Skip to content

Redaction and PII

Responses are redacted before an agent sees them, in two ways.

Every response is scanned for values that look like personal data, whatever column they are in, and each match is replaced with a marker such as [REDACTED:EMAIL]. The built-in scanner recognises:

Type Example shape
EMAIL [email protected]
PHONE North American phone numbers
SSN 123-45-6789
CREDIT_CARD 16-digit card numbers
IP_ADDRESS IPv4 addresses
MRN MRN followed by 6 to 10 digits

Columns whose names suggest free text (notes, description, body and so on) are scanned as text. An optional deeper scanner, built on Presidio, finds names and other entities; it needs the pii extra and pii.deep_enabled.

The scanner applies on every protocol, including the PostgreSQL wire, and to discovery results. It works on shapes: a sensitive value that looks like nothing in the table above is not redacted.

A policy rule can name columns to redact whatever they contain, with redact_columns. It follows output columns back to their source, so an alias does not escape it. It applies to MCP query results and HTTP JSON bodies. It does not apply on the PostgreSQL wire.

Each audit row records whether PII was found, which types, and how many values each redaction removed, so you can see redaction working without seeing the values.

Redaction keeps a query useful while hiding values. When a column must never leave at all, deny it with a source role or a policy columns condition: a denial holds on every protocol and does not depend on recognising a value’s shape.