Capability status
A plain-language map of what is stable, model-dependent, and experimental in the current release.
Keep raw customer text outside the model boundary.
A local API that detects, replaces, and records safely.
Run it, send text, pass only the returned text onward.
Status at a glance
Structured regex detection and typed replacement
Email, phone, IBAN, SSN, IPv4, URL, and Luhn-checked card patterns are the clearest local path. Validate your own corpus.
GLiNER2 local model path
The pinned local model can add contextual entities. Model availability, warm-up, runtime, and revision must be part of readiness and rollout checks.
HTTP operations
Authentication, rate limiting, idempotency, health probes, metrics, traces, and the local audit backend exist, but deployment configuration and retention remain operator-owned.
Relexicalization and reversible workflows
Readable replacements can help downstream tasks, but collision, restoration, and access-control risks require an application-specific review.
Browser/WASM surface
The public browser demo is regex-only and illustrative. It does not represent server-side model parity or complete DLP coverage.
Before calling it production
Pin versions, run the test suite and a representative corpus, verify the exact response contract, inspect every observability sink, and define what happens when Redis or the local model is unavailable. “Running” is not the same as “safe for your workload.”
Source of truth
This page describes the current repository, not a promise about an unreleased roadmap. If code, configuration, and marketing copy disagree, treat the code and release notes as the starting point for an issue and verify the behavior before deployment. The launch audit records what is fixed, deferred, and still operator-owned.