Protect sensitive data
Proxium scans each request before it leaves, and flags, redacts or blocks what you choose. Sensitive data scanning explains what it finds and how.
Set what Proxium does
Each project starts on the default policy of the gateway. On proxium.tech, five classes are on redact, with an alert:
| Class | Finds |
|---|---|
credit_card | Card numbers |
card_security | Card expiry dates and security codes |
iban | IBANs |
national_id | National ID numbers |
credential | API keys, tokens and private keys |
The other classes are off: email addresses, phone numbers, IP addresses, your own terms and prompt injection. The screen says This project uses the default policy until you change a class.
- Open Data protection in the console.
- For each class, select an action:
off,flag,redactorblock. - For
redactandblock, select Alert to get an alert for each match. Aflagalways sends one. - Select Save.
The next request uses the new settings. In force shows the action that applies. If the operator set a stricter floor for a class, it shows there too.
When you change a class, the classes become the project's own. A class that you did not change keeps the value of the default. A save of Your terms alone keeps the project on the default policy.
The AI check for secrets
The classes above find values with a known format. A password such as "hunter2" has none. The AI check reads each request and finds passwords, keys and other secrets of any shape. It can flag or block a request. It cannot redact, because it says that a secret is there, not where.
The AI check is part of some plans. A project can also use it with its own TypeSafe key. It is off until you select an action for Secrets (AI check), and each request then takes a short moment longer.
Go back to the default policy
- Open Data protection.
- Select Reset to default, and confirm.
The classes go back to the default policy of the gateway. Your terms stay. The API call is DELETE /api/teams/{slug}/guardrails.
To find out first what your traffic holds, set a class to flag for a few days. Your requests go out unchanged, and Matches shows where the values were.
Add your own terms
- In Your terms, type one word or phrase on each line, such as a customer name or a code name.
- Set the class Your terms to
flag,redactorblock. - Select Save.
A term matches as a whole word, in any case: acme matches ACME and not acmecorp. A project keeps at most 200 terms, each at most 100 characters.
Try a text
Paste a text in Try a text, and select Check. The console marks each match with its class and the action of your project, and shows the text as the vendor would get it. Proxium does not store or log the text.
Read what it found
Matches lists each match: when, the class, the action, where in the request (such as /messages/0/content), how many times, the app and the key prefix. It never shows the value: Proxium does not store it.
Get the alerts
Alerts go to the channels of Settings › Spend alerts. Set one channel first. See Get spend alerts.
At most one alert is sent for each class and app in a short window. It says how many requests matched since the last alert:
proxium: data protection flagged 3 requests of app 'support-bot' in project 'acme' that held a credit_card value. The value is not in this alert.
What a blocked call gets
{
"error": {
"message": "blocked by egress guardrail: credit_card detected at /messages/0/content (the matched value is deliberately not echoed)",
"type": "guardrail_blocked",
"code": "guardrail_blocked"
}
}
Related pages
- Sensitive data scanning: the classes, the checks and where the value never goes.
- Get spend alerts: the channels that alerts go to.
- Errors: every error code.