PII coverage
The pii detector finds 83 kinds of personal identifier with nothing configured, 51 of them confirmed by a checksum rather than a pattern alone. Each carries its patterns, its validator where there is one, and its context words.
The patterns come from presidio-analyzer 2.2.364 (revision 779dbd286d5e, MIT). 9 of the recognizers are pistra’s own, where Presidio has none, marked ‡ and listed below with their evidence. The page is generated from the tables the detector runs, so it cannot list a type the detector does not produce.
The detector is named for the bulk of what it finds, not for all of it. It also finds 19 kinds of API key and private key material, and those have their own page. An API key is not personal data, and it annotates credential/… rather than pii/…. The two are described by different facts: an identifier by its checksum, its language and its fpe alphabet, a credential by the prefix that carries it and where that shape was read from.
84 recognizers · 83 entity types · 166 patterns · 51 checksum-validated · language tags: de 13, en 51, es 3, fi 1, it 5, ko 4, kr 1, pl 1, sv 2, th 1, tr 2.
Entity types
Section titled “Entity types”Score is what a match is worth on its own, over the recognizer’s patterns, and +context the same range once one of the Context words is found near it. That second number is the one most rules see, since every recognizer here carries context words. Scores below is how to read both, and why a rule should usually ask a.validated || a.context_supported rather than name a threshold. Checksum says the recognizer has a validator. A span it accepts scores 1.0 and one it rejects is dropped, though it may also abstain and leave the pattern’s score standing. fpe is the alphabet the fpe operator uses for the type out of the box; a type without one is declined by that operator until fpe_alphabets names it. Max span is the longest match the recognizer can produce, in bytes, and it is what a streamed response is held back by when this type is enabled (see the commit horizon); a † means a pattern has an open repeat charged at a cap rather than measured.
| Entity | Recognizer | Language | Patterns | Score | +context | Checksum | fpe | Max span | Context |
|---|---|---|---|---|---|---|---|---|---|
ABA_ROUTING_NUMBER |
AbaRoutingRecognizer |
en | 2 | 0.05 – 0.30 | 0.40 – 0.65 | yes | digits | 38 | aba, routing, abarouting, association, bankrouting |
AE_EMIRATES_ID |
AeEmiratesIdRecognizer ‡ |
en | 1 | 0.50 | 0.85 | 63 | emirates id, eid, id number, الهوية الإماراتية, رقم الهوية, بطاقة الهوية, icp | ||
AE_PASSPORT |
AePassportRecognizer ‡ |
en | 1 | 0.10 | 0.45 | 33 | passport, passport number, جواز, جواز السفر, رقم الجواز | ||
AE_TRN |
AeTrnRecognizer ‡ |
en | 1 | 0.20 | 0.55 | 63 | trn, tax registration number, vat, الرقم الضريبي, رقم التسجيل الضريبي, fta | ||
AU_ABN |
AuAbnRecognizer |
en | 2 | 0.01 – 0.10 | 0.40 – 0.45 | yes | digits | 47 | australian business number, abn |
AU_ACN |
AuAcnRecognizer |
en | 2 | 0.01 – 0.10 | 0.40 – 0.45 | yes | digits | 38 | australian company number, acn |
AU_MEDICARE |
AuMedicareRecognizer |
en | 2 | 0.01 – 0.10 | 0.40 – 0.45 | yes | digits | 42 | medicare |
AU_TFN |
AuTfnRecognizer |
en | 2 | 0.01 – 0.10 | 0.40 – 0.45 | yes | digits | 38 | tax file number, tfn |
