PII redaction tester
Paste the text you are about to send a model. The page finds structured identifiers, checks the ones that carry a checksum, and hands back a redacted copy. The text never leaves your machine: there is no upload, no API key, and no network call anywhere in this page.
Matches found 0
Distinct types 0
Checksum failures 0
No matches yet.
Matches
| Match type | Match (masked) | Position | Checksum |
|---|
Redacted text
Highlighted text
Amber is a pattern match. Red is a string that looks like a card or an IBAN but failed its check digit, which is usually a test number or a near miss rather than real account data.
What the checksums actually tell you
A credit card number has a Luhn check digit, and an IBAN carries a two-digit check built from a mod-97 sum. This page runs both. When the check passes, the string is a well-formed card or account number, not a random 16 digits that a regex would happily flag. That distinction matters: a generic regex tester calls 4111111111111112 a card, and it is not one. Here it is labelled a card candidate with a failed checksum.
A passing check raises confidence; it does not prove the number is real or that anyone owns it. Test numbers like 4111 1111 1111 1111 pass Luhn because they are built to. Every other detector on the page, email, phone, SSN, IP and the rest, has no check digit at all, so those are pattern matches and carry a higher false positive rate. The page says which is which in the results table.
Why a browser tool is the right shape
Redaction is the step teams add after the first incident, once someone notices that a support transcript carried a card number into a prompt. By then the reflex is to bolt on a server-side filter, which means the very text you are worried about now travels over the network to be cleaned. A tool that runs in the tab inverts that: you check the string before it goes anywhere. For a solo builder or a small team, that is the whole point. The data you are protecting never has to survive a round trip to do it.
Pair this with a stricter prompt budget when you trim context, for example with the token budget calculator, so redaction and cost control land in the same pass over the request.
What this will not catch
This catches structured identifiers, and only those. It will miss names, street addresses, account nicknames, and anything whose meaning depends on the sentence around it. No regex fixes that. A line like "the lead on the Riverside deal" can identify a person and a project with no digit in sight, and this page will pass it through untouched.
Over-redacting is its own failure. Strip every proper noun and you hand the model a paragraph of placeholders that no longer says anything, and the answer you get back is worth less than the one you paid for. Redact the identifiers that carry legal or financial risk, keep the context the model needs, and read the highlighted output before you send it. This is a fast first pass, not a compliance guarantee, and it does not stand in for the data-handling rules your own regulator or contract puts on you.