dtwo Policy Store

Policies tagged "gdpr-ccpa"

airtable · egress

Airtable: Redact PII in Record Reads

Scans the responses of the Airtable record-read tools — the calls that return row fields values — and rewrites high-confidence PII shapes to a fixed…

airtableredact-piipiidlpredactionegresssoc2gdpr-ccpa

asana · egress

Asana: Redact PII in Task & Comment Reads

On the Asana MCP read path, this transform scans the free-text business fields that ride back in task, comment/story, and status-update responses — notes,…

asanaredact-piipiidlpredactionegresssoc2gdpr-ccpa

bigquery · egress

BigQuery: Redact PII in Query Results

Scans the content returned by BigQuery's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…

bigqueryredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

ms365 · ingress

Block Agent Email to External Recipients

Blocks agent-initiated Microsoft 365 email sends when any recipient address falls outside a corporate-domain allowlist.

ms365guard-external-sendingressemaildlpsoc2hipaagdpr-ccpa

bigquery · ingress

Block BigQuery Exfiltration and Cross-Project Writes

Inspects the raw GoogleSQL string carried by BigQuery SQL tools and denies any statement that moves data out of the tenant's own project — even when the call…

bigqueryguard-warehouse-exportingresssqlexfiltrationsoc2pci-dssgdpr-ccpa

snowflake · ingress

Block Bulk Export & External Staging (Snowflake)

Blocks Snowflake SQL-execution tool calls whose query text moves whole tables off the Snowflake perimeter — bulk export to cloud storage or a stage, and…

snowflakeguard-warehouse-sqlexportexfiltrationingresssoc2pci-dssgdpr-ccpa

google-calendar · ingress

Block Calendar Invites to External Attendees

Denies Google Calendar event-write tool calls — create event / create-event, update event / update-event, and the consolidated manage event — whenever any…

google-calendarguard-external-sendingresscalendarsoc2hipaagdpr-ccpa

zapier · ingress

Block External Sends Hidden in Zapier Instructions

Every Zapier MCP tool — in both the agentic and classic modes — accepts a free-text instructions string that Zapier's server-side AI uses to fill any…

zapierguard-external-sendingressemailsoc2gdpr-ccpa

zoom · ingress

Block External Team Chat Invites & Members

Stops a Zoom Team Chat agent from pulling external parties into the organization's chat surface.

zoomguard-external-sendingressteam-chatsoc2gdpr-ccpahipaa

dropbox · ingress

Block Public Dropbox Share, Download, and File-Request Links

Denies, by default, the Dropbox tools that turn an internal file into an internet-visible resource in a single call — before the request ever reaches Dropbox:

dropboxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa

google-calendar · ingress

Block Public Visibility & Guest Delegation

Blocks Google Calendar create and update event calls that would expose the event to the world or hand control of it to guests.

google-calendarguard-public-exposureingresssoc2gdpr-ccpa

box · egress

Box: Redact PII from File Content on Egress

Scans the responses of Box content-returning tools and rewrites personally identifiable information to fixed redaction tokens before the response reaches the…

boxredact-piipiiphidlpredactionegresssoc2hipaagdpr-ccpa

docusign · egress

Cap Docusign Directory and Document Egress

Bounds the two largest data-out channels in the Docusign MCP landscape:

docusigncap-bulk-exportpiidata-minimisationegresssoc2gdpr-ccpa

glean · ingress

Cap Glean Bulk Search Export

Clamps the bulk-export parameters on Glean search calls before they reach the Glean MCP server, so a single agent request cannot pull an entire indexed…

gleancap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa

google-drive · ingress

Cap Google Drive Search & Listing Page Sizes

Clamps the page size of Google Drive search and listing calls to a documented cap (25 results per call).

google-drivecap-bulk-exportdata-minimizationingresssoc2hipaagdpr-ccpa

intercom · ingress

Cap Intercom Contact Enumeration

caller is a CRM admin); clamp page size on everything else; allow the rest

intercomcap-bulk-exportcontact-enumerationdlpingresssoc2hipaapci-dssgdpr-ccpa

quickbooks · ingress

Cap QuickBooks Bulk Search Exports

Clamps the bulk-read levers on every QuickBooks Online search tool so an agent cannot pull the entire general ledger — or a full customer, vendor, or…

quickbookscap-bulk-exportbulk-exportdlpingresssoc2pci-dssgdpr-ccpa

airtable · ingress

Clamp Bulk Airtable Record Reads

Airtable bases routinely hold CRM contacts, applicant-tracking pipelines, customer/financial trackers, and — on HIPAA-eligible Enterprise plans — health-ops…

airtablecap-bulk-exportingresssoc2gdpr-ccpa

airtable · ingress

Confine Airtable Agent to Allowlisted Bases

An Airtable OAuth grant (or Personal Access Token) with the workspacesAndBases:read scope spans the entire workspace — every base the connected identity can…

airtablefence-sensitive-scopesingresssoc2gdpr-ccpa

confluence · ingress

Confluence: Deny Org-Wide & Public Publication

Stops a prompt-injected or erring agent from broadcasting Confluence content org-wide or to anonymous external readers.