CA_SIN |
CaSinRecognizer |
en | 2 | 0.05 – 0.50 | 0.40 – 0.85 | yes | digits | 38 | sin, sin number, social insurance, social insurance number, canada, nas, numéro nas, numéro d’assurance sociale, assurance sociale |
CREDIT_CARD |
CreditCardRecognizer |
en | 1 | 0.30 | 0.65 | yes | digits | 71 | credit, card, visa, mastercard, cc , amex, discover, jcb, diners, maestro, instapayment |
CRYPTO |
CryptoRecognizer |
en | 1 | 0.50 | 0.85 | yes | 242 | wallet, btc, bitcoin, crypto | |
DATE_TIME |
DateRecognizer |
en | 13 | 0.10 – 0.80 | 0.45 – 1.00 | 144† | date, birthday | ||
DE_BSNR |
DeBsnrRecognizer |
de | 1 | 0.20 | 0.55 | yes | 36 | betriebsstättennummer, betriebsstätten-nummer, bsnr, betriebsstätte, praxisnummer, arztpraxis, praxis, kassenärztliche vereinigung, kv-nummer, kv nummer, praxisadresse, praxisstandort, nebenbetriebsstätte, hauptbetriebsstätte, behandlungsort, vertragsarztpraxis | |
DE_FUEHRERSCHEIN |
DeFuehrerscheinRecognizer |
de | 1 | 0.35 | 0.70 | 42 | führerscheinnummer, führerschein, fahrerlaubnis, fahrerlaubnisnummer, fahrerlaubnisklasse, führerscheininhaber, fev, kba, kraftfahrt-bundesamt, driving licence, driving license, driver’s license, licence number, license number, dokument nr, dokument-nr, feld 5 | ||
DE_HANDELSREGISTER |
DeHandelsregisterRecognizer |
de | 1 | 0.50 | 0.85 | 91† | handelsregister, handelsregisternummer, amtsgericht, registergericht, hra, hrb, hr-nummer, registerauszug, handelsregistereintrag, firma, gesellschaft, gmbh, ag, ug, kg, ohg, einzelkaufmann, einzelkauffrau, handelsregisterblattnummer | ||
DE_HEALTH_INSURANCE |
DeHealthInsuranceRecognizer |
de | 1 | 0.30 | 0.65 | yes | 39 | krankenversicherungsnummer, krankenversichertennummer, versichertennummer, kvnr, krankenkasse, krankenversicherung, gesundheitskarte, egk, elektronische gesundheitskarte, gkv, gesetzliche krankenversicherung, krankenversicherungsausweis, versichertenausweis, versichertenkarte, aok, tkk, barmer, dak | |
DE_ID_CARD |
DeIdCardRecognizer |
de | 2 | 0.40 – 0.50 | 0.75 – 0.85 | yes | 35 | personalausweis, ausweis, personalausweisnummer, ausweisnummer, ausweisdokument, dokumentennummer, seriennummer, npa, neuer personalausweis, personalausweisgesetz, pauwsg, bundespersonalausweis, identity card, national id | |
DE_KFZ |
DeKfzRecognizer |
de | 5 | 0.20 – 0.30 | 0.55 – 0.65 | 34 | kennzeichen, kfz-kennzeichen, kraftfahrzeugkennzeichen, nummernschild, fahrzeugkennzeichen, zulassung, kfz, fahrzeug, auto, pkw, lkw, fahrzeugschein, fahrzeugbrief, zulassungsbescheinigung, amtliches kennzeichen | ||
DE_LANR |
DeLanrRecognizer |
de | 1 | 0.30 | 0.65 | yes | 36 | arztnummer, lanr, lebenslange arztnummer, arzt-nr, arzt nr, arzt-nummer, vertragsarzt, kassenarzt, niedergelassener arzt, kbv, kassenärztliche vereinigung, kv-nummer, rezept, verschreibung, behandelnder arzt, hausarzt, facharzt | |
DE_PASSPORT |
DePassportRecognizer |
de | 1 | 0.40 | 0.75 | yes | 35 | reisepass, pass, passnummer, reisepassnummer, passport, passport number, pass-nr, dokumentennummer, bundesrepublik deutschland, ausweisdokument, mrz | |
DE_PLZ |
DePlzRecognizer |
de | 1 | 0.05 | 0.40 | 20 | plz, postleitzahl, postanschrift, adresse, wohnort, ort, wohnanschrift, lieferadresse, rechnungsadresse, straße, strasse, hausnummer, postfach, bundesland, gemeinde, stadt, dorf | ||
