America.gov's browser filter keeps names and generic government IDs
The inspected client code adds four categories to Rampart's default keep-set, while the model card says generic government identifiers have no deterministic backstop.
By Ryan Merket · Published · Updated
RUNTIMEWIRE INVESTIGATION — Original analysis
Original reporting by RuntimeWire, based on documents, testing.
Why it matters
A keep-set decides what happens after detection: America.gov's inspected browser code appears to exempt names, URLs and generic government IDs from Rampart's default redaction policy. The model card reports only about 67.6% recall on a structured-government-ID probe and says those identifiers lack a deterministic backstop, while the code review does not establish what reaches servers or what server-side controls apply.
Reporting record
Finding
America.gov's inspected browser code adds GIVEN_NAME, SURNAME, URL and GOVERNMENT_ID to Rampart's default keep-set, excluding spans with those labels from redaction or blocking in the inspected paths.
How we verified
Methods: documents, testing.
America.gov's client-side privacy wrapper, shared filter implementation and composer/PDF processing code; Rampart's published model card; and a synthetic-label check of four inspected span-selection functions.
Inspected America.gov's client-side JavaScript, traced the keep-set through typed-message privacy checks and PDF and feedback text-scrubbing paths, and checked four span-selection functions using synthetic labels. Compared the configuration with Rampart's published defaults. No personal identifiers were submitted.
Evidence
Reproduction
RuntimeWire independently reproduced the core finding.
Use synthetic labels to check the four inspected span-selection functions: GIVEN_NAME, SURNAME, URL and GOVERNMENT_ID were excluded from selection, while SSN, PASSPORT, DRIVERS_LICENSE, EMAIL, PHONE and BANK_ACCOUNT remained selected.

What a Rampart model card is for
A model card gives the people choosing and deploying a model a concise record of what it was tested to do, where it falls short and what uses its developers consider appropriate. That helps a deployer judge whether the model fits a particular job and where extra testing or safeguards may be needed. It does not certify an application built around the model or document every choice made in a deployed service. Hugging Face's model-card guidance describes intended uses, evaluation and limitations as core contents; the original model cards paper proposed the format to clarify suitable use and reduce use in contexts where a model performs poorly.
For Rampart, the card makes a practical security distinction visible: the model's detection limits are separate from the rules an application uses to decide what to redact. Rampart's model card says the model cannot reliably check many government IDs using checksums, including case numbers, Medicare-style IDs, immigration receipts, passports and licenses. In a test of structured IDs, the model detected about 67.6%. That result measures the model alone, not America.gov's full system.
The card also reports roughly 14% aggregate recall for names written in non-Latin scripts and warns against relying on this release for populations that routinely use those scripts without compensating controls. That is a detection limitation. America.gov's keep-set is a separate policy choice that can exempt a name even when the model detects it.
America.gov's browser policy
America.gov's browser-based privacy filter appears configured to let detected names, URLs and a broad government-ID category pass without redaction, a departure from the defaults of the open-source Rampart system it uses. The finding comes from inspection of America.gov's client-side JavaScript; it does not establish what information reached a server or whether additional server-side controls apply.
The application adds GIVEN_NAME, SURNAME, URL and GOVERNMENT_ID to its keep-set, alongside the CITY, STATE and ZIP_CODE categories that Rampart keeps by default. In the inspected browser paths, the shared filter removes spans in those kept categories from the list selected for redaction or blocking. A name can therefore be recognized by the detector and still be left unchanged by policy.
The code path is used in typed-message privacy checks and in text scrubbing for PDFs and feedback. A synthetic-label check of four inspected span-selection functions reproduced the reported behavior: the four added categories were excluded, while SSN, PASSPORT, DRIVERS_LICENSE, EMAIL, PHONE and BANK_ACCOUNT remained selected. No personal identifiers were submitted in that check.
GOVERNMENT_ID is one label, not an umbrella covering every government-issued number. Separate labels exist for Social Security numbers, passports and driver's licenses; those categories remained subject to filtering in the synthetic check. The inspected America.gov code also contains additional regular expressions for some immigration receipt numbers, A-numbers, Medicare-style identifiers and housing or application case IDs. Those checks do not establish that every identifier is caught, or that every identifier passes through.
Rampart's published label taxonomy sets a different baseline: every detected span is redacted unless its category is explicitly kept. Its default keep-set is limited to city, state and ZIP code; names, URLs and generic government IDs are listed among the categories redacted by default. The Rampart source and README describe the same default-deny policy and say its client-side system is designed to replace personal values before text leaves the browser.
The GSA's announcement of America.gov on September 29th, 2026 described an AI-assisted gateway drawing on more than 29,000 government websites and intended to help people find services including benefits, passport renewals and Social Security information. That makes the filter policy relevant to a public-facing service where users may enter personal details while seeking help, though the code review does not show that any such details were transmitted.
National Design Studio introduced Rampart in June 2026 as an on-device filter, describing it as a first line of defense. The launch post describes regular expressions and validations as handling government IDs, while the technical model card says generic government identifiers without checksums rely on the model. The distinction may turn on which formats are meant by each description; the public materials do not resolve how America.gov's exemptions and additional patterns fit together.
The client code shows a configuration choice. It cannot answer why that policy was chosen, whether the same exclusions apply in every deployed flow, or whether server-side filtering, retention limits or access controls compensate after submission. The GSA's announcement describes the service's reach and purpose, but does not specify those safeguards. The verified finding is narrower: in the inspected browser selection paths, detected spans labeled as given names, surnames, URLs or generic government IDs are excluded from redaction or blocking.