Runfile
EU-WEST-1Northwood Bank
Search runs, controls, members, keys…⌘K
production4.8M / 12M eventsSPSahil Patel
Northwood BankGovernRedaction policy

Redaction policy

Drives the SDK's classify / redact / tokenize / encrypt decisions at the boundary. Every save creates a new signed version; old versions continue to apply to evidence captured under them.

Editor
Active policy
safe-banking-v8
Signed byAnders Møller (DPO) · Marta Schreiber (CCO)
Published17:02 · 22 May 2026
Applies toall new events
10 rules · 8 built-in · 2 custom
PII classTreatmentVault retentionResolverMFAJustificationPattern / classifierEdit
person_nametokenize180 daysVault Resolverrequiredrequiredner · NameEntity v3
us_ssntokenize + encrypt7 yearsVault Resolverrequiredrequired^\d{3}-\d{2}-\d{4}$
emailtokenize90 daysVault ResolverrequiredoptionalRFC 5322 strict
phonetokenize180 daysVault ResolverrequiredoptionalE.164
addresstokenize180 daysVault Resolverrequiredrequiredlibpostal v2
dobtokenize7 yearsVault ResolverrequiredrequiredISO 8601 strict
account_numbertokenize + encrypt7 yearsVault ResolverrequiredrequiredIBAN · Luhn account fmt
free_textLLM redact90 daysVault Resolverrequiredrequiredclassifier · v4 prompt
nb_internal_idcustomtokenize5 yearsVault ResolverrequiredrequiredNB-\d{8}
loan_applicationcustomtokenize + encrypt10 yearsVault ResolverrequiredrequiredLA-\d{12}
Customer-specific patterns
2 additional classes beyond the 8 built-in. Patterns reviewed by Anders Møller.
Token vault
Per-class retention. Resolver = role permission overlay. Every resolution logs MFA + justification to the audit-of-audit log.
Versioning
Events captured under v8 stay tagged v8 even after v9 publishes. Auditors can re-read evidence under the policy that produced it.
Version history · signed
WorkingHistoricalTrial
VersionTagAuthor / signerPublishedChangesActions
v9draftAnders Møllerin progress · started 2h ago+ device_geohash class · adjust SSN retention
v8activeMarta Schreiber / Anders Møller17:02 · 22 May 2026+ free_text LLM redaction · tightened address NER
v7historicalMarta Schreiber12 Apr 2026initial production policy
v6historicalAnders Møller04 Mar 2026pattern updates
Every save creates a signed version. DPO sign-off captured as an audit event; signers list above is what auditors see in the workpaper bundle.