
Databunker
Self-hosted vault for tokenizing and encrypting sensitive records
1.5k stars 94 forks last commit first released MIT
Actively maintained
Last commit 26 Jul 2026.

Databunker is a self-hosted, Go-based privacy vault for storing sensitive customer data (PII/PHI/KYC/PCI) using tokenization and strong encryption. It is designed to reduce exposure of plaintext data in application databases and to support common privacy compliance workflows.
Key Features
- Tokenization engine that replaces sensitive fields with UUID tokens for use in your application database
- Encrypted storage layer (designed to avoid plaintext at rest) with secure, hash-based indexing for lookups
- REST API intended as a “secure user table” replacement, with OpenAPI specification support
- Built-in protections aimed at reducing data exposure via bulk export and common injection patterns
- Consent management and privacy operations support (e.g., access requests, deletion/right-to-be-forgotten, portability)
- Audit trail and access logging for compliance and traceability
- Container-friendly deployment and support for common SQL backends
Use Cases
- Centralized vault for customer profile data to reduce PII exposure in primary application databases
- Compliance-oriented storage for regulated datasets (e.g., GDPR/CCPA/HIPAA-aligned workflows)
- Tokenization of high-risk identifiers (including payment-related data in supported editions) to reduce breach impact
Limitations and Considerations
- Some advanced capabilities commonly advertised for enterprise deployments (e.g., key rotation, multi-tenancy, credit-card tokenization) may depend on the Pro/enterprise offering rather than the core open-source edition.
Databunker fits teams that want to segregate sensitive data behind a dedicated service and integrate via a simple API. It is particularly useful when reducing plaintext exposure and audit scope is more important than building custom encryption and compliance tooling in-house.
Categories:
Tags:
Tech Stack:
Similar to Databunker

TeamPass
Collaborative on-prem password management with RBAC and encryption.
On-prem password manager enabling secure sharing and fine-grained access control over credentials.
OpenBao
Open source secrets management for keys, certificates, and tokens
OpenBao is an open source secrets management platform to securely store, generate, lease, and revoke secrets, certificates, and encryption keys with auditing and access control.
Plik
Temporary file upload and sharing service with web UI and CLI
Plik is a WeTransfer-like temporary file upload and sharing service with a web UI, CLI client, REST API, expiration (TTL), and multiple storage backends.

Documenso
Open-source document signing platform and DocuSign alternative
Open-source e-signature platform for creating, sending, embedding, and automating legally compliant digital signatures with API and developer tooling.


OliveTin
Web interface to run predefined shell commands securely
Self-hosted web UI that exposes YAML-defined shell commands as buttons, dashboards and API endpoints with ACLs, auth and logging for safe, repeatable server operations.

eLabFTW
Electronic lab notebook and lab inventory management for research teams
Open source electronic lab notebook (ELN) for documenting experiments, managing lab inventory, and coordinating equipment booking with granular permissions and auditing.