DE_SOCIAL_SECURITY |
DeSocialSecurityRecognizer |
de | 2 | 0.30 – 0.50 | 0.65 – 0.85 | yes | 47 | rentenversicherungsnummer, sozialversicherungsnummer, versicherungsnummer, rvnr, svnr, sv-nummer, rente, rentenversicherung, deutsche rentenversicherung, drv, sozialversicherung, sozialversicherungsausweis, rentenausweis | |
DE_TAX_ID |
DeTaxIdRecognizer |
de | 1 | 0.50 | 0.85 | yes | 44 | steueridentifikationsnummer, steuer-id, steuerid, steuerliche identifikationsnummer, steuerliche identifikation, persönliche identifikationsnummer, steuer identifikation, idnr, steuer-idnr, steuernummer, bzst | |
DE_TAX_NUMBER |
DeTaxNumberRecognizer |
de | 3 | 0.20 – 0.50 | 0.55 – 0.85 | 52 | steuernummer, steuer-nr, steuer nr, st.-nr, st-nr, finanzamt, umsatzsteuer, einkommensteuer, körperschaftsteuer, gewerbesteuer, steuerveranlagung, steuerbescheid | ||
DE_VAT_ID |
DeVatIdRecognizer |
de | 2 | 0.40 – 0.50 | 0.75 – 0.85 | yes | 41 | umsatzsteuer-identifikationsnummer, umsatzsteueridentifikationsnummer, ust-idnr, ust-id, ustidnr, umsatzsteuer-id, mehrwertsteuer, vat, vat-id, vat id, steueridentifikation, bzst, bundeszentralamt für steuern, finanzamt, invoice, rechnung | |
EMAIL_ADDRESS |
EmailRecognizer |
en | 1 | 0.50 | 0.85 | yes | 458† | ||
ES_NIE |
EsNieRecognizer |
es | 1 | 0.50 | 0.85 | yes | 37 | número de identificación de extranjero, NIE | |
ES_NIF |
EsNifRecognizer |
es | 1 | 0.50 | 0.85 | yes | 36 | documento nacional de identidad, DNI, NIF, identificación | |
ES_PASSPORT |
EsPassportRecognizer |
es | 1 | 0.05 | 0.40 | 33 | pasaporte, passport, número de pasaporte, passport number | ||
FI_PERSONAL_IDENTITY_CODE |
FiPersonalIdentityCodeRecognizer |
fi | 2 | 0.10 – 0.50 | 0.45 – 0.85 | yes | 41 | hetu, henkilötunnus, personbeteckningen, personal identity code | |
IBAN_CODE |
IbanRecognizer |
en | 3 | 0.50 | 0.85 | yes | 142 | iban, bank, transaction | |
IBAN_CODE |
OmIbanRecognizer ‡ |
en | 1 | 0.50 | 0.85 | yes | 91 | iban, account, bank, آيبان, رقم الحساب, حساب | |
IN_AADHAAR |
InAadhaarRecognizer |
en | 2 | 0.01 | 0.40 | yes | digits | 50 | aadhaar, uidai |
IN_GSTIN |
InGstinRecognizer |
en | 3 | 0.10 – 0.80 | 0.45 – 1.00 | yes | 57 | gstin, gst, goods and services tax, tax identification, gst number, gst registration | |
IN_PAN |
InPanRecognizer |
en | 3 | 0.01 – 0.50 | 0.40 – 0.85 | 40 | permanent account number, pan | ||
IN_PASSPORT |
InPassportRecognizer |
en | 1 | 0.10 | 0.45 | 32 | passport, indian passport, passport number | ||
IN_VEHICLE_REGISTRATION |
InVehicleRegistrationRecognizer |
en | 9 | 0.01 – 0.85 | 0.40 – 1.00 | yes | 38 | RTO, vehicle, plate, registration | |
IN_VOTER |
InVoterRecognizer |
en | 2 | 0.30 – 0.40 | 0.65 – 0.75 | 37 | voter, epic, elector photo identity card | ||
IP_ADDRESS |
IpRecognizer |
en | 12 | 0.10 – 0.60 | 0.45 – 0.95 | yes | 218† | ip, ipv4, ipv6 | |
IT_DRIVER_LICENSE |
ItDriverLicenseRecognizer |
it | 1 | 0.20 | 0.55 | 37 | patente, patente di guida, licenza, licenza di guida | ||
IT_FISCAL_CODE |
ItFiscalCodeRecognizer |
it | 1 | 0.30 | 0.65 | yes | 54 | codice fiscale, cf | |
IT_IDENTITY_CARD |
ItIdentityCardRecognizer |
it | 3 | 0.01 | 0.40 | 35 | carta, identità, elettronica, cie, documento, riconoscimento, espatrio | ||
IT_PASSPORT |
ItPassportRecognizer |
