vfps¶
A very fast and resource-efficient pseudonymization service for research data, with gRPC, REST and FHIR APIs, an admin UI, and highly available deployments.
How these numbers were measured
-
Namespaces, one level or many
Each namespace has its own pseudonym format and length. Build multi-level pseudonymization by chaining child namespaces off a parent, and hand out several pseudonyms per original value where a study needs them.
-
Oblivious, verifiable pseudonyms
Derive deterministic pseudonyms with an RFC 9497 VOPRF. The key holder never sees the value it pseudonymizes.
-
gRPC, REST and FHIR
Every operation is available over gRPC and JSON-transcoded REST, described by an OpenAPI specification. FHIR clients can use the MII pseudonymization operations.
-
Admin UI and CSV jobs
Browse and create namespaces, then pseudonymize, de-pseudonymize, import or export larger-than-memory CSV files as background jobs that stream straight to and from S3-compatible storage.
-
Namespace-scoped access control
OIDC sign-in, separate read, write and reverse-lookup grants per namespace. Vfps-issued personal access tokens and service accounts with fine-grained access for machine users.
-
Built for production
Stateless replicas on PostgreSQL, a hardened Helm chart, and OpenTelemetry metrics and traces.
Try it in a minute¶
Then create a namespace and a first pseudonym through the REST API:
curl -X POST http://localhost:8080/v1/namespaces \
-H "Content-Type: application/json" \
-d '{"name": "test", "pseudonymGenerationMethod": "PSEUDONYM_GENERATION_METHOD_SECURE_RANDOM_BASE64URL_ENCODED", "pseudonymLength": 32}'
curl -X POST http://localhost:8080/v1/namespaces/test/pseudonyms \
-H "Content-Type: application/json" \
-d '{"originalValue": "to be pseudonymized"}'
Continue with the getting started guide.
Supply chain you can verify¶
Every released container image is signed with cosign and ships with SLSA Level 3 build provenance, and the repository is continuously assessed by the OpenSSF Scorecard. See Security for how to verify an image before deploying it.