PostgreSQL Anonymizer is a PostgreSQL extension for masking or replacing personally identifiable or commercially sensitive data. Masking rules can be written in SQL using PostgreSQL DDL and stored in the database schema. Documented approaches include anonymous dumps, static and dynamic masking, replica masking, masking views, and data wrappers. Functions can randomize, fake, partially scramble, shuffle, add noise, generalize, or apply custom transformations. Identifier detection searches for common names using English and French dictionaries, though the documentation warns that it may report false positives or miss identifiers. A masked database role can export anonymized data with pg_dump; masking rules should be removed from the resulting dump. Installation instructions cover Linux distributions and self-hosted PostgreSQL, with source builds possible on macOS and use inside PostgreSQL on WSL2 for Windows. Installation requires superuser privileges, so a DBaaS provider must add the extension to its catalog. Dynamic masking prevents masked roles from using EXPLAIN, and masking rules can affect data integrity, such as changing a UNIQUE column to NULL. The license permits use, copying, modification, and distribution without a fee; commercial support is available separately.
Who it is for
The extension suits teams working with PostgreSQL that need to mask sensitive data for exports or database use. It may fit self-hosted deployments and DBaaS environments where the provider has added it to the extension catalog.
What is good
- Masking rules are declared in SQL and stored in the schema.
- Multiple masking methods and transformation functions are documented.
- Anonymized data can be exported with pg_dump.
- Use, copying, modification, and distribution carry no fee.
What to know first
- Installation requires superuser privileges.
- No native Windows build is available.
- macOS community support is not provided.
- Masking rules can affect data integrity.
Verdict
PostgreSQL Anonymizer provides several ways to mask data, with rules defined in the database schema. Check deployment permissions and platform constraints, and account for the documented risks to data integrity.
PostgreSQL Anonymizer plans and pricing
All plansCompared on data masking software
- Free plan
- Yes
- Masking methods
- both
- Synthetic data
- Yes
- Referential integrity
- Yes
- Data subsetting
- Yes
- API access
- Yes