it | 1 | 0.01 | 0.40 | 34 | passaporto, elettronico, italiano, viaggio, viaggiare, estero, documento, dogana | ||
IT_VAT_CODE |
ItVatCodeRecognizer |
it | 1 | 0.10 | 0.45 | yes | 55 | piva, partita iva, pi | |
KR_BRN |
KrBrnRecognizer |
ko | 2 | 0.05 – 0.10 | 0.40 – 0.45 | yes | 42 | 사업자등록번호, 사업자번호, 사업자, BRN, Business Registration Number, Korean BRN, business number, tax registration number | |
KR_DRIVER_LICENSE |
KrDriverLicenseRecognizer |
ko | 1 | 0.05 | 0.40 | yes | 51 | 운전면허, 운전면허번호, 면허번호, Korean driver license, Korean driver’s license | |
KR_FRN |
KrFrnRecognizer |
ko | 1 | 0.50 | 0.85 | yes | 53 | 외국인등록번호, Korean FRN, FRN, Foreigner Registration Number, Korean Foreigner Registration Number, 외국인번호 | |
KR_PASSPORT |
KrPassportRecognizer |
kr | 2 | 0.05 – 0.10 | 0.40 – 0.45 | 34 | Korean passport, Korean passport number, 대한민국 여권, 여권, passport, passport number | ||
KR_RRN |
KrRrnRecognizer |
ko | 1 | 0.50 | 0.85 | yes | digits | 53 | Korean RRN, Korean Resident Registration Number, Resident Registration Number, RRN, rrn, rrn# |
KW_CIVIL_ID |
KwCivilIdRecognizer ‡ |
en | 1 | 0.30 | 0.65 | yes | digits | 48 | civil id, civil number, paci, البطاقة المدنية, الرقم المدني, رقم البطاقة المدنية |
MAC_ADDRESS |
MacAddressRecognizer |
en | 2 | 0.60 | 0.95 | yes | 53 | mac, mac address, hardware address, physical address, ethernet | |
MEDICAL_LICENSE |
MedicalLicenseRecognizer |
en | 1 | 0.40 | 0.75 | yes | 35 | medical, certificate, DEA | |
NG_NIN |
NgNinRecognizer |
en | 1 | 0.01 | 0.40 | yes | digits | 44 | nin, national identification number, national identity number, nimc, national identity, nigeria id, nigerian identification |
NG_VEHICLE_REGISTRATION |
NgVehicleRegistrationRecognizer |
en | 1 | 0.50 | 0.85 | 28 | plate number, vehicle registration, license plate, number plate, plate, vehicle, registration | ||
PHONE_NUMBER |
PhoneRecognizer |
en | 1 | 0.40 | 0.75 | digits | 95 | phone, number, telephone, cell, cellphone, mobile, call | |
PH_TIN |
PhTinRecognizer |
en | 2 | 0.01 – 0.05 | 0.40 | yes | 51 | tin, taxpayer identification number, bir, taxpayer id, tax id, rdo, revenue district office | |
PH_UMID |
PhUmidRecognizer |
en | 2 | 0.30 – 0.50 | 0.65 – 0.85 | 50 | umid, unified multi-purpose id, crn, common reference number, sss, gsis, philhealth, pag-ibig, umid number, umid card, unified multipurpose id | ||
PL_PESEL |
PlPeselRecognizer |
pl | 1 | 0.40 | 0.75 | yes | digits | 44 | PESEL |
QA_ID |
QaIdRecognizer ‡ |
en | 1 | 0.10 | 0.45 | digits | 44 | qid, qatar id, qatari id, id number, البطاقة الشخصية, رقم البطاقة الشخصية, رقم الهوية, moi, metrash | |
SA_NATIONAL_ID |
SaNationalIdRecognizer ‡ |
en | 1 | 0.30 | 0.65 | yes | digits | 40 | national id, iqama, id number, هوية, الهوية, الهوية الوطنية, رقم الهوية, إقامة, الإقامة, رقم الإقامة, absher, أبشر |
SA_UNIFIED_NUMBER |
SaUnifiedNumberRecognizer ‡ |
en | 1 | 0.10 | 0.45 | digits | 40 | unified number, unified national number, الرقم الموحد, رقم المنشأة, 700 number | |
SA_VAT_NUMBER |
SaVatRecognizer ‡ |
en | 2 | 0.10 – 0.50 | 0.45 – 0.85 | 60 | vat, vat number, tin, tax number, tax id, الرقم الضريبي, رقم ضريبة القيمة المضافة, zatca, هيئة الزكاة | ||
SE_ORGANISATIONSNUMMER |
SeOrganisationsnummerRecognizer |
sv | 2 | 0.20 – 0.60 | 0.55 – 0.95 | yes | digits | 41 | organisationsnummer, orgnr, org nr, företagsnummer |
