Build1 publisher3 min readPublished
America.gov's browser filter exempts names and the GOVERNMENT_ID label from Rampart's redaction
America.gov's browser code adds four labels to Rampart's keep-set, letting detected names, URLs and generic government IDs skip redaction. Because the keep-set runs after the model, Rampart's published accuracy figures stop describing what those client paths remove.
The Engineer · Build desk

What happened
- Rampart ships with a keep-set of only CITY, STATE and ZIP_CODE, so America.gov's additions more than double the exempt list, to seven labels.
- The exempting filter runs in America.gov's typed-message privacy checks and in the text scrubbing applied to PDFs and feedback.
- RuntimeWire's synthetic-label test of four span-selection functions found SSN, passport, driver's license, email, phone and bank-account labels still selected.
- The review covered browser JavaScript only and does not establish what reached America.gov's servers or whether server-side controls apply.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- constraint Better detection from Rampart would not change America.gov's client-side output for the generic GOVERNMENT_ID label, because policy drops those spans after the model finds them.
- decision Anyone auditing a Rampart deployment has to read the application's keep-set alongside the model card, since the card measures detection and a few added labels can undo the vendor's defaults.
- exposure In America.gov's client code, protection for passport and license numbers depends on the model spotting them, and the card lists both among IDs it cannot confirm by checksum.
Rampart splits the job in two. The model detects spans and labels them. America.gov's shared filter then removes every span whose label is in the keep-set from the list selected for redaction or blocking [3]. Policy runs last, so it wins. A name the detector recognizes correctly is still left unchanged [3].
That ordering changes how Rampart's model card should be read. On a test of structured government IDs, the card reports the model detected about 67.6% [6], so roughly a third went unflagged [2]. The card also says the model cannot reliably check many government IDs by checksum, listing case numbers, Medicare-style IDs, immigration receipts, passports and licenses [7]. Without a checksum, nothing deterministic catches the IDs the model misses, according to RuntimeWire's reading of the card [7]. RuntimeWire also says the 67.6% measures the model alone, not America.gov's system [6].
For that figure to carry over to America.gov's browser, two things would have to hold. The site's inputs would have to look like the probe. Every ID the model detects would also have to carry a label that is still selected for redaction. The second condition fails for the generic GOVERNMENT_ID label. In the inspected paths, a span with that label is dropped from the redaction list, so for that label the selection rate is zero at any recall [3]. Passport and license labels stay selected [5]. For those, detection quality still decides the result, and they are two of the ID types the card says the model cannot confirm by checksum [7].
Names follow the same pattern. The card reports roughly 14% aggregate recall for names in non-Latin scripts and warns against relying on this release for populations that routinely use those scripts without compensating controls [8]. In America.gov's inspected paths that weakness has no effect on output, because GIVEN_NAME and SURNAME are kept even when detected [1].
How far the ID exemption reaches depends on labeling. RuntimeWire describes GOVERNMENT_ID as one label, not an umbrella for every government-issued number [10]. A number the model tags as SSN, PASSPORT or DRIVERS_LICENSE is still selected [5]. One it tags with the generic label passes through [1].
I think Rampart's split is the right design. Detection accuracy and redaction policy are separate questions, and a deployer with a real reason to keep a class of spans should be able to say so in one place. The card is also direct about where the model is weak, down to naming the populations it should not be trusted for [8]. The cost of the split is that neither the card nor the vendor's defaults describe a deployment once its keep-set changes. America.gov's change is four added labels in client code [1].
What to watch
- Whether America.gov explains the four keep-set additions or removes GOVERNMENT_ID from the list.
- Server-side testing that shows whether names and generic government IDs are redacted after they leave the browser.
- A Rampart release that adds checksum validation or documents which numbers the model assigns to the generic GOVERNMENT_ID label.