Getting Started
Your first website PII scan in 4 steps. No account required. Scan results are held in memory only and never stored.
A PII scan is an automated check for personal data that a website publishes to anyone who visits it. piisafe.eu is a hosted scanner: it crawls the pages you name, sends their text to the anonym.legal detection API, and shows you what came back. Personal data is defined as any information relating to an identified or identifiable natural person, in Article 4(1) of Regulation (EU) 2016/679 — the GDPR, which has applied across the EU since 25 May 2018.
Enter Your API Key
Get a free API key from anonym.legal, then paste it into piisafe.eu.
- Get key from anonym.legal
- Key is saved in your browser (localStorage) for convenience
- Each scan passes it to our server, which forwards it to anonym.legal; it is never stored or logged server-side
Configure Detection Settings
Choose what types of PII you want to detect:
- Compliance Presets: GDPR, HIPAA, PCI-DSS, CCPA (pre-configured)
- Custom Entities: Select specific types (Email, SSN, IBAN, etc.)
- Language: Choose from 48 languages for region-specific patterns
- Threshold: Adjust sensitivity (higher = fewer false positives)
Enter Target Website
Paste the URL of the website you want to scan:
- Auto-discovers pages via sitemap.xml or recursive crawling
- Review discovered pages and select which ones to scan
- Supports up to 1,000 pages per scan
- See estimated token cost before scanning
Launch Scan and View Results
Click "Start Scan" and watch real-time progress:
- Live Progress: Pages scanned, PII found, tokens used
- Risk Grade: A-F score based on findings
- Findings View: By type, page, or severity
- Export: HTML report, JSON, or CSV
Detection API at a Glance
| Feature | anonym.legal |
|---|---|
| Entity Types | 58 |
| Languages | 48 |
| Compliance Presets | 24 (GDPR, HIPAA, PCI-DSS, regional) |
| Detection Method | NLP + exact pattern recognisers |
| API Limit | 50,000 chars/call (auto-chunked) |
| Pricing | Token-based (€3 entry) |
| MCP Server | Yes |
Troubleshooting
Verify your key at the provider's dashboard. Ensure the key was issued by anonym.legal.
Check if the site has a valid sitemap.xml. If not, manually enter page URLs or enable recursive crawling.
Large sites take longer. Try scanning fewer pages. Check your internet connection and ensure the target site is accessible.
Pages larger than 50KB are automatically chunked into multiple API calls. Token cost scales with page size and entity count.
Increase the sensitivity threshold for stricter detection. Use presets instead of custom entity configurations.
Rate limits are per IP address, not per user: 30 API requests per minute, 20 new scans per hour, and 120 status polls per minute. Wait for the window to reset and retry. Everyone behind the same office router shares one budget.
A single scan analyses at most 1,000 pages, whatever number you ask for. Page discovery has its own ceiling, which you can set between 10 and 20,000 URLs. Split a larger site across several scans and keep each export.
The crawler reads only responses whose content type is text/html, so PDFs, images and JSON endpoints never reach the detector. It also parses the HTML without running scripts, so anything a page draws after load stays invisible to the scan.
Scan sessions live in server memory and nowhere else. A finished session is swept 35 minutes after the scan ends, and a service restart clears every session at once. Export your findings before you close the tab.
Next Steps
Ready to Start?
Scan your website for exposed PII in 5 minutes. No registration required.
Open Scanner →