confluenceatlassiandeny-public-exposurepublicationgovernanceingressfinserv-commseu-ai-actsoc2gdpr-ccpa

confluence · egress

Confluence: Redact PII from Page & Comment Responses

Scans the responses of Confluence page, comment, and search read tools and rewrites personally identifiable information to fixed redaction tokens before the…

confluenceatlassianredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

databricks · egress

Databricks: Mask Cardholder PANs in Responses

Masks payment-card numbers (PANs) in Databricks tool responses before the agent receives them.

databricksmask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa

databricks · egress

Databricks: Redact PII in Tool Responses

Scans the response payloads of the Databricks MCP tools that carry lakehouse data back to the agent and rewrites personally identifiable information to fixed…

databricksredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

gmail · ingress

Deny Agent Email Sends to External Recipients

Denies Gmail send-class tool calls when any recipient in to, cc, or bcc falls outside a documented corporate-domain allowlist.

gmailguard-external-sendingressemailsoc2hipaagdpr-ccpa

docusign · egress

Docusign: Redact SSN, Bank & Card Values on Egress

Scans the responses of Docusign envelope- and agreement-reading tools and rewrites high-confidence regulated identifiers before the response reaches the…

docusignredact-piitab-valuespiiphipandlpredactionegresssoc2gdpr-ccpa

dropbox · egress

Dropbox: Redact PII, PANs, and Secrets in File Content

Scans the responses of the Dropbox file-content read tools and sanitises the returned text before it reaches the agent.

dropboxredact-contentredact-piimask-pansecretspiidlpegresssoc2hipaagdpr-ccpa

confluence · ingress

Fence Confluence Reads & Search to Non-Restricted Spaces

Fences a configurable set of restricted Confluence spaces (placeholder keys: HR, LEGAL, SEC) out of the agent's read and search paths unless the caller's IdP…

confluenceatlassianfence-sensitive-scopesaccess-controlingresssoc2hipaagdpr-ccpa

glean · ingress

Fence Glean Search by Datasource

Glean's search tool fans out across every system the tenant has indexed (Drive, Confluence, Slack, Jira, Gmail/Outlook, GitHub, Salesforce, Gong, HR…

gleanfence-sensitive-scopesaccess-controldatasourceingresssoc2hipaagdpr-ccpa

gusto · ingress

Fence Gusto Compensation & Payroll Reads

Denies the highest-sensitivity Gusto read tools unless the caller's IdP-asserted groups include the placeholder group hr-payroll-admins.

gustofence-hr-and-credit-scopecompensationpayrollingresssoc2gdpr-ccpa

intercom · ingress

Fence Intercom Contact & Company PII Reads

Gates Intercom's structured-PII read surface — customer contact and company profiles — by IdP group.

intercomfence-sensitive-scopescontact-readspiiingresssoc2hipaapci-dssgdpr-ccpa

netsuite · ingress

Fence NetSuite HR & Payroll SuiteQL Queries

Fences the single biggest exfiltration surface on the NetSuite MCP server — ns runCustomSuiteQL, which runs arbitrary read-only SuiteQL across the entire ERP.

netsuitefence-sensitive-scopesingressgdpr-ccpasoc2

notion · ingress

Fence Notion Member Directory to Admin & IT

Denies calls to the Notion member-directory tool (notion-get-users, matched by the -get-users suffix) unless the caller's IdP groups include an admin or IT…

notionfence-sensitive-scopesaccess-controlpiiingresssoc2gdpr-ccpa

bigquery · ingress

Fence Regulated BigQuery Datasets by Group

Fences customer-designated regulated BigQuery data domains by data-domain IdP group, at ingress, before any statement or metadata lookup reaches BigQuery.

bigqueryfence-sensitive-scopesingressrbacsoc2hipaapci-dssgdpr-ccpa

google-drive · ingress

Fence Restricted Google Drive Files and Folders

Fences an admin-maintained denylist of restricted Google Drive file and folder IDs — HR records, M&A deal rooms, board packs, payroll — off the agent channel:

google-drivefence-restricted-folderssensitive-scopesingresssoc2hipaagdpr-ccpa

box · ingress

Fence Sensitive Box Folders by IdP Group

Fences pinned sensitive Box subtrees (HR, Finance, Legal, …) by ID.

boxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

databricks · ingress

Fence Sensitive Databricks Schemas

Fences off the most sensitive lakehouse namespaces from agents on the read side of Databricks.

databricksfence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

dropbox · ingress

Fence Sensitive Dropbox Paths by Team

Fences protected Dropbox subtrees by path prefix . Dropbox addresses files and folders by a root-relative path (/Finance/2026/payroll.

dropboxfence-sensitive-scopesingresssoc2hipaagdpr-ccpa

monday · ingress

Fence Sensitive monday Boards by IdP Group

monday boards are schemaless business databases: HR/recruiting boards (candidate PII), CRM/deal boards (financial), and IT/security trackers routinely live…

mondayfence-sensitive-scopesingresssoc2gdpr-ccpa

servicenow · ingress

Fence Sensitive ServiceNow Tables

Fences off the most sensitive ServiceNow tables from two routes that reach them:

servicenowfence-sensitive-tablespiiingresssoc2hipaapci-dssgdpr-ccpa

snowflake · ingress

Fence Snowflake Sensitive Schemas by Data Domain

Fences customer-designated sensitive data domains inside a Snowflake warehouse by inspecting the SQL text the agent is about to run — not by tool name, which…

snowflakefence-sensitive-scopesingresssoc2hipaapci-dssgdpr-ccpa

tableau · ingress

Fence Tableau Datasource Scope

Tableau's MCP server is a warehouse proxy: query-datasource runs a VizQL Data Service (VDS) query and returns raw row-level data — PII, PHI, payroll,…

tableaufence-sensitive-scopesaccess-controldatasourceingresssoc2gdpr-ccpa

asana · ingress

Fence Writes to Sensitive Asana Projects

Asana is routinely used for HR (hiring, performance, offboarding), legal, M&A, and incident work; those project bodies, comments, custom fields, and status…

asanafence-sensitive-scopesingresssoc2gdpr-ccpa

zoom · ingress

Fence Zoom Agentic Search to Native Corpora

Constrains Zoom's agentic-search tool ( search zoom) so it can only reach Zoom-native content.

zoomagentic-searchconstrain-aggregatoringresssoc2gdpr-ccpa

google-drive · ingress

Gate Google Drive Writes to an Authorized IdP Group

Baseline least-privilege policy for Google Drive MCP traffic.

google-driverole-gate-writesleast-privilegeingresssoc2gdpr-ccpa

zoom · ingress

Gate Zoom Transcripts & Recordings by Group

Gates retrieval of Zoom meeting transcripts, AI Companion summaries, and next-steps on the connector's core egress tools, enforcing minimum-necessary access:

zoomguard-transcriptsingresshipaagdpr-ccpasoc2

glean · egress

Glean: Redact PII from Read-Tool Responses

Scans the responses of Glean's content-returning read tools and rewrites high-confidence PII to fixed redaction tokens before the response reaches the…

gleanredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

gmail · ingress

Gmail Cap Bulk Export

Throttles mass-harvesting of a mailbox by capping the per-call blast radius of the two Gmail MCP surfaces that return many full email bodies at once:

gmailcap-bulk-exportdata-minimisationingresssoc2hipaagdpr-ccpa

gmail · ingress

Gmail: Role-Gated Writes (Read-Only Default)

Makes Gmail read-only by default on the MCP path. Verified read tools pass for everyone.

gmailrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

google-drive · egress

Google Drive: Redact PII from File Content

Scans the responses of the content-returning Google Drive tools — file reads, downloads, and Docs/Sheets/Slides content fetches — and rewrites personally…

google-driveredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

box · ingress

Guard Box Share Links and External Collaborations

Blocks the externally-visible Box sharing surface — the riskiest Box surface an agent can touch — before the call ever reaches Box:

boxguard-share-linkssharingexternal-sharingingresssoc2hipaagdpr-ccpa

power-bi · ingress

Guard DAX Whole-Table Dumps in Power BI

Power BI semantic models front the warehouse: a model imports or DirectQueries lakehouse/warehouse tables — finance, HR, customer PII.

power-biguard-warehouse-sqlingressdaxexfiltrationsoc2gdpr-ccpa

docusign · ingress

Guard Docusign External Recipients

Blocks Docusign envelope-creation and recipient-update tool calls when any recipient email address has a domain outside the configured counterparty allowlist.

