Skip to content

PII Masking

Choose presets and categories per API key to detect and mask sensitive data in API calls.

PleumRouter detects and masks selected personal-data categories in real time before data is sent to an AI provider. Each key can keep a preset or a category combination suited to its use. This feature does not replace data minimization or your organization’s compliance review.

Key features and detection targets#

What gets detected and masked (e.g. [MASKED_PHONE]) is chosen by the categories on the API key. Older keys with no category setting use their account-profile default. A finance, healthcare, or government profile — or an industry setting — retains its required categories, while the remaining categories stay key-configurable.

Standard preset (default for regular keys)

  • Contact numbers: mobile and landline phone numbers
  • Email: email addresses (partially masked)
  • Card numbers: credit and debit card numbers
  • Resident registration number (RRN): Korean RRN and foreigner registration numbers (13-digit format)
  • Passport number: old and next-generation Korean passport numbers
  • Driver license number: Korean driver license numbers (2-2-6-2 format)

Required protection for regulated profiles and industries — in addition to the above

  • Bank account number: finance profile (including hyphenated formats)
  • Patient ID, medical record number, health insurance number: healthcare profile
  • Military ID and CI/DI: government and applicable presets
RRNs, foreigner registration numbers, passport numbers, and driver-license numbers are in the standard preset. A regular key can adjust categories when needed, but a regulated profile or industry setting keeps required categories enabled on the server. Detection is format-based, so minimize sending sensitive data when possible.

Per-API-key presets and categories#

Choose Off, Minimal, Standard, Finance, Healthcare, Government, or Strict, or compose categories directly in the dashboard.

How to configure: On the dashboard's API Keys management page, open "PII Masking" for an issued key and choose a preset or categories. Keys with a regulated profile or industry setting cannot turn off masking or remove their required categories.

PIPA compliance#

Masking selected categories before data is sent to overseas AI providers can help reduce sensitive-data exposure. Detection depends on the selected profile and format, so minimize sensitive-data sharing and perform your own legal and compliance review.