Glossary
Terms used across the piighost documentation. Each entry defines the concept by
what it does. Class names stay in English.
- Anonymization
- Removing PII with no way to restore it. Irreversible by definition. A redacting placeholder factory anonymizes, since it keeps no mapping back to the value.
- Cipher
- A component that reversibly encrypts and decrypts bytes, so a store keeps
ciphertext instead of plaintext. A leak of the store yields nothing without
the key, held outside it.
RedisConversationMemoryandSqlAlchemyConversationMemorycan use one to encrypt persisted values.AesGcmCipheris the built-in AES-GCM backend. - Confidential data
- Everything
piighostprotects, that is personal data (PII) and secrets such as API keys. Each detected item is a value, replaced by a placeholder in the de-identified text. - Conversation memory
- The store that accumulates a thread's entities across messages, so a value
seen in one message keeps its placeholder in the next.
InMemoryConversationMemoryholds it in the process.RedisConversationMemorypersists it in Redis, andSqlAlchemyConversationMemoryin a SQL table. Both backends can encrypt the values with a cipher and hash the keys. - De-identification
- Replacing confidential data with placeholders while keeping the mapping between each value
and its placeholder, so the original can be restored later. The default
piighostpipeline de-identifies. Under the GDPR this is pseudonymization, not anonymization. - Detection
- One occurrence of a value spotted by a detector, that is a
Span, the matched text, a label, and a confidence in the range 0 to 1. Detecting Patrick asPERSONat(0, 7)with confidence0.95is oneDetection. - Detector
- The component that finds confidential data in a text and returns detections. Detectors
implement the
AnyDetectorprotocol and are interchangeable. The three families are regex, NER, and LLM, listed under their own entries. - Entity
- A group of detections that refer to the same value. Every occurrence of
the value is one detection. The group shares one placeholder and restores to
one value. Different from a detection, which is a single occurrence.
Entity. - Entity resolver
- The component that reconciles conflicting entities, that is entities that
share a detection or whose values are close.
MergeEntityResolvermerges entities that share a detection,FuzzyEntityResolvermerges near-duplicate values.SeparateEntityResolverkeeps the entities apart. It gives each shared detection to the largest entity holding it and drops it from the others. - Guard rail
- A component that re-checks the de-identified text for confidential data the pipeline missed. It
runs after replacement and raises if a residual value remains. A guard rail can
re-run a detector (
DetectorGuardRail), classify the output with a local GLiNER2 model (Gliner2GuardRail), query an LLM (LLMGuardRail) or the Mistral moderation API (ModerationGuardRail). - Linker
- The component that groups detections into entities. It finds the occurrences
that refer to the same value, so they share a placeholder. Linking
Patrick at
(0, 7)and patrick at(34, 41)yields one entity.ExactEntityLinker. - LLM detector
- A detector that prompts a large language model to return the values it finds as
structured output. Slower and less deterministic than regex or NER, but able
to reason about context.
LLMDetector. - NER detector
- Named Entity Recognition. An AI model that classifies the words of a text into
categories decided in advance, such as person, location, or organization.
Works on free text where a pattern cannot.
Gliner2Detector,Gliner2PiiDetector,SpacyDetector,TransformersDetector,PresidioDetector, andBridgeDetector, which awaits a model run elsewhere, for example in JavaScript in the browser. - Pepper
- A secret that keys a hasher, read from the
PIIGHOST_HASH_PEPPERenvironment variable. The pepper is mandatory, because a low-entropy value hashed without a secret stays brute-forceable. Used bySha256HasherandArgon2Hasher. - PII
- Personally Identifiable Information, the personal-data part of confidential
data. Any value that can identify a person, that is
name, address, phone number, email, location, organization, account number.
piighostfinds and replaces PII so a downstream LLM never sees the raw value. - Placeholder
- The token that replaces a value in the de-identified text, for example <<PERSON:1>> or <<EMAIL:1>>. What a placeholder looks like is decided by a placeholder factory.
- Placeholder factory
- The component that produces placeholders. It decides the token shape and what
the token preserves, that is a label, a stable identity, both, or nothing. Built-in
factories include
RedactPlaceholderFactory,LabelPlaceholderFactory,LabelCounterPlaceholderFactory,LabelHashPlaceholderFactory, andMaskPlaceholderFactory. - Placeholder preservation tag
- A phantom type (a type that exists only for the type checker) on a
placeholder factory, stating what its tokens preserve. The concrete tags are
PreservesNothing,PreservesLabel,PreservesShape,PreservesIdentityOnly,PreservesLabeledIdentityOpaque, andPreservesLabeledIdentityHashed.PreservesIdentity,PreservesRecognizableIdentity, andPreservesLabeledIdentityare abstract tags that group them. The middleware requiresPreservesRecognizableIdentityso it can restore values. It rejects a factory without this tag at type-check time. - Recognizer
- The token grammar the middleware uses to find a pipeline's placeholders in an
LLM response, without reaching into the anonymizer. A pipeline exposes it in its
recognizerattribute, which holds aBaseDelimitedPlaceholderFactoryorNone. - Regex detector
- A detector that recognizes fixed patterns, character strings that follow a
known structure such as an IBAN or a phone number. Effective on structured
formats, useless on free text like a first name or a written date.
RegexDetector. - Secret
- A credential that must never reach a model, such as an API key, an access
token, a private key, or a connection string. Secrets are the other part of
confidential data. They are detected through the catalog groups
piighost/secretsandpiighost/secrets-extended, pulled for example withcatalogs = ["catalog:piighost/secrets"]. The other catalog groups,piighost/genericand the regional ones, hold no secret pattern.Gliner2PiiDetectoralso asks its model for API keys and passwords. - Span
- A half-open character range
[start, end)inside a text, mirroring Python slice semantics. Every detection carries aSpanto mark where the value sits.Span. - Thread
- A conversation scope identified by a
thread_id. Memory is isolated per thread, so two parallel conversations never share confidential data. A placeholder stays stable across all the messages of one thread. - thread_id
- The string that identifies a thread. The thread pipeline and the middleware use it to scope memory and to route each message to the right conversation.