Skip to content

Add a first-class PII/PHI detector to the redaction gate #108

Description

@danielgwilson

Problem

Humanish's public-safety story advertises blocking PII/PHI/patient data (humanish/policies/redaction.yaml deny list; docs/contracts/policy.md "required redaction gates"). But the enforced automated gate is a secret/key/token + known-local-path regex denylist. It has no detector for free-form PII/PHI (names, emails, phone numbers, SSNs, DOBs, MRNs, medical detail). A real PHI string would pass redaction: passed and could flow into a public issue draft.

This is the project's central trust claim, and the author works in a healthcare (PHI) context, so the gap is high-consequence.

A companion docs-honesty PR is narrowing the claim now (enforced vs. author-responsibility). This issue tracks closing the gap for real.

Proposed: a first-class PII/PHI detector lane

  • A pii-phi detector applied to every public-bound artifact (run bundle text, Observer projection, feedback draft) as part of the redaction gate, failing closed on match.
  • Detection tiers:
    • Deterministic high-precision: emails, phone numbers, SSN, credit-card (Luhn), IBAN, IP, dates-of-birth, common MRN/insurance-id shapes.
    • Optional model-assisted NER for names/addresses/medical terms, behind a flag, local-model-friendly (no provider spend by default), with the deterministic tier always on.
  • Make it the shared redaction module's responsibility (see Redact absolute workspace path in blocked-TUI bundle + close verify scanner /tmp blind spot #107), so all three current redaction call sites use one detector.
  • redaction: passed should then mean "secret/path scan AND PII/PHI scan found no matches," with the verify check naming which tier ran.

Why this is also a differentiator

Public-safe-by-construction is the wedge. A credible, local-first PII/PHI gate that most synthetic-user/agent-eval tools lack turns the biggest current weakness into a defensible feature, and is directly on-brand for a maintainer-facing, public-repo-safe harness.

Acceptance

  • Deterministic PII detector with a tested corpus (true positives + non-flagging of synthetic fixtures).
  • Wired into the verify gate; planted PII fails closed.
  • Docs/policy updated from "author responsibility" to "enforced" for the covered classes.

Related: #107 (shared redaction module)

Activity

  1. danielgwilson commented on Jun 11, 2026

    @danielgwilson
    OwnerAuthor

    Status update (2026-06-11): deliberately deferred, not forgotten. Per the capture-vs-publish doctrine (docs/principles/invariants-and-defaults.md), a PII/PHI detector binds the publish boundary, and today no publish path for bundles exists (feedback drafts carry text + path strings only, gated by verify). The detector earns its complexity when evidence from real-data subjects enters scope — the multi-party clinical platform depth phase on the proof roadmap. Until then the enforced gate remains secrets/paths, and the README/policy docs state that scope honestly. Keeping open as the tracking issue, re-sequenced behind the depth phases.

  2. added
    enhancementNew feature or request
    privacy-boundaryPII, PHI, secret, token, or future-public safety boundary.
    proof-requiredCannot close without command, artifact, review, or run-bundle proof.
    area:coreCore run, artifact, history, lifecycle, and verification primitives.
    area:github-feedbackGitHub Issues, labels, templates, and feedback issue drafts.
    needs-specAccepted work needs a spec or split before implementation.
    agent-blockedExplicitly not eligible for autonomous pickup.
    next:parkParked until later.
    on Jul 15, 2026
  3. danielgwilson commented on Jul 15, 2026

    @danielgwilson
    OwnerAuthor

    Current status

    Unshipped and deliberately parked as of 0.15.2. Humanish enforces secret, token, hosted-URL, and known local-path scanning, but it does not detect free-form PII/PHI. Feedback commands do not mutate GitHub and require shareSafety.status === "share_ready", but that status does not currently mean that free-form PII/PHI detection ran.

    Implement this before accepting evidence from real-data subjects or adding a bundle-publication path.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    agent-blockedExplicitly not eligible for autonomous pickup.area:coreCore run, artifact, history, lifecycle, and verification primitives.area:github-feedbackGitHub Issues, labels, templates, and feedback issue drafts.enhancementNew feature or requestneeds-specAccepted work needs a spec or split before implementation.next:parkParked until later.privacy-boundaryPII, PHI, secret, token, or future-public safety boundary.proof-requiredCannot close without command, artifact, review, or run-bundle proof.risk:highHigh-risk work.

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions