# Presidio > Open-source Python library and Docker services that detect personal data in text and images and replace, mask, hash or encrypt it. Created at Microsoft and run since June 2026 by the community organisation Data Privacy Stack. - Canonical: https://www.anchorterminal.com/tools/microsoft-presidio - Markdown: https://www.anchorterminal.com/tools/microsoft-presidio.md (~5,900 tokens) - Slim: https://www.anchorterminal.com/tools/microsoft-presidio.min.md (~1,480 tokens, same facts, less prose, for token-sensitive contexts) - JSON: https://www.anchorterminal.com/tools/microsoft-presidio.json (this page as data, same URL with Accept: application/json) - Site index for agents: https://www.anchorterminal.com/llms.txt (full text: https://www.anchorterminal.com/llms-full.txt) - API: https://www.anchorterminal.com/api/v1/index.json - Updated: 2026-10-08 ## Overview **Grade B · 66/100 · rank #248 of 722 · #5 in Guardrails & safety filters · not agent-ready · confidence medium** ## Assessment MIT-licensed personal data detector with a public OpenAPI document, tests on Python 3.10 to 3.14 and about 1.2 million weekly PyPI downloads. The REST containers have no authentication, the project states no SLA or support, and it covers personal data only, with no prompt injection or content moderation checks. ## Facts | Field | Value | | --- | --- | | Vendor | Data Privacy Stack (https://dataprivacystack.org) | | Kind | SDK + MCP | | Category | Guardrails & safety filters (https://www.anchorterminal.com/categories/guardrails) | | Transport | HTTP | | Auth | None · None. The Python library runs in the caller's process, and the REST containers accept any caller. The FAQ states the endpoints have no built-in authentication by design and should sit behind a gateway, reverse proxy or service mesh (https://presidio.dataprivacystack.org/faq/). Optional recognisers that call Azure AI Language, Azure Health Data Services or a language model take those services' own credentials. | | Pricing | Free (Free · OSS) · Free under the MIT licence, with no hosted or paid option from the project and no account needed. The cost is the compute to run it, plus any outside service an optional recogniser is configured to call (https://github.com/data-privacy-stack/presidio/blob/main/LICENSE). | | x402 | No · No x402, MPP or L402 in the docs or the source (checked 2026-10-08). | | Licence | MIT | | Packages | pypi: `presidio-analyzer`; pypi: `presidio-anonymizer`; pypi: `presidio-image-redactor`; pypi: `presidio` | | Source | https://github.com/data-privacy-stack/presidio | | Docs | https://presidio.dataprivacystack.org | | llms.txt | not found | | Last release | 2026-07-22 | | GitHub stars | 11,231 (as of 2026-10-08) | | PyPI downloads / week | 1,217,281 | | Packages | `presidio-analyzer` and `presidio-anonymizer` 2.2.364, `presidio-image-redactor` 0.0.60, `presidio-structured` 0.0.8, `presidio-cli` 0.0.9, and the `presidio` meta-package | | Languages | Python 3.10 to 3.14 | | REST endpoints | Analyser: `/analyze`, `/recognizers`, `/supportedentities`, `/health`. Anonymiser: `/anonymize`, `/deanonymize`, `/anonymizers`, `/deanonymizers`, `/health`. Image redactor: `/redact` | | Detection | Named entity recognition (spaCy, Stanza, transformers, GLiNER), regular expressions, checksums, context words, allow lists and ad hoc recognisers | | Anonymiser operators | replace, redact, mask, hash, encrypt, keep, custom, and decrypt for reversal | | Images | OCR with Tesseract or Azure Document Intelligence, for standard image types and DICOM medical images | | Container images | `ghcr.io/data-privacy-stack/presidio-analyzer`, `presidio-anonymizer` and `presidio-image-redactor` | | Authentication | None built in. Deploy behind your own gateway or proxy | | Telemetry | None found in the source (searched 2026-10-08). The docs make no statement | | Releases in 90 days | 1 (2.2.364 on 2026-07-22) | | Capabilities | guard.pii, guard.self-host | | Tags | sdk, open-source, self-hosted, local, python, free, docker, openapi, pii, community-governed | | JSON | https://www.anchorterminal.com/api/v1/tools/microsoft-presidio.json | ## Score breakdown (methodology v0.4, October 2026 research run) Assessed 2026-10-08 from public evidence against the published checklist (https://www.anchorterminal.com/benchmark/#checklist). Confidence: medium. Performance and Task success pending (no score, not in the total); the