Hoppa till huvudinnehåll
Microsoft
separator
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.presidio-ubuntu-24-04-3040f91e-f2a1-48fd-a6ba-3f72a2fa782e/image0_logolarge.png

Presidio on Ubuntu 24.04 LTS by cloudimg

av cloudimg

Presidio PII Detection on Ubuntu 24.04 LTS by cloudimg

Presidio is an open source toolkit for detecting and anonymising personally identifiable information in free text. It pairs two cooperating HTTP services: an analyzer that locates PII entities and returns the entity type, exact character offsets and a confidence score for each, and an anonymizer that redacts, replaces, masks, hashes or encrypts those spans. Presidio was originally created at Microsoft and is now community governed under the Data Privacy Stack organisation. It is released under the MIT licence.

This image delivers both services fully installed, warmed and hardened on Ubuntu 24.04 LTS, so a private PII detection and redaction API is answering requests within minutes of launch.

### Secure by default

Presidio ships with no authentication of its own, which matters unusually much for this product: callers send exactly the sensitive text they are trying to protect, so an open endpoint is a data exposure surface rather than merely an abuse surface. In this image both services are bound to loopback and are not reachable directly. A single nginx gateway fronts them and enforces HTTP Basic authentication on every API path. The credential is generated uniquely on first boot into a root only file, so there is no default login and no shared secret between deployments. Only the static health probe used by load balancers is unauthenticated.

Submitted text is never written to disk. Access logging is disabled on every API path, the services run at a log level that does not echo analysed text, and the build asserts this empirically by submitting a marked string and proving it appears in neither the system journal nor any log file.

### Natural language model and licensing

The spaCy model en_core_web_lg is installed and warmed at build time so the first customer request is answered correctly rather than being the request that discovers the model cannot load. Its licence is verified during the build against the artifact itself, from both the model metadata and the licence file shipped inside the model package, and the build fails closed unless both state MIT. Model name, version and licence are recorded on the image at /opt/presidio/MODEL-PROVENANCE.txt. Recognisers based on models with restrictive or research only licences are deliberately not installed.

### What cloudimg gives you

  • Presidio analyzer and anonymizer preinstalled on a hardened, fully patched Ubuntu 24.04 LTS base
  • Standard Presidio API paths preserved, so existing client code works by pointing at the VM with credentials
  • A unique API credential generated on first boot, with no default login
  • Loopback bound services behind a single authenticated gateway
  • A paired step by step deploy guide and 24/7 cloudimg support

Recommended size is Standard_B2ms or larger. The analyzer holds the language model in memory, so 8 GiB gives comfortable headroom.

En snabbtitt

https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.presidio-ubuntu-24-04-3040f91e-f2a1-48fd-a6ba-3f72a2fa782e/image7_screenshot01.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.presidio-ubuntu-24-04-3040f91e-f2a1-48fd-a6ba-3f72a2fa782e/image6_screenshot02.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.presidio-ubuntu-24-04-3040f91e-f2a1-48fd-a6ba-3f72a2fa782e/image3_screenshot03.png
https://catalogartifact.azureedge.net/publicartifacts/cloudimg1647283583153.presidio-ubuntu-24-04-3040f91e-f2a1-48fd-a6ba-3f72a2fa782e/image5_screenshot04.png
Svenska (Sverige)
Ikon för inaktivering av sekretessval Dina sekretessval
Sekretess för konsumenthälsa Platskarta Kontakta oss Sekretess och cookies Användningsvillkor Varumärken Om våra annonser Hantera cookies