Person tag · Building Now
PII — Personal information redacted
Removes detected personal information before the local checker reads your text.
It can miss sensitive information. A PII tag does not mean the text is completely private.
Validation · Local preview
Validation in progress
The local workflow has passed development checks. Independent accuracy testing and human accessibility review are still pending.
Use this tag
PII runs automatically before PS in the same local package. There is no separate PII installation or complete-privacy guarantee.
Developer preview: Linux or macOS, Python 3.12+, Git, make, and Docker Engine with Compose. First setup downloads packages and models. A one-click installer and a Chrome Web Store release are not available yet.
Download source · Full setup guide
Get the source
Download the ZIP and read its README, or use Git:
git clone https://github.com/knwvmbrr/aitrust-id.git cd aitrust-idPrepare the checker
From the repository folder, install its checker dependencies:
python3 -m venv .venv .venv/bin/python -m pip install -r eval/requirements.txt python3 scripts/aitrust.py initStart your local services
With Docker Engine and Compose running, build and start only AI Trust ID:
make deploy ENV_FILE="$HOME/.config/aitrust-id/runtime.env" .venv/bin/python scripts/aitrust.py doctorCheck an answer
Save the answer as response.txt in this folder, then run:
.venv/bin/python scripts/aitrust.py check response.txt
A PII tag means detected values were redacted before checking. No PII tag does not prove that the answer contains no private information.
Optional Chrome tags: open chrome://extensions, enable Developer mode, choose Load unpacked, select this repository’s extension folder, then enter your local token in its options. Keep the services running and open ChatGPT. Tags appear below supported answers; click a tag for a short explanation.
Your answer goes to your own local service, not this website or a training database. Keep your token private. Do not paste it into a public report.
Stop the checker
make down ENV_FILE="$HOME/.config/aitrust-id/runtime.env"Baseline job
Redact detected personal information before local evaluation.
What the tag can claim
Detected entity values were redacted. Some categories, such as URLs, can contain public information. This does not certify that all sensitive information is gone.
Method and evidence
- Local Presidio recognition with a build-provisioned English model and offline email-domain validation.
- Development · standard v0.1.0
- Recognition thresholds are method settings, not a privacy guarantee.
Input
Original text received by the local gateway.
Output
Redactor output to the evaluator; entity type/count metadata in the assertion, without the original private values.
Supported scope
- Email recognition exercised against the real service
- Detected redaction precedes evaluation
- Offline suffix data; no runtime model download
Limits
- Personal or sensitive information can remain undetected
- English assets are the current development target
- Neither original nor redacted content should be submitted to a public report
Accuracy and validation
Real email redaction, pipeline ordering, source hashes, and synthetic log markers checked. Independent coverage and accuracy measurements are missing.
Cost and access
Free personal workflow. No paid detector, evidence, or verification gate.
Privacy
This catalogue does not evaluate your content. The personal reference implementation uses local services; detected redaction can miss sensitive information.
Dependencies
- Versioned claim and evidence contract
- Independent review for this tag
- Accessible presentation and a clear failure state
Failure behavior
A required redaction failure stops evaluation. It must not bypass redaction to obtain a tag.
Who owns the outcome
Maintainers own implementation; independent reviewers own validation; the product owner accepts release.
Before release
Publish agreed acceptance criteria, run independent validation, and verify the complete user workflow before release.
Tag enhancements in scope
- F-023 — Detected PII redaction. Remove recognized entities before evaluation Scope record; not an implementation claim.
Shared tag capabilities
- F-001 — Assertion envelope schema, JSON Schema 2020-12. Specify and deliver assertion envelope schema, JSON Schema 2020-12. Scope record; not an implementation claim.
- F-003 — Signal registry, 22 registered IDs with version suffixes. Specify and deliver signal registry, 22 registered IDs with version suffixes. Scope record; not an implementation claim.
- F-004 — Abstention as a first-class state — UNK. Specify and deliver abstention as a first-class state — UNK. Scope record; not an implementation claim.
- F-005 — Per-tag confidence floors. Specify and deliver per-tag confidence floors. Scope record; not an implementation claim.
- F-007 — Content-free assertion records. Return hashes, offsets, and metadata without embedding evaluated text Scope record; not an implementation claim.
- F-008 — Signed assertion integrity. Sign an exact canonical tag record with an identified key Scope record; not an implementation claim.
- F-009 — Cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Specify and deliver cost-to-defeat ladder — statistical / behavioural / structural / cryptographic. Scope record; not an implementation claim.
- N-005 — Label dispute, correction, and supersession workflow. Specify and deliver label dispute, correction, and supersession workflow. Scope record; not an implementation claim.
- N-006 — Versioned regression checks and revalidation triggers. Specify and deliver versioned regression checks and revalidation triggers. Scope record; not an implementation claim.
References
Scope record T-PII. Preserved scope is not implementation evidence.