total is Σ(score × weight) ÷ 80 over the 7 assessed categories. "This run" is each category's share of the 100 points. | Category | Weight | This run | Score (0–100) | Points | | --- | --- | --- | --- | --- | | Reliability | 16% | 20 | 78 | 15.6 | | Performance | 10% | pending | pending | n/a | | Schema & documentation | 13% | 16.2 | 69 | 11.2 | | Agent ergonomics | 13% | 16.2 | 69 | 11.2 | | Security & auth | 14% | 17.5 | 53 | 9.3 | | Payments & pricing | 10% | 12.5 | 60 | 7.5 | | Task success | 10% | pending | pending | n/a | | Maintenance & community | 7% | 8.8 | 63 | 5.5 | | Transparency & trust (editorial 76, provenance 53) | 7% | 8.8 | 65 | 5.7 | | Negative events | up to −15 | up to −15 | none recorded | 0 | | **Total** | | | | **66 → B** | ### Why each score - Reliability 78: Local-software reading. Installs from PyPI as `presidio-analyzer` and `presidio-anonymizer`, with Python 3.10 to 3.14 stated in the install docs and package metadata (20). Public CI on GitHub Actions tests each package on five Python versions. Six of the last eight runs on main passed, one was cancelled and the run of 8 October 2026 failed (20 of 25). 68 open issues, two of them labelled bug, and 98 open pull requests. Most issues opened since 20 September have no reply (15 of 25). Versions count up as 2.2.x for every release, feature releases included, and CHANGELOG.md has no section for 2.2.364, whose changes sit under unreleased (8 of 15). Version 2.2.364, past 1.0, though the image redactor package is 0.0.60 (15). - Performance: Pending. Latency is measured per call by our probes, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until the first probe window closes. - Schema & documentation 69: API reading for the REST services. An OpenAPI 3.0 document covers eight paths of the analyser and anonymiser. The image redactor's /redact is not in it (22 of 25). presidio.dataprivacystack.org/llms.txt returns 404 (0). Operations carry a one-line summary and description, and the docs explain each module, without guidance on when not to use a call (14 of 20). Request schemas are typed, with one enum in the document, and anonymiser operator parameters are objects keyed by entity type (10 of 15). Request and response examples are given, with 400 and 422 shapes for the anonymiser. The analyser's 500 on missing text is not in the document (11 of 15). Tagged releases and a public changelog, though 2.2.364 has no changelog section and the document's own version reads 2.0 (12 of 15). - Agent ergonomics 69: `/analyze` takes an entity list, a score threshold and an allow list, and leaves the decision trace off unless return_decision_process is set, so responses can be kept small (20 of 25). Text can be a string or an array for batches. There is no pagination, and none is needed for span lists (14 of 20). Errors are JSON with an error field and a 400, 422 or 500 status, but the analyser answers 500 for a missing text or language, and open issue 2256 reports that an unsupported entity is dropped without an error (10 of 20). Calls are stateless and safe to retry. Results from model-based recognisers depend on the loaded model (16 of 20). Two required fields and working defaults, with a Python library only (9 of 15). - Security & auth 53: Local-software reading. The REST services have no authentication, and the FAQ says this is by design and that a gateway, proxy or service mesh should sit in front (10 of 30). The analyser only reads text and returns spans. The anonymiser returns a transformed copy and deletes nothing. There are no roles or approval steps (12 of 20). It returns positions, types and scores for the caller's own text, not content from third parties (10). Requests accept a correlation_id that is written to the service log, and return_decision_process explains each match. No audit log beyond that (9 of 15). SECURITY.md routes reports to GitHub private vulnerability reporting with acknowledgement in 48 hours, CodeQL runs in CI and workflow actions are pinned to commit hashes. No published advisories, no bug bounty and no security.txt (12 of 20). - Payments & pricing 60: MIT-licensed package the owner runs, with no hosted or paid option from the project, read with the self-hosted rule. 20 for pricing, 20 for a free start and 20 for use without an account or key. No x402, MPP or L402 in the docs or source (0). - Task success: Pending. Task success needs the category task suites run through each tool, which haven't run yet, so this run doesn't score it. Its weight is shared across the assessed categories until then. A data provider's data-quality score is published on its listing now and becomes half of this category when it's scored. - Maintenance & community 63: 2.2.364 was released on 22 July 2026, 78 days before the check (20). It is the only release in the last 90 days, with 2.2.363 on 28 June just outside (5 of 20, a quarter of the line where earlier dossiers gave half for two). 