Tool Open source
deident-wasm is a Rust privacy transformation engine for structured datasets. It applies declarative YAML policies to CSV, JSONL/NDJSON, Parquet, and DICOM data, supporting reversible pseudonymization and risk-assessed anonymization. Policies classify columns as direct identifiers, quasi-identifiers, sensitive data, or utility fields and can tokenize, remove, redact, bucket, truncate dates, or retain prefixes. The engine also detects identifiers embedded in content using built-in or custom regular expressions, with options to redact, tokenize, or replace matches with structurally valid fakes.
It can process chained datasets with shared token scoping so foreign keys remain joinable after pseudonymization. Jobs may run in isolated WebAssembly sandboxes using Wasmtime and WASI, with a fresh store, one preopened directory, no network access, and memory, CPU, and time limits. An optional XChaCha20-Poly1305 mapping vault stores original-to-token mappings for authorized reversal.
The tool produces risk reports containing row counts, identifier actions, pattern findings, and equivalence-class statistics; a minimum-k requirement can act as a CI post-condition. Its anonymization mode is described as reducing and measuring re-identification risk rather than certifying anonymity, while pseudonymized output remains personal data. The repository also documents DICOM metadata de-identification with consistent UID remapping.
1 use taken from transcripts — each links to the moment in the video.
A Rust privacy engine that transforms CSV datasets according to declarative YAML policies. It supports reversible pseudonymization, risk-assessed anonymization, joinable tokens, re-identification reports, and isolated WebAssembly execution.
1 in the library.