Enterprise
Overview
Visitors type things into a chat that were never meant to be kept: an email address, a card number, a bank account. With PII Redaction on, that data is detected and masked at the moment the message arrives. What lands in your chat logs is the masked version — the original text is never written anywhere and cannot be recovered afterwards, by you or by us.
How It Works
- The visitor sends a message - the AI reads it as typed and answers normally
- The reply is generated, then both sides are masked - detected personal data is replaced with a mask like [email redacted]
- Only the masked text survives - storage, emails, exports and webhooks all receive the same masked version
- Every website is separate - you choose the categories per website
Stored everywhere as
[email redacted]
What Can Be Masked
- Email addresses - anything shaped like an email address
- Payment card numbers - 13 to 19 digits, checksum-verified, with or without spaces
- IBAN bank accounts - validated by country code and checksum
- Phone numbers (international format) - numbers with a country prefix such as +44 20 7946 0958; domestic formats are left alone
Each category has its own switch, so you can mask card numbers while still letting emails through for lead capture.
What about phone numbers?
A number with a country prefix, such as +44 20 7946 0958, is unmistakably a phone number and is masked safely. Domestic formats cannot be verified — 020 7946 0958 looks exactly like an order number or a tracking code, and masking those would corrupt the support conversations your chatbot handles every day. That is why the phone category covers international formats only. Nothing is masked on a guess.
One Rule, Every Surface
Because masking happens once, at the moment of storage, every place that shows conversation content shows the same masked text:
- Chat logs - in your dashboard
- Email notifications - AI notifications, escalations and daily reports
- Analytics and previews - anywhere a message is quoted
- Exports and transcripts - CSV downloads and conversation transcripts
- Webhooks and the API - your own endpoints receive the masked version too
There is no unmasked copy sitting behind any of these — the masked version is the only version that exists.
Turning It On
- Open the PII Redaction page from your dashboard
- Switch it on and pick the categories you want masked
- Send a test message from the dashboard test chat — masking applies there too, so you can see it work
The change takes effect on the next message. There is nothing to install and no change to your widget code.
Good To Know
- Answers are unaffected - the AI sees the current message as typed and can act on it; only what gets stored is masked
- Follow-up questions about masked data - in later messages the AI sees the masked history, so it may ask the visitor to repeat details from earlier turns
- The contact form is exempt - an email submitted through the lead capture form your chatbot shows is a deliberate submission and is saved as a lead
- Tickets and bookings keep working - an email given for a support ticket or a booking is a deliberate contact request and is saved with it; only card numbers or IBANs pasted into their text are masked
- Images are not scanned - a photo of a card is stored as an image, not as text
- Existing conversations are not rewritten - masking starts with the next message
Email masking and lead capture do not mix
If a visitor types their email into the conversation, lead capture cannot save an address it never sees. Keep the email category off if collecting emails from chat is part of how you use Asyntai — or rely on the contact form, which is exempt.
Note: PII Redaction is part of an Enterprise agreement. Email [email protected] and we will walk you through it.