30 issues were opened since 1 August and 11 are closed, main had 14 commits in the 30 days to 8 October, and 98 pull requests are open (15 of 25). Current packages on PyPI for the analyser, anonymiser, image redactor, structured module and CLI (15). Dependabot, committed uv lockfiles and CI on five Python versions, with the latest run on main failing (8 of 10). - Transparency & trust 65: MIT licence, with the copyright line changed from Microsoft Corporation to Presidio Contributors in July 2026 (30). The software runs on the owner's machines and there is no hosted service, so there is no privacy policy or retention statement to read. The docs say which optional recognisers call outside services (Azure AI Language, Azure Health Data Services, LangExtract with a hosted or Ollama model) (20 of 30). Deprecations appear in the changelog and as banners on old config files, and the move of images from Microsoft's registry to GHCR is announced, but no dates are given and the `kr` alias removal is marked release TBD (10 of 20). We found no telemetry code in the repository and no statement on telemetry in the docs (16 of 20). Fix list for a coding agent, everything this grade says the listing lacks, the biggest gain first (16 items): https://www.anchorterminal.com/fixes/microsoft-presidio.md (JSON https://www.anchorterminal.com/fixes/microsoft-presidio.json) ### What we couldn't check - The lead named Microsoft as vendor. Presidio left Microsoft for the community organisation Data Privacy Stack (announced 29 June 2026). github.com/microsoft/presidio and microsoft.github.io/presidio redirect to the new addresses. The slug keeps the old name. - No legal entity is named for Data Privacy Stack on its site, the docs or the licence. - No privacy policy is published, so provenance.privacy is left out. The MIT licence stands in for terms. - Whether the project runs no telemetry is inferred from a search of the source. The docs make no statement. - unchecked: the governance documents in the data-privacy-stack/MVG repository were not read. - unchecked: issue reply times were read from comment counts in the GitHub search API, not from each thread. ### Sources - repository at commit 2523c7b (README, LICENSE, SECURITY.md, SUPPORT.md, CI workflows, source): (seen 2026-10-08) - changelog: (seen 2026-10-08) - project transition notice: (seen 2026-10-08) - transition blog post, 29 June 2026: (seen 2026-10-08) - OpenAPI document: (seen 2026-10-08) - installation docs (Python versions, GHCR images): (seen 2026-10-08) - FAQ (ownership, no built-in authentication): (seen 2026-10-08) - PyPI release history for the analyser package: (seen 2026-10-08) - PyPI download counts: (seen 2026-10-08) - GitHub API: stars, releases, issues, CI runs, advisories: (seen 2026-10-08) - old address redirects to the new organisation: (seen 2026-10-08) - domain registration: (seen 2026-10-08) ## Who's behind it (provenance 53/100, checked 2026-10-08) | Check | Finding | Points | | --- | --- | --- | | Legal entity named | Data Privacy Stack (community organisation, no legal entity stated) | 20/20 | | Domain age | dataprivacystack.org, registered 2026-04-13 (under a year) | 0/15 | | Endpoint on the vendor's domain | no hosted endpoint | n/a | | Terms of service | nothing hosted, so the MIT licence stands in | 10/10 | | Privacy policy | nothing hosted, not scored | n/a | | Status page | not found | 0/10 | | Changelog | published | 10/10 | | security.txt | not found | 0/10 | A library and self-hosted containers, not a service. Code is on github.com under the data-privacy-stack organisation and docs on presidio.dataprivacystack.org. Presidio was created at Microsoft. The transition notice says it is now a community-governed project under Data Privacy Stack and is not owned or operated by a commercial entity. The blog post announcing the move is dated 29 June 2026. github.com/microsoft/presidio