SE_PERSONNUMMER |
SePersonnummerRecognizer |
sv | 2 | 0.10 – 0.50 | 0.45 – 0.85 | yes | digits | 49 | personnummer, svenskt personnummer, svensk id, ssn, personal identity number, samordningsnummer |
SG_NRIC_FIN |
SgFinRecognizer |
en | 2 | 0.30 – 0.50 | 0.65 – 0.85 | 34 | fin, fin#, nric, nric# | ||
SG_UEN |
SgUenRecognizer |
en | 1 | 0.30 | 0.65 | yes | 39 | uen, unique entity number, business registration, ACRA | |
TH_TNIN |
ThTninRecognizer |
th | 1 | 0.50 | 0.85 | yes | digits | 52 | Thai National ID, Thai ID Number, TNIN, เลขประจำตัวประชาชน, เลขบัตรประชาชน, รหัสปชช |
TR_LICENSE_PLATE |
TrLicensePlateRecognizer |
tr | 2 | 0.30 | 0.65 | yes | 35 | plaka, araç plakası, plaka numarası, kayıt plakası, tr plaka, license plate, number plate, plate, taşıt plakası, kayıt | |
TR_NATIONAL_ID |
TrNationalIdRecognizer |
tr | 1 | 0.30 | 0.65 | yes | digits | 44 | tc kimlik, kimlik no, kimlik numarası, tckn, tc no, nüfus cüzdanı, national id, turkish id, türk kimlik |
UK_DRIVING_LICENCE |
UkDrivingLicenceRecognizer |
en | 1 | 0.50 | 0.85 | yes | 62 | driving licence, driving license, driver’s licence, driver’s license, dvla, dl number, licence number, license number | |
UK_NHS |
NhsRecognizer |
en | 1 | 0.50 | 0.85 | yes | digits | 42 | national health service, nhs, health services authority, health authority |
UK_NINO |
UkNinoRecognizer |
en | 1 | 0.50 | 0.85 | 36 | national insurance, ni number, nino | ||
UK_PASSPORT |
UkPassportRecognizer |
en | 1 | 0.10 | 0.45 | 34 | passport, passport number, travel document, uk passport, british passport, her majesty, his majesty, hm passport, hmpo | ||
UK_POSTCODE |
UkPostcodeRecognizer |
en | 1 | 0.10 | 0.45 | 23 | postcode, post code, postal code, zip, address, delivery, mailing, shipping, correspondence | ||
UK_VEHICLE_REGISTRATION |
UkVehicleRegistrationRecognizer |
en | 3 | 0.15 – 0.30 | 0.50 – 0.65 | yes | 26 | vehicle, registration, number plate, licence plate, license plate, reg, vrn, dvla, v5c, logbook, mot, car, insured vehicle | |
URL |
UrlRecognizer |
en | 4 | 0.50 – 0.60 | 0.85 – 0.95 | 1118† | url, website, link | ||
US_BANK_NUMBER |
UsBankRecognizer |
en | 1 | 0.05 | 0.40 | digits | 68 | check, account, account#, acct, bank, save, debit | |
US_DRIVER_LICENSE |
UsLicenseRecognizer |
en | 2 | 0.01 – 0.30 | 0.40 – 0.65 | 75 | driver, license, permit, lic, identification, dls, cdls, lic#, driving | ||
US_ITIN |
UsItinRecognizer |
en | 3 | 0.05 – 0.50 | 0.40 – 0.85 | digits | 38 | individual, taxpayer, itin, tax, payer, taxid, tin | |
US_MBI |
UsMbiRecognizer |
en | 2 | 0.30 – 0.50 | 0.65 – 0.85 | 42 | medicare, mbi, beneficiary, cms, medicaid, hic, hicn | ||
US_NPI |
UsNpiRecognizer |
en | 2 | 0.10 – 0.40 | 0.45 – 0.75 | yes | digits | 42 | npi, national provider, provider, npi number, provider id, provider identifier, taxonomy |
US_PASSPORT |
UsPassportRecognizer |
en | 2 | 0.05 – 0.10 | 0.40 – 0.45 | 36 | us, united, states, passport, passport#, travel, document | ||
US_SSN |
UsSsnRecognizer |
en | 5 | 0.05 – 0.50 | 0.40 – 0.85 | yes | digits | 38 | social, security, ssn, ssns, ssid |
ZA_ID_NUMBER |
ZaIdNumberRecognizer |
en | 1 | 0.20 | 0.55 | yes | digits | 52 | id, identity, identity number, id number, south african id, rsa id, smart id, national id |
Scores
