Databunker

Databunker

Self-hosted vault for tokenizing and encrypting sensitive records

1.4kstars
89forks
Last commit: 2mo ago
Repo age: 7y old
Databunker screenshot

Databunker is a self-hosted, Go-based privacy vault for storing sensitive customer data (PII/PHI/KYC/PCI) using tokenization and strong encryption. It is designed to reduce exposure of plaintext data in application databases and to support common privacy compliance workflows.

Key Features

  • Tokenization engine that replaces sensitive fields with UUID tokens for use in your application database
  • Encrypted storage layer (designed to avoid plaintext at rest) with secure, hash-based indexing for lookups
  • REST API intended as a “secure user table” replacement, with OpenAPI specification support
  • Built-in protections aimed at reducing data exposure via bulk export and common injection patterns
  • Consent management and privacy operations support (e.g., access requests, deletion/right-to-be-forgotten, portability)
  • Audit trail and access logging for compliance and traceability
  • Container-friendly deployment and support for common SQL backends

Use Cases

  • Centralized vault for customer profile data to reduce PII exposure in primary application databases
  • Compliance-oriented storage for regulated datasets (e.g., GDPR/CCPA/HIPAA-aligned workflows)
  • Tokenization of high-risk identifiers (including payment-related data in supported editions) to reduce breach impact

Limitations and Considerations

  • Some advanced capabilities commonly advertised for enterprise deployments (e.g., key rotation, multi-tenancy, credit-card tokenization) may depend on the Pro/enterprise offering rather than the core open-source edition.

Databunker fits teams that want to segregate sensitive data behind a dedicated service and integrate via a simple API. It is particularly useful when reducing plaintext exposure and audit scope is more important than building custom encryption and compliance tooling in-house.

Categories:

Tags:

Tech Stack:

Share:

Similar Services

Vaultwarden

Vaultwarden

Bitwarden-compatible password manager server written in Rust

53.6k
2.5k
Last commit: 3d ago

Vaultwarden is a lightweight, Bitwarden-compatible password manager server in Rust, designed for self-hosting with official Bitwarden clients.

Alternative to:
Bitwarden
Bitwarden
+9
KeePassXC

KeePassXC

Cross-platform offline password manager using encrypted KDBX databases

25.5k
1.7k
Last commit: 1mo ago

KeePassXC is a secure, cross-platform password manager that stores credentials and sensitive notes in encrypted KeePass-compatible KDBX files with autofill and browser in...

Alternative to:
KeePassXC
KeePassXC
+10
Infisical

Infisical

Open-source platform for secrets, PKI certificates, and privileged access

24.5k
1.7k
Last commit: 20h ago

Infisical is an open-source platform to manage and deliver app secrets, certificates (PKI), SSH credentials, and encryption keys across teams and infrastructure.

Alternative to:
HashiCorp Vault
HashiCorp Vault
+9
Ente

Ente

End-to-end encrypted cloud for photos and 2FA

23.9k
1.4k
Last commit: 1d ago

Open-source, end-to-end encrypted platform for private photo backup, sharing, and authenticator (2FA) sync across devices, with optional self-hosting.

Alternative to:
Google Photos
Google Photos
+14
Bitwarden

Bitwarden

Open-source password manager with zero-knowledge security and self-hosting.

17.9k
1.5k
Last commit: 16h ago

Bitwarden is an open-source password manager that stores, shares, and autofills credentials with zero-knowledge encryption; supports cloud or self-hosted deployments.

Alternative to:
1Password
1Password
+9
Passbolt

Passbolt

Open-source password and secret manager for teams

5.6k
361
Last commit: 26d ago

Passbolt is an open-source, security-first password and secret manager for teams, with end-to-end encryption, granular sharing permissions, and auditing.

Alternative to:
Passbolt Cloud
Passbolt Cloud
+11