Skip to main content

Protect sensitive data

Proxium scans each request before it leaves, and flags, redacts or blocks what you choose. Sensitive data scanning explains what it finds and how.

Set what Proxium does​

  1. Open Data protection in the console.
  2. For each class, select an action: off, flag, redact or block.
  3. For redact and block, select Alert to get an alert for each match. A flag always sends one.
  4. Select Save.

The next request uses the new settings. In force shows the action that applies. If the operator set a stricter floor for a class, it shows there too.

tip

To find out first what your traffic holds, set a class to flag for a few days. Your requests go out unchanged, and Matches shows where the values were.

Add your own terms​

  1. In Your terms, type one word or phrase on each line, such as a customer name or a code name.
  2. Set the class Your terms to flag, redact or block.
  3. Select Save.

A term matches as a whole word, in any case: acme matches ACME and not acmecorp. A project keeps at most 200 terms, each at most 100 characters.

Try a text​

Paste a text in Try a text, and select Check. The console marks each match with its class and the action of your project, and shows the text as the vendor would get it. Proxium does not store or log the text.

Read what it found​

Matches lists each match: when, the class, the action, where in the request (such as /messages/0/content), how many times, the app and the key prefix. It never shows the value: Proxium does not store it.

Get the alerts​

Alerts go to the channels of Settings › Spend alerts. Set one channel first. See Get spend alerts.

At most one alert is sent for each class and app in 10 minutes. It says how many requests matched since the last alert:

proxium: data protection flagged 3 requests of app 'support-bot' in project 'acme' that held a credit_card value. The value is not in this alert.

What a blocked call gets​

403 body
{
"error": {
"message": "blocked by egress guardrail: credit_card detected at /messages/0/content (the matched value is deliberately not echoed)",
"type": "guardrail_blocked",
"code": "guardrail_blocked"
}
}