# Sensored

> Updated 2026-09-29 · type: tool · category: ai-infrastructure · status: active · rev 1

Sensored strips PII and PHI from text in a streaming pass before it reaches an LLM, using local regex and NER with an optional external AI-confirmation step.

- Open source: yes (MIT)
- Self-hostable: yes
- Pricing model: free
- Best for: A builder who wants to redact PII/PHI from text on the way into an LLM, streaming-first, with the detection core (regex + NER) running locally so sensitive data can be sanitized without leaving the machine.
- Not for: A team needing a certified, audited compliance-grade redaction guarantee, or one that cannot accept the optional AI-confirmation step's fail-open behavior when the external API is unavailable.
- Last verified: 2026-09-29

- **Canonical:** https://gtmstacker.com/registry/tool/sensored/
- **Source:** [atomicpages · GitHub](https://github.com/atomicpages/sensored)
- **Tags:** ai-infrastructure, pii-redaction, phi, privacy, streaming, self-hostable
- **Repository:** https://github.com/atomicpages/sensored

## Is Sensored open source?

Yes, Sensored is open source under the MIT license.

## How much does Sensored cost?

Sensored is free to use.

## Can I self-host Sensored?

Yes, Sensored can be self-hosted (the source is available under the MIT license).


---

Sensored is a streaming-first PII/PHI redactor that sanitizes text before it reaches an LLM. Open source: yes (MIT); self-hostable for the core, where the regex and NER detection run locally, with an optional AI-confirmation step that calls an external API and fails open. It is free, has ~1 star, and is maintained by atomicpages.

## What it does

Sensored sits between your data and a language model and strips personally identifiable information and protected health information out of the text on the way in. It is streaming-first, so it can redact as tokens flow rather than buffering whole documents. The detection core is two local layers — regular-expression matching for structured identifiers plus named-entity recognition for names, places, and the like — and both run on your own machine. There is also an optional third layer: an AI-confirmation step that calls an external API to double-check candidate spans. That step is off the local-only path, and it fails open — if it cannot run, content is not blocked. Open source: yes (MIT); self-hostable core; free.

## Provenance

- MIT per repo; ~1 star (very early project).
- Streaming-first PII/PHI redaction that sanitizes text before it reaches an LLM.
- Self-hostable core: regex + NER run locally.
- Optional AI-confirmation step calls an EXTERNAL API and FAILS OPEN (atomicpages/sensored, verified 2026-09-29).
- Surfaced via the GTM Stacker studio daily pull (2026-09-29 pass); license/facts verified against the primary repo 2026-09-29.

## Why it matters for a GTM stack

GTM pipelines routinely pipe prospect and customer text — emails, call notes, support threads — into LLMs, and that text is full of PII (and sometimes PHI). Redacting it before it reaches the model is exactly the right control point, and Sensored's local regex + NER core lets you do that without the sensitive data leaving your machine. The honest read: two caveats decide whether you can rely on it. If you enable the optional AI-confirmation step, text does leave the machine (it hits an external API), and that step fails open — so an outage lets un-confirmed content through rather than blocking it. Combined with a ~1-star track record and no published recall/precision numbers, treat Sensored as a useful local-first redaction layer to evaluate, not a compliance guarantee — and if you need a hard block, do not depend on the fail-open confirmation path.
