Skip to main content Announcing Tool Gateway MCP: the universal MCPRead the announcement
PII Redaction for Tool Calls and Logs

October 2026

PII Redaction for Tool Calls and Logs

HR, support and finance records carry SSNs, phone numbers and email addresses, often in free text that a field rule can’t reach. PII Redaction replaces each one with [REDACTED] in what the agent sends and what tools return, and in request and response bodies before Advanced Logs stores them. Detection runs on StackOne’s own model, inside StackOne’s runtime.

In Permission Policies, Redact PII sits next to Semantic rule, and both capabilities are backed by a model.

What’s new

  • Redact PII policy rule. A new capability in Policies removes the classes an admin selects from tool inputs and outputs: email address, phone number, social security number and credit card number. A rule covers the whole project or specific linked accounts.
  • Only the match changes. Redaction replaces the matched span, so a ticket description keeps its text and loses the phone number inside it.
  • Block on inputs. Set the rule to Block to refuse a call whose inputs contain the chosen PII, before anything reaches the provider. PII found in a response is still redacted.
  • Record references and keys kept. Classes the rule doesn’t name pass through unchanged, so employee numbers, record UUIDs and API keys stay available for the agent’s next call.
  • Monitor only first. A policy in Monitor only records PII detections without changing the call.
  • Redaction metadata for callers. When a rule removes something from a response, the tool result carries policyMetadata.redactedClasses over REST and MCP, and the policy log records the call with the effect redacted.
  • Advanced Logs setting. The Redact personal information (PII) toggle in Project Settings > Advanced Logs replaces personal data in the request and response bodies of action calls before the log is written. Path, status code, connector and linked account stay intact, so logs remain searchable.
  • In-process model. After a pattern pass, a 23MB token classifier trained by StackOne reads the text in the same process that runs the action. No third-party detection service sees the data, and detection adds milliseconds rather than a network hop.

What the agent receives

On the output side, a Redact PII rule runs on the tool response after Defender has scanned it and before the agent receives it. With Redact, the rule replaces each match and lets the call continue, so the response keeps its structure:

{
  "isError": false,
  "result": {
    "data": {
      "id": "4182",
      "employeeNumber": "E-10482",
      "workEmail": "[REDACTED]",
      "notes": "Call [REDACTED] about the W-4."
    }
  },
  "policyMetadata": {
    "result": "partial",
    "maskedFields": [],
    "redactedClasses": [
      { "class": "email", "level": "project" },
      { "class": "phone_number", "level": "project" }
    ]
  }
}

On the input side, Redact replaces matches in the arguments the agent sends, and Block refuses the call before it reaches the provider.

The Advanced Logs setting works separately. It is on or off for the whole project, applies to new logs only, and covers every kind of personal data the scan detects, including names, postal addresses and government ID numbers.

Detection accuracy

Span F1 on 1,000 held-out examples per dataset, compared with Presidio, the open-source baseline. Connector PII is the closest match to what agents read through StackOne:

DatasetStackOnePresidio
Connector PII (connector field values)98.7%63.8%
OpenPII (synthetic prose)89.9%67.3%
Nemotron-PII (business documents)95.3%69.4%
Privy (JSON, SQL and XML payloads)98.9%51.3%

Generic detectors often mistake order numbers, record references and timestamps for personal data, and redacting one breaks the agent’s next call. On 500 connector field values containing no personal data, StackOne’s model flagged 0.4% as PII and Presidio flagged 51.6%.

The OpenPII row uses 1,000 English validation rows of OpenPII 1.5M by Ai4Privacy / Ai Suisse SA (CC BY 4.0), measured on 8 October 2026. The other rows were measured on 30 September 2026.

StackOne’s model was trained on the train splits of Connector PII, Nemotron-PII and Privy, among other data, and never on OpenPII. Connector PII is StackOne’s own dataset, and no test example appears in the training data.

Getting started

Create a policy under Project Settings > Policies, add the Redact PII capability, select the classes and choose Redact or Block. Start the policy in Monitor only, which records PII detections without changing calls, then switch it to Enforce.

The PII Redaction docs cover both surfaces, their limits and setup. The PII Redaction page shows tool responses before and after redaction, next to the benchmark. Redact PII sits beside the tool and field rules from the Policies release, and Observability covers the Advanced Logs setting.

Put your AI agents to work

All the tools you need to build and scale AI agent integrations, with best-in-class connectivity, execution, and security.