Section titled “Scores”A score is the recognizer author’s confidence, not a calibrated probability. For the rows extracted from Presidio it is Presidio’s own number, kept verbatim; a pistra row picks its own on the same scale. Three things move it between the pattern matching and a rule reading it:
| score becomes | |
|---|---|
| a context word within 5 words before the match | min(1.0, max(score + 0.35, 0.40)) |
| a checksum validator says valid | 1.0 |
| a checksum validator says invalid | dropped, no annotation at all |
| a second detector found the same span and type | + agreement_boost, off unless configured |
The validator is tri-state, as it is upstream. A recognizer whose Checksum column says yes can still abstain on a span it does not recognise the shape of, and then the pattern’s own score stands. So the column is a claim about the recognizer, not a guarantee about every match.
Nothing is dropped by default
Section titled “Nothing is dropped by default”guardrails.score_threshold defaults to 0, matching Presidio’s default_score_threshold, so every annotation above reaches policy however weak. That is deliberate. A threshold is a silent subtraction, and which findings a deployment can afford to lose is not a question a detector can answer. It does mean that a rule that asks only what was found will fire on the weakest patterns here:
IT_IDENTITY_CARD ItIdentityCardRecognizer 0.01IT_PASSPORT ItPassportRecognizer 0.01DE_PLZ DePlzRecognizer 0.05ES_PASSPORT EsPassportRecognizer 0.05US_BANK_NUMBER UsBankRecognizer 0.05AE_PASSPORT AePassportRecognizer 0.10Those exist to be lifted by the words around them, and they are scored where they are for that reason. On their own they are close to “a run of digits of about the right length”.
Ask for corroboration, not a number
Section titled “Ask for corroboration, not a number”The rule that wants findings worth acting on is this one:
annotations.exists(a, a.category == "pii" && (a.validated || a.context_supported))validated is the checksum; context_supported is the enhancer. Together they are what a threshold of 0.40 approximates, and they say it directly, so the rule keeps meaning what it meant if a row’s score is retuned upstream. Reach for a.score when you want to rank findings or tune against your own traffic; reach for these two when you want to act on them. See the policy reference for the annotation vocabulary.
Added by pistra
Section titled “Added by pistra”Presidio has no recognizer for these, so they are pistra’s own, written in guardrails/pii/native/*.yaml in the shape of a custom recognizer, built into the tables by the same generator, covered by the same prefilters, and on by default like every other row.
Evidence is the part worth reading. A national identifier is a run of digits that only a checksum tells from a phone number, and no issuer publishes its algorithm, so the check each row declares is the one the published validators agree on. Where a row declares none it says why, a wrong validator being worse than no validator. Each row is held at test time to the examples beside its declaration, synthetic values that satisfy the scheme and belong to nobody. That is proof of consistency, not of truth; Find Gulf identifiers says how to hold one to an identifier that is real.
