Pages
Policy Config — Data Redaction

Source: c65 policy-definitions.md P9 — detector-list shape

‹ Policy Catalog

Data Redaction

Beta

Sensitive content — secrets, PII, PHI — is detected and redacted before leaving the proxy, in both prompts and responses. The minimisation answer for HIPAA and GDPR.

Data Protection
high
P9
SatisfiesOWASP LLMATLASCSF 2.0ISO 27001ISO 42001EU AI ActHIPAAGDPR
Underlying control— show
content: kind in (secret, pii)edit as custom control →

Redaction detectors

Detectors toggle individually; hit counts are the last 24h.

Secrets

high
3 hits
high
1 hit
medium
6 hits
medium
11 hitshigher false-positive rate

PII / PHI

medium
41 hits
high
0 hits
high
0 hitsenable for HIPAA scope
low
8 hits

Exceptions

Scoped carve-outs with a reason and an expiry — accepted risk, on the record.

ScopeValueReasonExpires
No exceptions — the policy applies everywhere.

Remediation shown on findings: Enable redaction for the detector; rotate any secret already disclosed.

Qpoint Brand Style Guide