> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datafog.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# DataFog Core

> Detect PII and apply explicit privacy transformations from Rust, Python, Node.js, and browsers.

DataFog Core is a multi-runtime engine for detecting sensitive text and applying
privacy transformations. The implementation lives in Rust, with thin bindings
for Python, Node.js, and browser WebAssembly.

<Note>
  DataFog Core is distributed as `datafog-core`. It is separate from the
  established `datafog` Python package and does not reproduce its legacy API.
  Existing users should follow [Migrate from DataFog
  Python](/guides/migrating-from-datafog-python).
</Note>

## What it does

<Columns cols={2}>
  <Card title="Detect PII" icon="magnifying-glass" href="/concepts/findings-and-ranges">
    Scan text for structured findings with explicit ranges and detector provenance.
  </Card>

  <Card title="Transform text" icon="wand-magic-sparkles" href="/concepts/privacy-transformations">
    Redact, mask, remove, pseudonymize, or tokenize selected findings.
  </Card>

  <Card title="Control selection" icon="sliders" href="/guides/configuration">
    Select entity types, apply per-entity overrides, and exempt approved values.
  </Card>

  <Card title="Restore tokens" icon="rotate-left" href="/guides/tokenization-and-restoration">
    Restore provider-issued tokens atomically under an exact authorization scope.
  </Card>
</Columns>

## Supported entities

Text scans recognize these entities without a locale:

* `EMAIL`
* `PHONE`
* `SSN`
* `CREDIT_CARD`
* `IP_ADDRESS`
* `DATE`
* `ZIP_CODE`
* `BEARER_TOKEN` (0.4.1; [explicit Authorization headers](/reference/bearer-token))
* `JWT` ([recognition rules](/reference/jwt))
* `API_KEY` (0.4.1; [supported providers](/reference/api-keys))
* `PRIVATE_KEY` (complete PEM blocks — [format and boundaries](/reference/private-keys))

Structured scans also discover `PERSON` in supported name fields. See
[structured person discovery](/guides/person-discovery) for field mappings.

<Note>
  **German coverage (0.4.0+):** an explicit German locale adds `DE_IBAN`,
  `DE_VAT_ID`, `DE_TAX_ID`, `DE_SOCIAL_SECURITY_NUMBER`, `DE_POSTAL_CODE`,
  `DE_PASSPORT_NUMBER`, and `DE_RESIDENCE_PERMIT_NUMBER`. See the
  [German entity reference](/reference/german-entities) for examples, required
  contexts, and format limitations. This coverage is available in Core 0.4.0 or newer.
</Note>

UUID identifiers can also be detected with an explicit `detect_uuid: true`
option in Core 0.4.0 or newer. See [UUID identifiers](/reference/uuid) for the supported
syntax and why this detector is opt-in.

Built-in entity names are uppercase. The finding contract remains extensible so
custom detectors can introduce additional entity names in the future.

## Operation model

```text theme={null}
scan(text)                    -> findings
transform(text, findings, …) -> transformed text + records
scan_and_transform(text, …)  -> scan, then transform
restore(text, context)       -> restored text + records
```

`transform` never scans implicitly. Use `scan_and_transform` when you want the
explicit scan-then-transform convenience operation.

## Start here

<Columns cols={2}>
  <Card title="Install a package" icon="download" href="/get-started/installation">
    Choose the distribution for your runtime.
  </Card>

  <Card title="Run the quickstart" icon="play" href="/get-started/quickstart">
    Detect and redact an email address in a few lines.
  </Card>
</Columns>

[US routing number detection](/reference/us-routing-number) adds `US_ROUTING_NUMBER` with explicit text context.
[National Provider Identifiers detection](/reference/npi) adds `NPI` with explicit text context.

[DataFog Core 0.4.1](/releases/0-4-1) is published across all four runtimes and includes Rust/Python capability discovery and a [compatibility policy](/reference/compatibility). The higher-level Python adapter is integrated in [merged PR #179](https://github.com/DataFog/datafog-python/pull/179); its package release is separate.

[Core 0.4.1](/releases/0-4-1) adds default `API_KEY`, `BEARER_TOKEN`, and `CREDENTIAL_URI` detection. The runtime registry reports 23 supported entities and 14 defaults. The local Python 4.9 adapter integration gate passed against the exact candidate wheel; the release notes record its evidence and limits.
