Node reference
Mask PII node: strip personal data before the model
pii_mask · Updated September 28, 2026
The Mask PII node finds personal data in text and swaps it for tokens such as <PERSON_1> and <EMAIL_1>, so an agent downstream can still read and act on the message without seeing who it is about.
When to use it
- Before an Agent node that reads support tickets, form submissions, emails or notes.
- Healthcare or finance text, with the matching profile, where a leaked identifier is costly.
- Any workflow where the model does not need to know who someone is to do its job.
Ports
- Inputs
in- Outputs
outerror
Configuration
- Text
text - template · default "{{ input }}"
- Profile
profile - string · default "general"Which kinds of data to look for. Options come from the shield.
- Sensitivity
preset - relaxed | balanced | strictStricter catches more and over-masks more.
- Entities
entities - listLeave empty to use the profile's own list.
- Countries
countries - listISO codes. GLOBAL is always on, ALL turns on every country.
- Default phone region
default_phone_region - string
- Never mask
allow_list - list
- Always mask
deny_list - list
- If the shield is down
on_error - pass_through | fail · default "pass_through"
Output
Fires out with the masked text. Fires error only when masking is unavailable and If the shield is down is set to fail; by default the text passes through unmasked instead.
Example
in: Hi, I'm Nimal Perera, card 4111 1111 1111 1111, call +94 77 123 4567.
out: Hi, I'm <PERSON_1>, card <CREDIT_CARD_1>, call <PHONE_1>.Good to know
- Profile picks what to look for: general, healthcare, finance or minimal. Sensitivity trades misses for over-masking.
- National IDs are only found for the countries you turn on; email, phone, card and IBAN always are.
- The run records how many values were masked, never the values themselves.
- See PII masking for profiles, countries and the allow and deny lists.
Keep reading
- PII masking: keep personal data away from the modelMask names, emails, phone numbers, card numbers and national IDs before an AI agent sees them, using the Mask PII node and its data profiles.
- Agent node: Claude with tools and structured outputThe Agent node calls Claude with your prompt, uses attached HTTP, app, API and MCP tools in a loop, and returns text plus structured output to branch on.
- Credentials and securityHow Worfilo protects API keys, app connections and MCP secrets: encryption at rest, redaction in run history, SSRF protection and sandboxed templates.
Build it on the canvas
Create a free account, describe the workflow or wire it yourself, and run it in the browser.