Overview
Conduit’s PII redaction system automatically detects and masks sensitive personal information in customer conversations before they are processed by AI models. This ensures that private data like phone numbers, email addresses, and social security numbers are never exposed to external AI services. When enabled, PII values are replaced with tokens (e.g.,[REDACTED_EMAIL_1]) before being sent to AI, and then restored in the final response—maintaining conversation context while protecting sensitive data.
How It Works
The PII redaction system uses a three-step process:- Detection - Scans incoming messages for PII patterns using regex-based matching
- Redaction - Replaces detected PII with unique tokens (e.g.,
[REDACTED_PHONE_1]) - Restoration - After AI processing, restores original values in the response
Supported PII Types
Conduit detects and redacts the following categories of personal information:| Category | Examples | What’s Detected |
|---|---|---|
| Contact Information | Emails, phone numbers, addresses, URLs | [email protected], +1 (555) 123-4567, 123 Main Street |
| Government Identifiers | Social Security Numbers | 123-45-6789 |
| Financial Information | Credit/debit card numbers | 4111-1111-1111-1111 |
| Person Name | Individual names | Configurable per workspace |
| Date of Birth | Birth dates | Configurable per workspace |
| Customer Account Number | Account identifiers | Configurable per workspace |
| Security Credentials | Passwords, PINs | Configurable per workspace |
| Health Information | Medical IDs, healthcare data | Configurable per workspace |
Enabling PII Redaction
Workspace-Level Configuration
- Navigate to Settings > Privacy
- Toggle PII Redaction to enable
- Click Configure to customize which PII categories to redact
- AI-assisted message responses
- Phone call transcripts and summaries
- Workflow automations
- Knowledge base queries
Selecting PII Categories
You can choose exactly which types of PII to redact:- Click Configure PII Types in the privacy settings
- Select or deselect individual categories
- Use Select All or Deselect All for bulk changes
- Save your preferences
By default, all PII categories are enabled when you turn on PII redaction. You can then customize which types to exclude based on your needs.
Detection Patterns
Contact Information
Email Addresses- Standard format:
[email protected] - Obfuscated format:
user[dot]name[at]example[dot]com
- International format:
+1 555-123-4567 - Various separators:
(555) 123-4567,555.123.4567 - Minimum 6 digits with optional country code
- US-style addresses:
123 Main Street,456 Oak Ave - Recognizes common suffixes: Street, St, Road, Rd, Avenue, Ave, Boulevard, Blvd, Drive, Dr, Lane, Ln, Court, Ct
Government Identifiers
Social Security Numbers- Standard format:
XXX-XX-XXXX
Financial Information
Credit/Debit Cards- 13-16 digit card numbers
- Various formats with spaces or dashes
Token Format
Redacted values are replaced with descriptive tokens that indicate the type and sequence:[REDACTED_EMAIL_1], helping AI understand the relationship.
Integration Points
PII redaction is automatically applied across all AI-powered features:AI Message Responses
Messages are redacted before being sent to AI models for generating responses. The AI sees tokens instead of actual values, then responses are restored with original data.Phone Transcripts
Call transcripts, summaries, and metadata are processed through PII redaction before storage and AI analysis.Workflows
Any workflow step that involves AI processing respects your PII redaction settings.Knowledge Base
Queries to your knowledge base are redacted before processing.Best Practices
Start with all categories enabled
Start with all categories enabled
Begin with comprehensive protection, then selectively disable categories only if needed for your specific use case.
Test with sample conversations
Test with sample conversations
Before going live, test PII redaction with various message formats to ensure detection works as expected for your customer communication patterns.
Review AI responses
Review AI responses
Periodically review AI-generated responses to verify that PII is being properly restored and conversations remain natural.
Consider your compliance requirements
Consider your compliance requirements
Match your PII category selections to your industry’s regulatory requirements (HIPAA, PCI-DSS, GDPR, etc.).
Limitations
- Language support: Detection patterns are optimized for English language formats
- Custom patterns: Currently, custom PII patterns cannot be added—only the built-in categories are available
- Person names: Names require explicit category enablement and may not be automatically detected without additional context
Frequently Asked Questions
Does PII redaction affect AI response quality?
Does PII redaction affect AI response quality?
No. The AI receives contextual tokens that indicate relationships (same email referenced twice = same token), and original values are restored in the final response. Most customers see no difference in response quality.
Is redacted data stored anywhere?
Is redacted data stored anywhere?
Token mappings are stored temporarily for response restoration, then discarded. Original PII values are never stored by AI processing systems.
Can I disable redaction for specific conversations?
Can I disable redaction for specific conversations?
PII redaction is a workspace-wide setting. Individual conversations cannot bypass redaction when it’s enabled.
What happens if redaction misses some PII?
What happens if redaction misses some PII?
While the system catches most common PII formats, edge cases may occur. For highly sensitive environments, consider combining PII redaction with additional data handling policies.