Skip to content

Personal data

What a model sees when the organisation redacts personal data, and what your code gets back.

Redaction is a policy the organisation switches on, separately for outside providers and for models on its own machines. When it is on, the server finds personal data, such as names, email addresses, phone numbers, IBANs, card numbers and places, before a request reaches a model.

Two modes

Mode The model sees The answer you get
Redact Draft a reply to <PERSON> about invoice 4471. What the model wrote, placeholders included
Tokenise Draft a reply to [PERSON_1] about invoice 4471. The real values put back, streamed or whole

Results from document search and from attachments are handled the same way.

Tools on the server

Each MCP server registered on Fadenstack has its own setting: allow puts the real values back before the tool is called, redact gives the tool the placeholders, and block refuses a call that contains personal data. See MCP servers.

What your code is told

  • With the extra events switched on, the server sends a faden.pii event with the kinds of data found and how many, never the data itself. See Events.
  • An agent may let the user switch between the two modes, if its version allows it. The SDK then sends the user's choice.
  • If redaction is required but cannot run, the request fails with an error rather than going out unredacted, unless the organisation's policy says to let it through or to send it to its own machines instead.