Best-in-Class
PII Dectection,
Open Source


A 300M-parameter multilingual model for detecting
and redacting personally identifiable information.
Built for production privacy workflows.
0.471
avg. SPY
F1 score
42
entity
types
300M
params
encoder
RESEARCH
Capabilities of GLiNER2-PII

PII extraction. Identify and extract 42 entity types across seven categories - 5× coverage of OpenAI's Privacy Filter.
Learn more

Customizable schema at inference. The target schema is an input to the model, not baked into the weights.
Learn more

One forward pass, deterministic inference. Model evaluates all 42 entity types simultaneously.
Deploy GLiNER2-PII
EFFICIENCY
Smaller, faster, built to self-host
SOTA performance at fraction of the size
vs OpenAI Privacy Filter.
Low latency
Optimized for real-time, production pipelines.
Stay on your infrastructure
Apache 2.0 license. Can run on-prem or air-gapped, or deployed with Pioneer.
< 100ms
Average latency
per request
5x
Label coverage
versus OpenAI Privacy Filter
300M
Parameters
versus OpenAI's 1.5B
35M+
Downloads on
Hugging Face

GLiNER2-PII Benchmark Results
Evaluated on SPY (Synthetic PII Yesterday), 200 documents split evenly between legal Q&A forums and medical transcripts. None of the models in the comparison were trained on this data, making it an out-of-distribution test.
OpenAI Privacy Filter
NVIDIA GLiNER PII
FASTINO GLiNER2-PII
Parameters
1.5B
—
0.3B
Entity types
8 (fixed)
—
42 (customizable)
Architecture
Decoder (autoregressive)
Encoder (GLiNER)
Encoder (GLiNER2)
Custom schema at inference
Recall - Legal domain
0.640
0.431
0.722
Precision - Legal domain
0.250
0.374
0.522
F1 score - Legal domain
0.360
0.401
0.475
Recall - Medical domain
0.671
0.431
0.681
Precision - Medical domain
0.271
0.341
0.355
F1 score - Medical domain
0.386
0.381
0.467