← Work

pii-toolkit-cy

I built pii-toolkit-cy for personal-data redaction and field-level encryption in Node.js. It provides redact() and createPiiCipher(), without runtime dependencies.

  • Node.js
  • AES-256-GCM
  • scrypt
  • Zero dependencies
  • ESM

The problem

I built this for two separate tasks: removing personal information from free text before it leaves a system, and encrypting identity fields at rest.

Redaction patterns can mistake order numbers or payment amounts for personal data. In field encryption, I avoid reusing IVs or substituting a fast hash for a key-derivation function.

The approach

I use conservative patterns in redact() for emails, payment cards, IBANs and phone numbers. The patterns are designed to leave bare integers, such as order IDs, unchanged.

I use AES-256-GCM in createPiiCipher(), with a fresh random IV for each value and scrypt for key derivation. Authenticated decryption checks for tampering.

I provide ESM exports and TypeScript types, with no runtime dependencies.

The result

I keep the code available on GitHub. I use redact() on free text before passing it on, and createPiiCipher() for fields that need encryption at rest. The library is not published on npm.