---
title: Sensitive Data Redaction
description: Datadog, the leading service for cloud-scale monitoring.
breadcrumbs: >-
  Docs > Datadog Security > AI Guard > Set Up AI Guard > Sensitive Data
  Redaction
---

> For the complete documentation index, see [llms.txt](https://docs.datadoghq.com/llms.txt).

# Sensitive Data Redaction

{% callout %}
# Important note for users on the following Datadog sites: app.ddog-gov.com



{% alert level="danger" %}
AI Guard isn't available in the {% placeholder "user-datadog-site-name" /%} site.
{% /alert %}


{% /callout %}

AI Guard uses Sensitive Data Scanner to identify sensitive data, such as personally identifiable information (PII), credentials, and secrets, in messages evaluated by AI Guard. Matching data can be hashed, replaced with custom text, or partially redacted before it is sent to the model. To replace each match with a label or `****`, use the **Redact** action and enter the value as the replacement text.

{% alert level="warning" %}
Sensitive data redaction is supported only with manual SDK integration. Automatic instrumentations, such as OpenAI or Anthropic, aren't supported yet: they report Sensitive Data Scanner findings, but they don't redact the messages your application sends to the model. To redact sensitive data, call the SDK directly and forward the redacted conversation returned by the evaluation. See [AI Guard SDK](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md).
{% /alert %}

## Supported SDK versions{% #supported-sdk-versions %}

| Language   | Minimum version    |
| ---------- | ------------------ |
| Python     | dd-trace-py 4.14.0 |
| JavaScript | dd-trace-js 6.13.0 |
| Java       | Coming soon        |
| Ruby       | Coming soon        |

## Setup{% #setup %}

To enable sensitive data redaction, configure redaction rules for AI Guard, enable sensitive data scanning for your service, and apply the replacements returned by AI Guard.

### 1. Configure redaction rules

Sensitive Data Scanner rules for AI Guard are configured at the organization level. To choose what data AI Guard redacts and how it is replaced:

1. Go to Security > Sensitive Data Scanner > Configuration > [AI Guard](https://app.datadoghq.com/sensitive-data-scanner/configuration/ai-guard).
1. Create or edit an AI Guard scanning group and enable the rules for the sensitive data you want to detect.

{% image
   source="https://docs.dd-static.net/images/security/ai_guard/ai_guard_sds_configuration.84a5f1ecf4b64de484db1984443b0ec6.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/ai_guard/ai_guard_sds_configuration.84a5f1ecf4b64de484db1984443b0ec6.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The AI Guard tab on the Sensitive Data Scanner configuration page" /%}

Under Action on Match, select what happens when the rule matches sensitive data:

{% image
   source="https://docs.dd-static.net/images/security/ai_guard/ai_guard_action_on_match_options.580730fdf88ee486816d54be4fd62df1.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/ai_guard/ai_guard_action_on_match_options.580730fdf88ee486816d54be4fd62df1.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="Sensitive Data Scanner Action on Match options: Hash, Redact, Partially Redact, Mask, and No Action" /%}

- **Hash**: Permanently replaces the entire matched value with a hashed token.
- **Redact**: Permanently replaces the entire matched value with replacement text that you specify.
- **Partially Redact**: Permanently obscures only part of the matched value.
- **Mask**: Hides the matched value in Datadog, but preserves the underlying value so users with permission can reveal it.
- **No Action**: Leaves the matched value unchanged.

To replace sensitive data before it is sent to the model with an exact value, select **Redact** and enter replacement text such as `[sensitive_data]` or `****`.

{% image
   source="https://docs.dd-static.net/images/security/ai_guard/ai_guard_redact_replacement_text.6c082a939456a28b70bd86fe9f5a9cf6.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/ai_guard/ai_guard_redact_replacement_text.6c082a939456a28b70bd86fe9f5a9cf6.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="The Redact action selected with a custom replacement text field" /%}

Tags categorize the finding but do not change the matched content.

{% alert level="info" %}
This configuration applies across your organization. The rules are applied only to services for which sensitive data scanning is enabled.
{% /alert %}

### 2. Enable sensitive data scanning for a service

Enabling the Sensitive Data Scanner rules for AI Guard is not sufficient on its own. After the rules are enabled, you must also enable sensitive data scanning on the AI Guard service you want to protect:

1. Go to Security > AI Guard > Settings > [Services](https://app.datadoghq.com/security/ai-guard/settings/services).
1. Edit the default policy or the policy for the service and environment you want to protect.
1. Under Sensitive data scanning, select one of the following options, then save the policy:
   - Disabled: AI Guard doesn't scan requests for sensitive data.
   - Scanning: AI Guard scans requests for sensitive data and reports the findings on the AI Guard span, but returns the messages unchanged.
   - Scanning and redacting: AI Guard scans requests for sensitive data and redacts the matches, following the action configured for each rule.

{% image
   source="https://docs.dd-static.net/images/security/ai_guard/ai_guard_sensitive_data_scanning.1a7e0cf5a8e88c4e3396761e788e8f96.png?auto=format&fit=max&w=850 1x, https://docs.dd-static.net/images/security/ai_guard/ai_guard_sensitive_data_scanning.1a7e0cf5a8e88c4e3396761e788e8f96.png?auto=format&fit=max&w=850&dpr=2 2x"
   alt="An AI Guard service policy with the Disabled, Scanning, and Scanning and redacting options for sensitive data scanning" /%}

The service policy enables or disables the complete Sensitive Data Scanner configuration for that service. Configure which data is detected and redacted on the [AI Guard configuration page in Sensitive Data Scanner](https://app.datadoghq.com/sensitive-data-scanner/configuration/ai-guard).

When Scanning and redacting is enabled, AI Guard redacts the last message of the evaluated conversation.

{% alert level="info" %}
Because the conversation context is built incrementally, AI Guard doesn't rescan the conversation history. Replacing the messages in your application with their redacted versions is the responsibility of your SDK implementation. See [AI Guard SDK](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md).
{% /alert %}

### 3. Apply redaction replacements with the SDK

When the SDK evaluates messages, the evaluation response includes a fully redacted replacement and its path for each value that a configured rule mutates. The SDK applies these replacements to a copy of the evaluated conversation and returns it with the evaluation result. Forward that conversation to the model, and keep it in your application state, so that sensitive data does not leave your application and is not reintroduced on the next turn.

AI Guard scans only the last message in each evaluation call, and uses the preceding messages as context. This includes a user prompt, assistant response, tool call arguments, or tool call result when it is the last message being evaluated. Earlier messages in the conversation are not rescanned, so the result carries the full conversation you passed in with only the last message redacted. Applying replacements does not modify your application-owned message objects.

The way you read the redacted conversation depends on the SDK language:

- [Python](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md?prog_lang=python#example-apply-sensitive-data-redaction-python)
- [JavaScript](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md?prog_lang=node_js#example-apply-sensitive-data-redaction-node-js)
- [Java](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md?prog_lang=java#example-apply-sensitive-data-redaction-java)

To turn off redaction in the tracer while keeping detection and reporting, set `DD_AI_GUARD_REDACTION_ENABLED=false` in your application environment. Evaluation still runs and findings are still reported, but the SDK returns the messages unchanged.

## Further reading{% #further-reading %}

Additional helpful documentation, links, and articles:

- [Set Up AI Guard](https://docs.datadoghq.com/security/ai_guard/setup.md)
- [AI Guard SDK](https://docs.datadoghq.com/security/ai_guard/setup/sdk.md)
- [Sensitive Data Scanning Rules](https://docs.datadoghq.com/security/sensitive_data_scanner/scanning_rules.md)
