Download the PHP package thejenos/smart-pii-redactor without Composer

On this page you can find all versions of the php package thejenos/smart-pii-redactor. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.

FAQ

After the download, you have to make one include require_once('vendor/autoload.php');. After that you have to import the classes with use statements.

Example:
If you use only one package a project is not needed. But if you use more then one package, without a project it is not possible to import the classes with use statements.

In general, it is recommended to use always a project to download your libraries. In an application normally there is more than one library needed.
Some PHP packages are not free to download and because of that hosted in private repositories. In this case some credentials are needed to access such packages. Please use the auth.json textarea to insert credentials, if a package is coming from a private repository. You can look here for more information.

  • Some hosting areas are not accessible by a terminal or SSH. Then it is not possible to use Composer.
  • To use Composer is sometimes complicated. Especially for beginners.
  • Composer needs much resources. Sometimes they are not available on a simple webspace.
  • If you are using private repositories you don't need to share your credentials. You can set up everything on our site and then you provide a simple download link to your team member.
  • Simplify your Composer build process. Use our own command line tool to download the vendor folder as binary. This makes your build process faster and you don't need to expose your credentials for private repositories.
Please rate this library. Is it a good library?

Informations about the package smart-pii-redactor

Smart PII Redactor for Laravel AI

Latest Version on Packagist Tests Total Downloads

Keep personal data out of your LLM provider's hands. This package adds a provider driver to laravel/ai that sits in front of any other provider (OpenAI, Anthropic, Gemini, …). It finds PII in everything sent to the model, swaps it for placeholders like [PERSON_0], and swaps the real values back into the model's reply.

Your application, including stored conversations, always works with the real values. Only the request to the provider is redacted.

Features

Detected entities

Entity Detected by Example
PERSON NER model Dana Whitcombe
ORGANIZATION NER model Halcyon Data Systems
LOCATION NER model Rotterdam
EMAIL Regex [email protected]
URL Regex https://reports.example.com/v2/export
IPV4_ADDRESS Regex 203.0.113.47
IPV6_ADDRESS Regex 2001:db8:4f2a::9c1
SSN Regex 123-45-6789
CREDIT_CARD Regex 4111 1111 1111 1111
PHONE Regex +1 (503) 555-0142
IBAN Regex GB82WEST12345698765432
API_KEY Regex sk-live-…, AKIA…, secret_key…
BEARER_TOKEN Regex Bearer eyJhbGciOi…

Detection is heuristic. NER models miss some names and flag some non-names, and the phone and IPv6 patterns can match things like dates and times. Treat this as a strong safety net, not a guarantee, and use logging to check real traffic.

Requirements

The NER model is loaded through PHP's FFI extension. With the default ffi.enable=preload, FFI works only on the command line (queues, Artisan), not under PHP-FPM or Octane. To redact in web requests, set this in your php.ini:

Installation

Install the package:

Named-entity recognition uses Stanford NER, which runs on Java, so a Java runtime (8 or newer) must be available as java on the PATH.

The Stanford NER jar and the English 3-class classifier ship with the package in resources/models, so there's nothing else to download.

Configuration

Add a provider named redactor to config/ai.php and point it at the provider that should actually handle the requests:

The provider must be named redactor: the driver reads its settings from ai.providers.redactor.

only and except take entity names or SmartPiiRedactorEntites cases:

Usage

Use redactor wherever you'd pick a provider. Everything else about your agents stays the same.

Per agent, with laravel/ai's Provider attribute:

Or per call:

Streaming works the same way:

Or make it the default for every agent in config/ai.php:

Remembered conversations

Agents that remember conversations store the original prompt and the restored reply. Earlier messages are masked again on every request, so history never reaches the provider unredacted either.

Tools

Tool call arguments are restored before your tool runs, so tools receive real values. Tool results are masked before they're sent back to the model.

Provider-side tools are different: OpenAI's web_search, for example, runs on the provider's servers with the placeholder, so it searches for weather in [LOCATION_0]. The event and the stored step show the restored value, but the search results won't reflect it. If a provider tool needs a real value, either exclude that entity with except, or use your own tool instead.

Using the redactor directly

You can also detect and mask text yourself, without laravel/ai:

The placeholder map is kept in your application's default cache store under the given key.

Verifying what is sent

Set 'log' => true on the redactor provider to record the traffic between your app and the base provider:

Message Level Contents
Provider request. debug Method, URL, headers and the JSON body exactly as sent
Provider response. debug Status, headers and the JSON body ((streamed) for streams)
Provider stream finished. debug The full streamed reply and tool calls, as received
Detected PII is still present in an outgoing message. warning Message index, role and entity tag

Messages are prefixed with [smart-pii-redactor]. Logs only ever contain the redacted data the provider saw, never the restored values. The leak warning names the entity type, not the value. Authorization, x-api-key, api-key and x-goog-api-key headers are replaced with ***.

Security notes

Testing

The tests use the real NER model, so run the installation commands above first.

Changelog

See CHANGELOG for what has changed recently.

Releasing

Releases are automated. Bump version in composer.json and push to main. The release workflow runs the tests, tags vX.Y.Z, publishes a GitHub release, notifies Packagist and updates the changelog. Pushes that don't change the version don't release anything.

Security vulnerabilities

Please report security issues privately to [email protected] rather than opening a public issue.

Credits

License

The MIT License (MIT). See LICENSE for more information.


All versions of smart-pii-redactor with dependencies

PHP Build Version
Package Version
Requires php Version ^8.4
agentile/php-stanford-nlp Version ^0.1.1
illuminate/contracts Version ^11.0||^12.0||^13.0
laravel/ai Version ^1.0
spatie/laravel-package-tools Version ^1.16
Composer command for our command line client (download client) This client runs in each environment. You don't need a specific PHP version etc. The first 20 API calls are free. Standard composer command

The package thejenos/smart-pii-redactor contains the following files

Loading the files please wait ...