pii-toolkit-cy
I built pii-toolkit-cy for personal-data redaction and field-level encryption in Node.js. It provides redact() and createPiiCipher(), without runtime dependencies.
The problem
I built this for two separate tasks: removing personal information from free text before it leaves a system, and encrypting identity fields at rest.
Redaction patterns can mistake order numbers or payment amounts for personal data. In field encryption, I avoid reusing IVs or substituting a fast hash for a key-derivation function.
The approach
I use conservative patterns in redact() for emails, payment cards, IBANs and phone numbers. The patterns are designed to leave bare integers, such as order IDs, unchanged.
I use AES-256-GCM in createPiiCipher(), with a fresh random IV for each value and scrypt for key derivation. Authenticated decryption checks for tampering.
I provide ESM exports and TypeScript types, with no runtime dependencies.
The result
I keep the code available on GitHub. I use redact() on free text before passing it on, and createPiiCipher() for fields that need encryption at rest. The library is not published on npm.