A secure data anonymization tool with a modern frontend and FastAPI backend. Supports login, PII detection, and masking or hashing options.
- Python 3.8+
- FastAPI, Uvicorn, pandas, openpyxl, bcrypt, passlib, itsdangerous, Jinja2, python-multipart, and python-dotenv
Create a local .env file and configure these values before starting the application:
SESSION_SECRET_KEY=replace-with-a-long-random-secret
OBSCURA_ADMIN_USERNAME=admin
OBSCURA_ADMIN_PASSWORD_HASH=replace-with-a-bcrypt-hash
OBSCURA_USER_USERNAME=user
OBSCURA_USER_PASSWORD_HASH=replace-with-a-bcrypt-hashGenerate bcrypt hashes locally with Passlib. Do not commit the .env file or real credentials.
python3 -m venv venv
source venv/bin/activate
pip install fastapi uvicorn pandas openpyxl bcrypt passlib[bcrypt] itsdangerous jinja2 python-multipart python-dotenv
uvicorn backend.main:app --reloadThen visit http://localhost:8000.
- File upload and preview
- PII auto-detection
- Masking or hashing
- Download of anonymized files
- User and admin access control
- Action logging
backend/— FastAPI logic and anonymization codefrontend/— HTML, CSS, and JavaScript interfacetemp/— temporary uploaded filesresults/— anonymized outputs
- Credentials are loaded from environment variables and are not included in the repository.
- The session secret must be configured before the application starts.
- Never commit
.env, real passwords, API keys, or personal data.