Skip to main content

Set up protection of personally identifiable information

This article explains how to create and configure a PII (Personally Identifiable Information) protection policy in Creatio AI Studio to control how PII or other sensitive data is detected and handled before and after LLM execution in your organization.

Your PII protection customizations shall always be consistent with your organization’s guidelines and applicable data processing laws and regulations.

Example

Create a global PII protection policy that tokenizes email addresses and phone numbers in all LLM requests.

  1. Log in to Creatio AI Studio.

  2. Go to the Trust & Governance block → Policies.

  3. Click New in the top right. This opens a window.

  4. Select PII protection as the policy type.

  5. Go to the General settings & Runtime block and fill out the general settings.

    Field

    Field value

    Policy name

    A human-readable name for the policy. For example, "PII redaction."

    Scope

    To whom this policy applies. Available values:

    • "Global" — applies to all agents and LLM calls across the entire organization.
    • "Agent" — applies only to a specific agent.

    Enforcement

    What happens when a PII match is detected. Available values:

    • "Disabled" — the policy is configured but takes no action.
    • "Observe" — detects PII and logs matches without blocking or altering requests.
    • "Enforce" — actively redacts or tokenizes detected values in the payload.

    Set to "Enforce" out of the box. We recommend switching it to "Observe" first. Observe mode lets you review detection results in the decision log without affecting live LLM requests, allowing you to validate entity coverage and tune your configuration safely.

    Severity

    The severity level assigned to this policy. Set to "High" out of the box. Available values:

    • "Low"
    • "Medium"
    • "High"
    • "Critical"
  6. Go to Select which sensitive values this policy should detect before model execution block and check the boxes for each entity type for which the policy must scan. Email, Phone, and Payment card are selected out of the box. Select all entity types relevant to your compliance requirements. Unselected types are not detected or redacted, even if present in the payload.

    Sensitive value

    Description

    Email

    Standard email address patterns, for example, john.doe@creatio.com.

    Phone

    Phone numbers in national and international formats, for example, +1 312 555 0187.

    Full name

    First and last name combinations.

    Address

    Physical mailing or street addresses.

    National ID

    Government-issued ID numbers, social security numbers, and similar.

    Bank account

    Bank account and IBAN-formatted numbers.

    EIN (US Tax ID)

    Employer identification number, a unique number assigned by the IRS to identify a business entity for tax purposes in the USA.

    Payment card

    Credit and debit card numbers.

  7. Add organization-specific IDs (optional). If your organization uses internal data IDs that are not covered by the standard entity detectors, add them to the Add tenant-specific identifiers that should be detected alongside the standard entity detectors block.

    Input

    Description

    Regex patterns

    The field reads "Regex patterns — one per line, structured IDs like internal keys or case numbers." Enter one regex pattern per line, for structured IDs such as internal keys or case numbers. For example, "client_[0-9]{6}" or "lead_[A-Z]{3}-[0-9]{4}."

    Dictionary entries

    The field reads "Dictionary entries — one per line, for tenant-specific labels, reserved names, record aliases." Enter one entry per line, for organization-specific labels, reserved names, or record aliases. For example: "vip_customer_id" or "case_reference."

  8. Configure the action on match. Go to the Define how matched values are rewritten and what evidence is retained in the decision log block and select how the policy handles detected PII.

    1. Select one of the following in the Action on match field:

      Mode

      Behavior

      Mask

      Replaces detected values inline using a static placeholder label before the request is sent to the LLM. The original value is not preserved or recoverable from the payload. You can specify whether to store the original values in the audit log.

      Tokenize

      Replaces detected values using reversible placeholders, effectively hiding them from the LLM. The original values are restored in the outbound response after model execution is complete.

      Mask mode is irreversible. Once a value is masked in the inbound payload, the LLM never receives the original data, and it cannot be restored from the request. Use "Tokenize" mode if the original value must be available in the model response or downstream processing. Do not switch from "Mask" mode to "Tokenize" mode on a live policy without reviewing audit log entries first.

    2. Specify how matched values must appear in the payload sent to the LLM in the Placeholder style — how matched values read in the payload field, available when the "Mask" mode is selected. Out of the box, "Entity label."

    For example, you set up tokenizing of emails and phone numbers:

    Mode

    Text

    Before

    Customer John Doe can be reached at john.doe@tenant.com or +1 312 555 0187. Refund account is GB29 NWBK 6016 1331 9268 19.

    After (Mask)

    Customer John Doe can be reached at [EMAIL] or [PHONE]. Refund account is GB29 NWBK 6016 1331 9268 19.

    After (Tokenize)

    Customer John Doe can be reached at john.doe@tenant.com or +1 312 555 0187. Refund account is GB29 NWBK 6016 1331 9268 19.

  9. Configure runtime scan options at the bottom of the Define how matched values are rewritten and what evidence is retained in the decision log block.

    Toggle

    Description

    Pre-flight request scan

    Runs the PII detector on the inbound payload before the LLM call. Required for inbound payload protection. Toggled on out of the box and non-editable.

    Post-flight response scan

    Runs a second detection pass on the LLM-generated response before it is returned to the user. Useful for catching PII re-generated or inferred by the model. Toggled off out of the box.

    Hide original values from audit log

    Stores only the masked version of detected PII in the decision log, keeping original values out of audit storage. Toggled on out of the box. Keeping it turned on affects your ability to review original data during policy audits or compliance reviews. Once this setting is active and a decision is logged, the original value cannot be retrieved from the audit log.

  10. Set where the policy applies. The Active environments card reads "Active in all environments" out of the box. To test the policy in one environment before it applies elsewhere, click Add environment and select that environment. When the environment of a run cannot be determined, a policy limited to specific environments still applies to that run. With the "Agent" scope, add at least one agent in the Assigned agents card. Creatio AI Studio does not save an agent-scoped policy without one and reports "Select at least one target agent."

  11. Review the before-and-after preview, which shows how a sample payload reads once the policy has run.

  12. Review all settings across the page and click Create policy.

As a result, Creatio AI Studio applies the PII protection policy to all governed LLM requests that fall within the configured scope, and the Policies list shows it with the "Observing" or "Enforcing" status. You can monitor the policy live in the Trust & Governance section.

Creatio AI Studio ships with a Default (system) PII policy that is already active, global, and set to "High." Your own global policy overrides it. To turn the built-in policy off without creating a policy, open it on the Policies page, click Disable default protection, and confirm. Re-enable default protection restores it.

Verify that the policy is masking​

A PII policy runs before the model, so the proof is in the model input rather than the agent's reply. Send a message containing obviously fake values, read the model input in the live-preview trace, and confirm the matching decision was recorded. You can also open the run in the Observability section: in its Execution timeline, each PII protection check appears next to the model call it preceded. Learn more: Review policy decisions.


See also​

Review policy decisions

Monitor governance activity

Configure a HITL policy

Creatio.ai overview