Tool Open source

deident-wasm

deident-wasm is a Rust privacy transformation engine for structured datasets. It applies declarative YAML policies to CSV, JSONL/NDJSON, Parquet, and DICOM data, supporting reversible pseudonymization and risk-assessed anonymization. Policies classify columns as direct identifiers, quasi-identifiers, sensitive data, or utility fields and can tokenize, remove, redact, bucket, truncate dates, or retain prefixes. The engine also detects identifiers embedded in content using built-in or custom regular expressions, with options to redact, tokenize, or replace matches with structurally valid fakes.

View repository Mentioned in 1 video ↓

Overview

It can process chained datasets with shared token scoping so foreign keys remain joinable after pseudonymization. Jobs may run in isolated WebAssembly sandboxes using Wasmtime and WASI, with a fresh store, one preopened directory, no network access, and memory, CPU, and time limits. An optional XChaCha20-Poly1305 mapping vault stores original-to-token mappings for authorized reversal.

The tool produces risk reports containing row counts, identifier actions, pattern findings, and equivalence-class statistics; a minimum-k requirement can act as a CI post-condition. Its anonymization mode is described as reducing and measuring re-identification risk rather than certifying anonymity, while pseudonymized output remains personal data. The repository also documents DICOM metadata de-identification with consistent UID remapping.

What deident-wasm is used for

1 use taken from transcripts — each links to the moment in the video.

  • A Rust privacy engine that transforms CSV datasets according to declarative YAML policies. It supports reversible pseudonymization, risk-assessed anonymization, joinable tokens, re-identification reports, and isolated WebAssembly execution.

Videos mentioning deident-wasm

1 in the library.