answers 301 to github.com/data-privacy-stack/presidio, and microsoft.github.io/presidio shows a moved notice. The LICENSE copyright line reads Presidio Contributors. The FAQ says usage terms are the repository's licence and that there is no warranty or SLA. No privacy policy was found on dataprivacystack.org or the docs site. Nothing is hosted, so the field is left out. security.txt returns 404 on dataprivacystack.org and presidio.dataprivacystack.org. SECURITY.md uses GitHub private vulnerability reporting. RDAP gives 2026-04-13 as the registration date of dataprivacystack.org. The repository was created on 4 May 2018. ### Terms and privacy, as read A reading by a fixed set of rules, each answered with the vendor's own sentence. Not legal advice. **Terms of service**. Nothing is hosted by the vendor, so there are no terms of service to read. The MIT licence stands in and the check scores in full. **Privacy policy**. Nothing is hosted by the vendor, so there is no privacy policy to read and the check isn't scored. ## Live (updated 2026-10-08 18:24 UTC) - Watching changelog - Always current: https://www.anchorterminal.com/api/v1/live/microsoft-presidio.json ## Probe metrics Not measured yet. Our benchmark probes haven't run, so there's no availability, latency or error rate from a run and Performance is pending. Live uptime, where we poll the endpoint, is under Live and doesn't change the score. ## Strengths - MIT licence, source on GitHub, and nothing to buy. No account, key or card is needed to install or run it - OpenAPI 3.0 document for the analyser and anonymiser REST services, with request examples and 400 and 422 error shapes - CI runs each package on Python 3.10, 3.11, 3.12, 3.13 and 3.14, with CodeQL and Dependabot configured - Detection is tunable per call with an entity list, a score threshold, an allow list and ad hoc recognisers - Anonymiser operators cover replace, redact, mask, hash, encrypt and custom functions, and encrypted values can be reversed with the key ## Weaknesses - The REST containers have no authentication by design. The FAQ says to put a gateway or proxy in front - SUPPORT.md states no SLA and no official support. The project is run by volunteers since leaving Microsoft - One release in the 90 days to 8 October 2026 (2.2.364 on 22 July), and CHANGELOG.md has no section for it - Covers personal data only. No prompt injection, jailbreak or content moderation checks - The README warns that detection is automated and may miss personal data, so other protections are still needed - 98 open pull requests, and most issues opened since 20 September 2026 had no reply on 8 October ## Before you call it (notes for agents) 1. Install from PyPI or pull images from ghcr.io/data-privacy-stack. The mcr.microsoft.com/presidio-* images are no longer updated 2. Download a spaCy model (python -m spacy download en_core_web_lg) before the first `AnalyzerEngine()` call, or use the Docker image 3. Send both text and language to `/analyze`. A request missing either returns HTTP 500 with a JSON error field 4. Pass entities and score_threshold to limit results. Many country-specific recognisers are disabled by default and need enabling in the registry YAML 5. Keep the containers on a private network or behind your own authenticating proxy. They accept any caller ## Connect Install: ```bash pip install presidio-analyzer presidio-anonymizer python -m spacy download en_core_web_lg ``` First request: ```bash docker run -d -p 5002:3000 ghcr.io/data-privacy-stack/presidio-analyzer:latest curl -X POST http://localhost:5002/analyze \ -H "Content-Type: application/json" \ -d '{"text": "My phone number is 555-123-4567.", "language": "en"}' ``` Through letme (picks today, calling later): https://letme.dev/microsoft-presidio. letme answers with the pick and how to call it direct; calling through letme (one key, the vendor's own price) comes later. How it works: https://www.anchorterminal.com/letme/index.md ## Similar tools Ranked by shared capabilities, then score. Same-category tools with no shared capability key are listed last. | Tool | Grade | Score | Rank | Shared capabilities | x402 | Markdown | | --- | --- | --- | --- | --- | --- | --- | | NVIDIA NeMo Guardrails | B | 68.4 | 179 | guard.pii, guard.self-host | no | https://www.anchorterminal.com/tools/nemo-guardrails.md | | Vela 2.0 | B | 66.5 | 237 | guard.pii, guard.self-host | no | https://www.anchorterminal.com/tools/vela.md | | Lakera Guard (Check Point AI Guardrails) | C | 59.6 | 424 | guard.pii, guard.self-host | no | https://www.anchorterminal.com/tools/lakera-guard.md | | Guardrails AI | D | 49.6 | 604 | guard.pii, guard.self-host | no | https://www.anchorterminal.com/tools/guardrails-ai.md | | Google Cloud Model Armor | BB | 77.9 | 15 | guard.pii | no | https://www.anchorterminal.com/tools/google-model-armor.md | | Amazon Bedrock Guardrails | BB | 74.8 | 56 | guard.pii | no | https://www.anchorterminal.com/tools/amazon-bedrock-guardrails.md | ## Panel reviews (0) Reviewed by the Anchor panel (https://www.anchorterminal.com/reviewers/index.md): . Desk reviews, written from public documentation, pricing, terms, source and status history on 1 October 2026. No calls made. For a desk review, the outcome says whether the reviewer's questions could be answered from public material: success, partial or failure. How reviews work: https://www.anchorterminal.com/reviews/how-it-works.md ## Notable - Presidio moved from Microsoft to Data Privacy Stack, a community organisation with a Technical Steering Committee. The announcement is dated 29 June 2026, and the old GitHub and docs addresses redirect (source: ) - Container images are published to ghcr.io/data-privacy-stack. The mcr.microsoft.com/presidio-* images stay available for older tags and are no longer updated (source: ) - Release 2.2.364 on 22 July 2026 and 2.2.363 on 28 June 2026. `presidio-analyzer` had 1,217,281 PyPI downloads in the week to 8 October 2026 (source: ) - The analyser combines named entity recognition (spaCy by default, or Stanza, transformers and GLiNER), regular expressions, checksums and context words. The source tree holds more than 90 predefined recogniser modules, many country-specific and disabled by default (source: ) - The README warns that detection is automated and there is no guarantee that all sensitive information is found (source: ) - SUPPORT.md states the project has no SLA or official support (source: ) ## Compare - [Amazon Bedrock Guardrails vs Presidio](https://www.anchorterminal.com/compare/amazon-bedrock-guardrails-vs-microsoft-presidio.md): BB 74.8 vs B 66 - [Google Cloud Model Armor vs Presidio](https://www.anchorterminal.com/compare/google-model-armor-vs-microsoft-presidio.md): BB 77.9 vs B 66 - [Guardrails AI vs Presidio](https://www.anchorterminal.com/compare/guardrails-ai-vs-microsoft-presidio.md): D 49.6 vs B 66 - [Lakera Guard (Check Point AI Guardrails) vs Presidio](https://www.anchorterminal.com/compare/lakera-guard-vs-microsoft-presidio.md): C 59.6 vs B 66 - [Presidio vs Mistral Moderation API](https://www.anchorterminal.com/compare/microsoft-presidio-vs-mistral-moderation.md): B 66 vs C 58.4 - [Presidio vs NVIDIA NeMo Guardrails](https://www.anchorterminal.com/compare/microsoft-presidio-vs-nemo-guardrails.md): B 66 vs B 68.4 - [Llama Guard 4 vs Presidio](https://www.anchorterminal.com/compare/llama-guard-vs-microsoft-presidio.md): D 49.1 vs B 66 ## Verify this listing For the vendor. The badge or a plain link to this page verifies the listing, from a page on dataprivacystack.org or one of its subdomains, or the README of github.com/data-privacy-stack/presidio. It shows the listing is the vendor's and that the vendor knows it's here, and it never changes a grade, rank or review. The vendor sends the page's address to `POST https://www.anchorterminal.com/api/v1/verify` as `{"slug": "microsoft-presidio", "url": "…"}`, or calls the `verify_listing` tool at https://www.anchorterminal.com/mcp. We fetch the page once, then again every week; two failed checks in a row and the verification lapses, and a later pass restores it. What we check: https://www.anchorterminal.com/builders/index.md#verify HTML badge: ```html Presidio on Anchor Terminal ``` Markdown badge, for a README: ```markdown [![Presidio on Anchor Terminal](https://www.anchorterminal.com/badges/microsoft-presidio.svg)](https://www.anchorterminal.com/tools/microsoft-presidio) ``` Plain link: ```html Presidio on Anchor Terminal ``` ## Share this listing For the vendor. Sharing assets for social media, two PNGs of 1200 × 630 that say Presidio is listed on Anchor Terminal, with the vendor's logo and this page's address and no grade or score. - Dark: https://www.anchorterminal.com/assets/share/microsoft-presidio-dark.png - Light: https://www.anchorterminal.com/assets/share/microsoft-presidio-light.png