; &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;tokens&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;key&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt; &lt;span class="n"&gt;ok&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
        &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mu&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;RUnlock&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
        &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;tok&lt;/span&gt;  &lt;span class="c"&gt;// fast path: read-only&lt;/span&gt;
    &lt;span class="p"&gt;}&lt;/span&gt;
    &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mu&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;RUnlock&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;

    &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mu&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Lock&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="c"&gt;// ... create new token ...&lt;/span&gt;
    &lt;span class="n"&gt;t&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;mu&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Unlock&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
    &lt;span class="k"&gt;return&lt;/span&gt; &lt;span class="n"&gt;newToken&lt;/span&gt;  &lt;span class="c"&gt;// slow path: only for first occurrence&lt;/span&gt;
&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;In real logs, PII values repeat heavily. The RLock fast path handles ~95% of lookups with zero contention.&lt;/p&gt;




&lt;h2&gt;
  
  
  Benchmark: 780MB Production Log
&lt;/h2&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Metric&lt;/th&gt;
&lt;th&gt;Value&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;Input size&lt;/td&gt;
&lt;td&gt;780 MB (4.2M lines)&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;PII instances found&lt;/td&gt;
&lt;td&gt;47,283&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Processing time&lt;/td&gt;
&lt;td&gt;2 min 48 sec&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Peak memory&lt;/td&gt;
&lt;td&gt;12 MB&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;Throughput&lt;/td&gt;
&lt;td&gt;~4.6 MB/s&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;False positive rate&lt;/td&gt;
&lt;td&gt;&amp;lt; 0.3% (validated on 1,000 random samples)&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;For comparison, a Python regex-based approach on the same file took &lt;strong&gt;23 minutes&lt;/strong&gt; with 1.8GB peak memory.&lt;/p&gt;




&lt;h2&gt;
  
  
  Multi-Jurisdiction Compliance
&lt;/h2&gt;

&lt;p&gt;The tool ships with 7 compliance profiles, each enabling only the PII patterns required by that jurisdiction:&lt;/p&gt;

&lt;div class="table-wrapper-paragraph"&gt;&lt;table&gt;
&lt;thead&gt;
&lt;tr&gt;
&lt;th&gt;Profile&lt;/th&gt;
&lt;th&gt;Jurisdiction&lt;/th&gt;
&lt;th&gt;What It Catches&lt;/th&gt;
&lt;/tr&gt;
&lt;/thead&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;default&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Full scan&lt;/td&gt;
&lt;td&gt;All 11 pattern types&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;pipl&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;China (PIPL)&lt;/td&gt;
&lt;td&gt;ID Card, CN Mobile, Email, IPv4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;gdpr&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;EU (GDPR)&lt;/td&gt;
&lt;td&gt;Email, IPv4/v6, Credit Card&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;ccpa&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;California (CCPA)&lt;/td&gt;
&lt;td&gt;Email, IP, Phone, Credit Card, SSN&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;hipaa&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;US Medical (HIPAA)&lt;/td&gt;
&lt;td&gt;Email, Phone, SSN, IPv4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;appi&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Japan (APPI)&lt;/td&gt;
&lt;td&gt;Email, Phone, My Number, IPv4&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td&gt;&lt;code&gt;pdpa&lt;/code&gt;&lt;/td&gt;
&lt;td&gt;Singapore/Thailand&lt;/td&gt;
&lt;td&gt;Email, Phone, IPv4, ID Card&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;&lt;/div&gt;

&lt;p&gt;Switch profiles with a single flag:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight shell"&gt;&lt;code&gt;./pii_redactor &lt;span class="nt"&gt;--input&lt;/span&gt; server.log &lt;span class="nt"&gt;--profile&lt;/span&gt; gdpr &lt;span class="nt"&gt;--output&lt;/span&gt; clean.log
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;






&lt;h2&gt;
  
  
  Audit Report
&lt;/h2&gt;

&lt;p&gt;Every run generates an audit report — essential for compliance documentation:&lt;br&gt;
&lt;/p&gt;

&lt;div class="highlight js-code-highlight"&gt;
&lt;pre class="highlight plaintext"&gt;&lt;code&gt;═══════════════════════════════════════════
  PII Redaction Audit Report
═══════════════════════════════════════════
  File: server_2024.log
  Encoding: UTF-8
  Lines: 4,218,903
  Duration: 2m48s
  ─────────────────────────────────────
  PII Type          Hits    Examples
  ─────────────────────────────────────
  Email             12,847  user@corp.com → [EMAIL_0001]
  IPv4              28,102  10.0.0.1 → [IP_0001]
  Credit Card          891  4111...1111 → [CC_0001]
  Phone (Intl)       2,443  +1-202-... → [PHONE_0001]
  JWT                3,000  eyJhbG... → [JWT_0001]
═══════════════════════════════════════════
&lt;/code&gt;&lt;/pre&gt;

&lt;/div&gt;



&lt;p&gt;The tokenization map (&lt;code&gt;[EMAIL_0001]&lt;/code&gt; ↔ original value) is kept in memory only during processing and never written to disk — zero data leakage by design.&lt;/p&gt;




&lt;h2&gt;
  
  
  Try It
&lt;/h2&gt;

&lt;p&gt;The tool runs on Windows, macOS (Apple Silicon), and Linux. No dependencies, no Docker, no cloud account.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;GitHub&lt;/strong&gt;: &lt;a href="https://github.com/gn000q/pii_redactor" rel="noopener noreferrer"&gt;github.com/gn000q/pii_redactor&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;Download pre-built binaries&lt;/strong&gt;: &lt;a href="https://gnqster.gumroad.com/l/pii-redactor-v2" rel="noopener noreferrer"&gt;PII Redactor V2 on Gumroad&lt;/a&gt; — includes cross-platform binaries, sample test data, config templates, and a quick-start guide.&lt;/p&gt;




&lt;h2&gt;
  
  
  What's Next
&lt;/h2&gt;

&lt;p&gt;I'm considering adding:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;YAML/JSON structured log parsing (currently handles flat text)&lt;/li&gt;
&lt;li&gt;Custom pattern loading from external config files&lt;/li&gt;
&lt;li&gt;Streaming mode for piped input (&lt;code&gt;tail -f | pii_redactor&lt;/code&gt;)&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;&lt;strong&gt;What does your PII cleanup workflow look like?&lt;/strong&gt; I'd love to hear if you're dealing with similar issues — especially if you're feeding logs to AI APIs.&lt;/p&gt;

</description>
      <category>go</category>
      <category>security</category>
      <category>ai</category>
      <category>privacy</category>
    </item>
  </channel>
</rss>
