PII scrubbing
PII scrubbing removes personal data from content as your organization ingests it, before the text is indexed or used in answers. Owners and Admins set the level under Settings → Security, on the Data tab, in the PII scrubbing card.
The levels
Off — no automatic scrubbing. Removing personal data from ingested content becomes your organization's responsibility.
Standard (the default) — removes high-certainty identifiers only: Social Security numbers and validated card numbers. Contact details stay; a support email in a manual is knowledge.
Strict — also removes email addresses and phone numbers, and runs an AI check that redacts sentences carrying sensitive personal context.
Removed values are replaced in the stored text with a placeholder that names what was removed: [PII-REMOVED:SSN], [PII-REMOVED:CREDIT_CARD], [PII-REMOVED:EMAIL], [PII-REMOVED:PHONE], or [PII-REMOVED:CONTEXTUAL] for a sentence the AI check flagged.
Per-source overrides
Under Per-source overrides you can pin a different level for one kind of source. Each follows the organization level by default (Inherit) or can be set to Off, Standard, or Strict. A pinned level replaces the organization level for that kind of source, so it can be higher or lower:
Website — crawled web pages.
Files — uploads, desktop sync, and drive connectors.
Media — audio, video, YouTube, and meeting notetaker transcripts.
Connectors — support, CRM, chat, and email systems.
When you add a source in the Add knowledge wizard, the Redaction section offers Also redact names, emails & phone numbers. Turning it on applies the Strict level to that source. This switch can only raise the level for that source, never lower it. Despite its label, it does not detect names (see Known limits).
Where it applies
Scrubbing runs once, at ingest, before content is split and indexed. It changes the stored text permanently; the original uploaded file, where one is kept, is not changed. It covers uploads, crawled pages, transcripts of audio and video, meeting notetaker transcripts, Slack, and documents from business-system connectors.
Changes apply to newly ingested and re-processed content. Existing documents keep their prior scrubbing until they are re-ingested. If the organization's policy cannot be read at ingest time, Records Labs falls back to Standard and marks the document so it can be found and re-processed under your real policy.
Scrubbing does not apply to what people type into chat or Help Desk conversations. Separately, secrets pasted into chat (API keys, tokens, private keys, and similar) are redacted before the message is stored. API keys and tokens inside ingested documents are not caught by PII scrubbing, so remove them before you upload.
Known limits
Scrubbing is pattern-based, so it is precise rather than exhaustive:
Social Security numbers are recognized only in the
123-45-6789form.Card numbers must look like a card (13 to 16 digits, with or without the usual grouping) and pass the checksum. Numbers right after words like "part", "model", "serial", "SKU", "item", "order", "invoice", or "PO" are left alone so product and order identifiers survive.
Phone numbers are recognized in North American formats.
The Strict AI check only examines sentences that mention terms such as salary, medical, patient, social security, or confidential, up to 25 sentences per document. If the check cannot run, the sentence is kept.
Names are not detected or removed at any level. If names must not reach the index, remove them before uploading.
When scrubbing is off, removing personal data is your organization's responsibility.