You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit 34e1220
Browse filesBrowse the repository at this point in the historyBrowse files
|**Feature / Initiative**|[UIESTRAT-229: Enable collection & upload of Observability OTel data stripped of PII/sensitive data](https://redhat.atlassian.net/browse/UIESTRAT-229)|
384
+
385
+
The three core inference spans (`/v1/query`, `/v1/streaming_query`, `/v1/responses`) carry
386
+
raw, un-hashed request/response content for evaluation, relaxing the original metadata-only rule
387
+
(**R7**; §Why "Safe observability by design"). Raw content
388
+
can contain PII, so it must be detected and redacted before it leaves LCORE. **This addendum
389
+
defines that redaction strategy.**
390
+
391
+
### The problem
392
+
393
+
Once spans carry raw text (prompts, responses, RAG chunks, tool I/O), that text
394
+
can contain PII. So it must be scrubbed of PII before the span leaves LCORE — before OTLP export
395
+
to a hosted backend such as LangFuse, and before any cross-org sharing. (This is a portfolio-wide
396
+
obligation from Red Hat's AI Assessment (AIA/PIA) process, not specific to LCORE.) We do this by
397
+
**detecting and redacting PII**.
398
+
399
+
### The redactor we want
400
+
401
+
A shared, production-proven redactor already exists:
402
+
`data-anonymizer` (used by Ask Red Hat et all). It is
403
+
Presidio-based and detects email, hostname, IP (v4/v6), location, organization, person, phone,
404
+
and URL. Reusing it — rather than each team writing its own — is the goal. See the
0 commit comments