# Presidio (slim) > Open-source Python library and Docker services that detect personal data in text and images and replace, mask, hash or encrypt it. Created at Microsoft and run since June 2026 by the community organisation Data Privacy Stack. - Full: https://www.anchorterminal.com/tools/microsoft-presidio.md (~5,900 tokens) · this version ~1,480 tokens · JSON https://www.anchorterminal.com/tools/microsoft-presidio.json · canonical https://www.anchorterminal.com/tools/microsoft-presidio - Index: https://www.anchorterminal.com/llms.txt · API: https://www.anchorterminal.com/api/v1/index.json · Updated: 2026-10-08 **B · 66/100 · rank #248 of 722 · #5 in Guardrails & safety filters · not agent-ready · confidence medium** Assessment: MIT-licensed personal data detector with a public OpenAPI document, tests on Python 3.10 to 3.14 and about 1.2 million weekly PyPI downloads. The REST containers have no authentication, the project states no SLA or support, and it covers personal data only, with no prompt injection or content moderation checks. ## Facts - Kind: SDK + MCP · vendor: Data Privacy Stack · category: Guardrails & safety filters · legal entity: Data Privacy Stack (community organisation, no legal entity stated) · provenance 53/100 - Local only (HTTP): pypi `presidio-analyzer`, pypi `presidio-anonymizer`, pypi `presidio-image-redactor`, pypi `presidio` - Auth: None · pricing: Free · x402: no · licence: MIT - Probe metrics: not measured yet (probes haven't run) - Packages: `presidio-analyzer` and `presidio-anonymizer` 2.2.364, `presidio-image-redactor` 0.0.60, `presidio-structured` 0.0.8, `presidio-cli` 0.0.9, and the `presidio` meta-package - Languages: Python 3.10 to 3.14 - REST endpoints: Analyser: `/analyze`, `/recognizers`, `/supportedentities`, `/health`. Anonymiser: `/anonymize`, `/deanonymize`, `/anonymizers`, `/deanonymizers`, `/health`. Image redactor: `/redact` - Detection: Named entity recognition (spaCy, Stanza, transformers, GLiNER), regular expressions, checksums, context words, allow lists and ad hoc recognisers - Anonymiser operators: replace, redact, mask, hash, encrypt, keep, custom, and decrypt for reversal - Images: OCR with Tesseract or Azure Document Intelligence, for standard image types and DICOM medical images - Container images: `ghcr.io/data-privacy-stack/presidio-analyzer`, `presidio-anonymizer` and `presidio-image-redactor` - Authentication: None built in. Deploy behind your own gateway or proxy - Telemetry: None found in the source (searched 2026-10-08). The docs make no statement - Releases in 90 days: 1 (2.2.364 on 2026-07-22) - Scores: Reliability 78, Performance pending, Schema & documentation 69, Agent ergonomics 69, Security & auth 53, Payments & pricing 60, Task success pending, Maintenance & community 63, Transparency & trust 65 · total over the 7 assessed categories - Why: Reliability, Local-software reading. · Schema & documentation, API reading for the REST services. · Agent ergonomics, `/analyze` takes an entity list, a score threshold and an allow list, and leaves the decision trace off unless return_decision_process is se… · Security & auth, Local-software reading. · Payments & pricing, MIT-licensed package the owner runs, with no hosted or paid option from the project, read with the self-hosted rule. · Maintenance & community, 2.2.364 was released on 22 July 2026, 78 days before the check (20). · Transparency & trust, MIT licence, with the copyright line changed from Microsoft Corporation to Presidio Contributors in July 2026 (30). - Sources: 12, open questions: 6, both in the full twin - Capabilities: guard.pii, guard.self-host - JSON: https://www.anchorterminal.com/api/v1/tools/microsoft-presidio.json - Verify (for the vendor): the badge `https://www.anchorterminal.com/badges/microsoft-presidio.svg` or a link to https://www.anchorterminal.com/tools/microsoft-presidio from a page on dataprivacystack.org or one of its subdomains, or the README of github.com/data-privacy-stack/presidio, then `POST https://www.anchorterminal.com/api/v1/verify` `{"slug", "url"}` or `verify_listing` at /mcp; re-checked weekly, no effect on the grade. Snippets in the full twin. ## Before you call it 1. Install from PyPI or pull images from ghcr.io/data-privacy-stack. The mcr.microsoft.com/presidio-* images are no longer updated 2. Download a spaCy model (python -m spacy download en_core_web_lg) before the first `AnalyzerEngine()` call, or use the Docker image 3. Send both text and language to `/analyze`. A request missing either returns HTTP 500 with a JSON error field 4. Pass entities and score_threshold to limit results. Many country-specific recognisers are disabled by default and need enabling in the registry YAML 5. Keep the containers on a private network or behind your own authenticating proxy. They accept any caller ## Connect ```bash pip install presidio-analyzer presidio-anonymizer python -m spacy download en_core_web_lg ``` ```bash docker run -d -p 5002:3000 ghcr.io/data-privacy-stack/presidio-analyzer:latest curl -X POST http://localhost:5002/analyze \ -H "Content-Type: application/json" \ -d '{"text": "My phone number is 555-123-4567.", "language": "en"}' ``` Full config and headless snippets are in the full page. Through letme (picks today, calling later): https://letme.dev/microsoft-presidio ## Similar tools | Tool | Grade | Score | Shared capabilities | Slim | | --- | --- | --- | --- | --- | | NVIDIA NeMo Guardrails | B | 68.4 | guard.pii, guard.self-host | https://www.anchorterminal.com/tools/nemo-guardrails.min.md | | Vela 2.0 | B | 66.5 | guard.pii, guard.self-host | https://www.anchorterminal.com/tools/vela.min.md | | Lakera Guard (Check Point AI Guardrails) | C | 59.6 | guard.pii, guard.self-host | https://www.anchorterminal.com/tools/lakera-guard.min.md | | Guardrails AI | D | 49.6 | guard.pii, guard.self-host | https://www.anchorterminal.com/tools/guardrails-ai.min.md | | Google Cloud Model Armor | BB | 77.9 | guard.pii | https://www.anchorterminal.com/tools/google-model-armor.min.md | ## Panel reviews (0, desk reviews from public material, no calls made)