Open source · Security & Privacy

Access Log PII Redactor

Remove personal and sensitive values from exported access logs.

v0.1.0 · Node.js 22+ · MIT

Browse the public repository · View releases

Stream an exported access log, redact the query parameters, headers, addresses and identifiers a policy declares, and write the redacted records somewhere else. Every record this tool cannot vouch for is quarantined: withheld from the output, located by line number and shape, and never echoed into a message.

This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.

Run the checked-in example

npm install --global access-log-pii-redactor

Read the result

Or run it from a checkout with node bin/access-log-pii-redactor.mjs.

Where this check stops

This tool cannot tell you a log is free of personal data. It removes what the policy names and what the enabled detectors match. A pass means those rules were applied to every record and every record was written; it is not a statement about what is left.

Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.

Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.