How it works
- After policy checks and the prompt injection firewall, the gateway runs the configured detector over every message’s text content,
promptandinput. - Each finding is replaced in place. Without a vault key the replacement is
[REDACTED:<TYPE>]. With a vault key it is a numbered token such as[PII_1], and the original value is stored encrypted beside the request trace. - Everything downstream sees only the redacted text: input guardrails, the cache key, the provider, the audit log and exported trace spans.
- When the model answers, the completion is scanned too. What reaches your client depends on the model’s
pii_output_mode.
Configuration
Key fields
builtin runs the in-process regex detector. http calls your detection sidecar at pii.http_url. off disables detection entirely. Any other value stops startup.The full URL the gateway
POSTs to, path included. Required when detector is http.Version name to base64-encoded 32-byte AES-256 key. Standard or URL-safe base64, with or without padding. A key that is not exactly 32 bytes stops startup rather than silently falling back to one-way redaction. Version names are 1–32 letters, digits,
- or _.The version new values are sealed with. Required when more than one key is configured.
How the completion is handled. See Outbound PII.
gateway.yaml and the environment, so a change needs a restart.
Detectors
Built-in entities
| Entity | Matches |
|---|---|
EMAIL | Email addresses |
EMIRATES_ID | UAE Emirates ID (784-YYYY-NNNNNNN-C, dashes optional) |
IBAN | IBANs, mod-97 checked |
CREDIT_CARD | 13–19 digit card numbers, Luhn checked |
AADHAAR | India Aadhaar: 12 digits in groups of four |
PAN | India PAN: five letters, four digits, one letter |
SAUDI_ID | Saudi national ID / iqama: 10 digits starting with 1 or 2 |
PHONE | International numbers starting + or 00 |
IP_ADDRESS | IPv4 addresses |
HTTP sidecar
Withdetector: http the gateway sends each text to your service and redacts the spans it returns. Use this for NER-grade detection (names, addresses, other languages).
start and end are byte offsets into text; spans outside the text are ignored. entity_type becomes the <TYPE> in the placeholder. The call times out after 10 seconds, and any non-200 status is treated as a detection failure.
Outbound PII
The completion text is always scanned and the redacted copy is what the audit log and the cache store.pii_output_mode decides what the client receives:
| Mode | Client receives | Latency |
|---|---|---|
passthrough | The provider’s response as it streams, unredacted. | No added latency. |
buffer | The full response, buffered, with PII replaced by [REDACTED:<TYPE>]. Streamed requests are replayed as a stream after the scan. | Time to first token becomes time to last token. |
Reversible redaction
With a vault key configured, each redacted value is encrypted with AES-256-GCM and stored alongside the trace, bound to its organization, trace, token and position. Values are stored only when the request body itself is recorded (see Request Logging); a request sent withX-ManyLayers-Store-Logs: false keeps no values.
Generate a key
pii.vault in the YAML.Reveal an original
A caller holding
gateway.traces.sensitive.read (Gateway admins by default) opens a trace in Request Traces and selects Show Original, or calls the API:$TRACE_ID is the X-ManyLayers-Trace-Id response header of the original request. The response holds id, request_body (tokens replaced by their values) and restored (how many changes were undone), and is sent with Cache-Control: no-store. Every attempt, allowed or denied, is written to the organization’s access log.Rotate the vault key
Rotate the vault key
Add a new version and make it current:
MANYLAYERS_PII_VAULT_KEYS="v1:<old>,v2:<new>" and MANYLAYERS_PII_VAULT_KEY_VERSION=v2, then restart. New values are sealed with v2; existing values keep decrypting with v1. Remove v1 only after every trace it sealed has aged out of audit retention — a removed version makes its values unreadable.Why Show Original can refuse
Why Show Original can refuse
The endpoint returns
409 not_reconstructable rather than a possibly wrong original when the caller’s own text already contained a [PII_n]-shaped string, when two rewrites left identical text from different originals, or when the stored body no longer matches its recorded changes. It returns 404 when the body was not recorded or nothing was redacted reversibly, and 503 pii_vault_not_configured when the service has no key.Redaction for logs only
Redaction for logs only
To keep prompts intact for the model but scrub the stored copy, set
pii.detector: off and add a logging config with redaction.pii: true. See Request Logging.Gateway redaction runs before every guardrail. A
pii guardrail adds category-level control per workspace and rule; both can run together, and the guardrail sees the already-redacted text.Next steps
Guardrails
Add per-workspace PII, secrets and regex checks on input and output.
Request Logging & Audit
Control which bodies are stored and how they are redacted.
Caching
How redacted requests form cache keys.
Prompt Injection Firewall
The check that runs just before redaction.