Skip to main content

Protect sensitive data

Proxium scans each request before it leaves, and flags, redacts or blocks what you choose. Sensitive data scanning explains what it finds and how.

Set what Proxium does​

Each project starts on the default policy of the gateway. On proxium.tech, five classes are on redact, with an alert:

ClassFinds
credit_cardCard numbers
card_securityCard expiry dates and security codes
ibanIBANs
national_idNational ID numbers
credentialAPI keys, tokens and private keys

The other classes are off: email addresses, phone numbers, IP addresses, your own terms and prompt injection. The screen says This project uses the default policy until you change a class.

  1. Open Data protection in the console.
  2. For each class, select an action: off, flag, redact or block.
  3. For redact and block, select Alert to get an alert for each match. A flag always sends one.
  4. Select Save.

The next request uses the new settings. In force shows the action that applies. If the operator set a stricter floor for a class, it shows there too.

When you change a class, the classes become the project's own. A class that you did not change keeps the value of the default. A save of Your terms alone keeps the project on the default policy.

The AI check for secrets​

The classes above find values with a known format. A password such as "hunter2" has none. The AI check reads each request and finds passwords, keys and other secrets of any shape. It can flag or block a request. It cannot redact, because it says that a secret is there, not where.

The AI check is part of some plans. A project can also use it with its own TypeSafe key. It is off until you select an action for Secrets (AI check), and each request then takes a short moment longer.

Go back to the default policy​

  1. Open Data protection.
  2. Select Reset to default, and confirm.

The classes go back to the default policy of the gateway. Your terms stay. The API call is DELETE /api/teams/{slug}/guardrails.

tip

To find out first what your traffic holds, set a class to flag for a few days. Your requests go out unchanged, and Matches shows where the values were.

Add your own terms​

  1. In Your terms, type one word or phrase on each line, such as a customer name or a code name.
  2. Set the class Your terms to flag, redact or block.
  3. Select Save.

A term matches as a whole word, in any case: acme matches ACME and not acmecorp. A project keeps at most 200 terms, each at most 100 characters.

Try a text​

Paste a text in Try a text, and select Check. The console marks each match with its class and the action of your project, and shows the text as the vendor would get it. Proxium does not store or log the text.

Read what it found​

Matches lists each match: when, the class, the action, where in the request (such as /messages/0/content), how many times, the app and the key prefix. It never shows the value: Proxium does not store it.

Get the alerts​

Alerts go to the channels of Settings › Spend alerts. Set one channel first. See Get spend alerts.

At most one alert is sent for each class and app in a short window. It says how many requests matched since the last alert:

proxium: data protection flagged 3 requests of app 'support-bot' in project 'acme' that held a credit_card value. The value is not in this alert.

What a blocked call gets​

403 body
{
"error": {
"message": "blocked by egress guardrail: credit_card detected at /messages/0/content (the matched value is deliberately not echoed)",
"type": "guardrail_blocked",
"code": "guardrail_blocked"
}
}