| Entity | Recognizer | Evidence |
|---|---|---|
AE_EMIRATES_ID |
AeEmiratesIdRecognizer |
Pattern only, on purpose. A Luhn over all fifteen digits is widely used and real cards are documented failing it, and a wrong validator drops the id it should have found. |
AE_PASSPORT |
AePassportRecognizer |
The shape Microsoft Purview publishes. Nine characters from the digits and C F G H J K L M N P R T V W X Y Z, not all digits; no checksum. |
AE_TRN |
AeTrnRecognizer |
A check digit is said to exist and is not published; shape and context. |
IBAN_CODE |
OmIbanRecognizer |
ISO 13616. Oman’s IBAN is mandatory since 1 July 2024 and Presidio’s IBAN map does not have it yet; goes away when it does. |
KW_CIVIL_ID |
KwCivilIdRecognizer |
Weighted sum modulo 11 (weights 2 1 6 3 7 9 10 5 8 4 2), as several independent validators have it; the issuer publishes nothing. |
QA_ID |
QaIdRecognizer |
Century, birth year, nationality code, serial. No check digit, so the score is low and the context words carry it. |
SA_NATIONAL_ID |
SaNationalIdRecognizer |
Luhn over all ten digits, as every published validator has it (SAP KBA 2384001 among them); the issuer publishes nothing. |
SA_UNIFIED_NUMBER |
SaUnifiedNumberRecognizer |
No checksum is published; the score is low and the context words carry it. |
SA_VAT_NUMBER |
SaVatRecognizer |
Shape only. 3, nine digits, 00003 for the VAT account; the looser fifteen-digit shape scores 0.1. |
Phone numbers
Section titled “Phone numbers”PhoneRecognizer is the one recognizer above that is not a pattern. Presidio hands the text to python-phonenumbers, Google’s libphonenumber, at leniency VALID and reports what it finds at 0.4. The detector does the same through the Go port of that library, with its numbering metadata from libphonenumber v9.0.37, so the answer is the library’s rather than a pattern’s approximation of it. phone_regions on the detector lists the regions whose national formats are read (default US GB DE FR IL IN CA BR SA AE QA KW BH OM, Presidio’s eight and the six Gulf states); a number written with its country code is found whatever the list says. Each region is a library call per run of digits long enough to be one of its numbers, so the list is also a cost on text dense with long numbers, and none on prose. A year or a time is shorter than any region’s shortest number and is never shown to the library. A number is reported only within the shape the table’s span is measured from, which is up to sixteen digits with the common separators, so an extension is left off the match rather than the match dropped, and a number in an exotic separator is not found.
Language
Section titled “Language”The language tag is Presidio’s. Its analyzer runs only the recognizers registered for the language of the request. The pii detector has no request language and runs every active recognizer over every segment, so a German registration plate is found in an English prompt. Narrow with entities: or recognizers: on the detector. Those are also the lever over the streaming horizon.
Digits
Section titled “Digits”Every script’s decimal digits are digits. The engine folds each of them onto its ASCII value before any pattern runs (Arabic-Indic ٠–٩, Devanagari ०–९, fullwidth 0–9, every set Unicode files under category Nd), so an identifier typed from an Arabic keyboard is found by the same recognizer, validated by the same checksum, and reported at its own offsets in the text as sent. This is wider than Presidio, whose \d is unicode and whose [0-9] is not, by accident of authoring; here every pattern sees every digit, custom recognizers included.
What the pattern tier does not cover
Section titled “What the pattern tier does not cover”Everything above is a structured identifier: a format, sometimes with a checksum. Names, places, organisations, nationalities and dates have no format, and come from the nlp detector (a token-classification model in this process) or the remote detector (a presidio-analyzer with its own NLP engine). Their labels are renamed into the entity vocabulary by entity_map, whose default is:
| Model label | Entity |
|---|---|
GPE |
LOCATION |
LOC |
LOCATION |
MISC |
MISC |
ORG |
ORGANIZATION |
PER |
PERSON |
PERS |
PERSON |
A label the map does not name keeps its own.
Your deployment’s vocabulary
Section titled “Your deployment’s vocabulary”This page is the floor. A running node’s own list (these types, narrowed by each detector’s selection, plus custom recognizers, a model’s labels and a remote analyzer’s filter) is served live as GET /admin/v1/guardrails/entity-types, with the detector that produces each type. fpe_alphabets and an MCP server’s restore: list are checked against that vocabulary at load.
Regenerate with make gen-docs; re-extract from upstream with make gen-recognizers.