Pages
Policy Config — Data Redaction
Source: c65 policy-definitions.md P9 — detector-list shape
‹ Policy Catalog
Data Redaction
BetaSensitive content — secrets, PII, PHI — is detected and redacted before leaving the proxy, in both prompts and responses. The minimisation answer for HIPAA and GDPR.
Data Protection
high
P9Satisfies
OWASP LLM
ATLAS
CSF 2.0
ISO 27001
ISO 42001
EU AI Act
HIPAA
GDPR
Underlying control— show
content: kind in (secret, pii)edit as custom control →Redaction detectors
Detectors toggle individually; hit counts are the last 24h.
Secrets
high
3 hitshigh
1 hitmedium
6 hitsmedium
11 hitshigher false-positive ratePII / PHI
medium
41 hitshigh
0 hitshigh
0 hitsenable for HIPAA scopelow
8 hitsExceptions
Scoped carve-outs with a reason and an expiry — accepted risk, on the record.
| Scope | Value | Reason | Expires | |
|---|---|---|---|---|
| No exceptions — the policy applies everywhere. | ||||
Remediation shown on findings: Enable redaction for the detector; rotate any secret already disclosed.