docusignguard-external-sendingresssoc2gdpr-ccpa

ms365 · ingress

Guard OneDrive/SharePoint Share Links

Stops agents from opening OneDrive/SharePoint files to the whole internet. It guards the two Microsoft 365 sharing tools:

ms365share-linkssharingingresssoc2iso27001-nisthipaagdpr-ccpa

gusto · ingress

Gusto Cap Roster Export

Throttles full-roster exfiltration on Gusto's two broad outbound list tools — list company employees and list company contractors — by rewriting their…

gustocap-bulk-exportpiidata-minimisationingressgdpr-ccpasoc2

gusto · egress

Gusto: Redact Financial IDs in Responses

Instantiates PF-02 (redact-pii-egress) on the Gusto read path.

gustoredact-pii-egressredact-piipiifinancial-piidlpredactionegresssoc2gdpr-ccpa

hubspot · ingress

HubSpot Cap Bulk Export

Clamps the page size of HubSpot bulk-read tool calls before they reach the HubSpot MCP server, so a single agent request to a covered bulk-read tool can…

hubspotcap-bulk-exportpiidata-minimisationingresssoc2hipaapci-dssgdpr-ccpa

hubspot · ingress

HubSpot Read-Only

Makes the HubSpot connection read-only by blocking the write tool.

hubspotaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpa

hubspot · egress

HubSpot Redact PII

Redacts sensitive contact information from HubSpot tool responses before they reach the caller.

hubspotpiidlpredactionegresssoc2hipaagdpr-ccpa

hubspot · ingress

HubSpot Role-Gate Writes

Gates every HubSpot write tool behind an IdP group: callers whose JWT groups claim contains crm-writers may create and update CRM records; everyone else gets…

hubspotrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

intercom · egress

Intercom: Mask Card Numbers in Conversation Responses

Masks payment-card numbers (PANs) in Intercom conversation content returned to agents by the conversation- and free-text-returning read tools.

intercommask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa

intercom · egress

Intercom: Redact PII from Conversation & Contact Reads

Scans the free-text returned by Intercom's conversation- and contact-read MCP tools and rewrites high-confidence personal identifiers and credential shapes…

intercomredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

jira · ingress

JIRA: Cap Field and Result Exposure on Reads

Narrows the breadth of JIRA read requests before they run, on the two read surfaces that can pull large amounts of issue data into model context:

jiraatlassiancap-bulk-exportdata-minimisationingresssoc2gdpr-ccpa

jira · ingress

JIRA: Deny Sensitive Project Search and View

Keeps issues that belong to a configurable set of "sensitive" JIRA projects out of read access through the JIRA MCP server.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

jira · ingress

JIRA: Protect Sensitive Projects from Writes

Blocks write operations against issues that belong to a configurable set of "sensitive" JIRA projects.

jiraatlassianaccess-controldata-protectioningresssoc2gdpr-ccpaiso27001-nistfinserv-comms

jira · egress

JIRA: Redact Sensitive Information from Issue Views

Redacts sensitive content from the responses of JIRA issue-view tools before they reach the caller.

jiraatlassianpiisecretsdlpredactionegresssoc2gdpr-ccpaiso27001-nist

linear · egress

Linear: Redact Customer Revenue and Contacts

Masks commercial and contact identifiers in the responses of Linear's Customers read tools before they reach the agent.

linearredact-piipiidlpredactionegressgdpr-ccpasoc2

gmail · egress

Mask Card Numbers in Email Content Read by Agents

Masks payment-card-number (PAN) shapes in email content returned to agents by Gmail mailbox-read tools.

gmailmask-pan-egressegressemailcardholder-datadlpsoc2pci-dssgdpr-ccpa

ms365 · egress

Microsoft 365: Redact PII from Mail, Files & Transcripts

Scans the responses of the highest-density PII read surfaces in Microsoft 365 — mail bodies, Excel ranges, SharePoint list items, meeting transcripts, and…

ms365redact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

monday · egress

monday: Redact PII in Board & Doc Reads

Two egress controls in one policy, both scoped to the monday MCP read path:

mondayredact-piipiidlpredactionegresssoc2gdpr-ccpa

netsuite · ingress

NetSuite Cap SuiteQL Bulk Export

Instantiates the PF-08 cap-bulk-export family as a transform-only ingress policy on ns runCustomSuiteQL — the NetSuite MCP tool that runs arbitrary read-only…

netsuitecap-bulk-exportsuiteqldata-minimisationingresssoc2pci-dssgdpr-ccpa

netsuite · egress

NetSuite: Redact Financial PII in Responses

Instantiates PF-02 (redact-pii-egress) on the NetSuite read path.

netsuiteredact-piipiifinancial-piidlpredactionegressgdpr-ccpasoc2

notion · egress

Notion: Redact PII from Read Responses

Scans the responses of the Notion hosted MCP server's content-returning read tools and rewrites personally identifiable information to fixed redaction tokens…

notionredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

power-bi · egress

Power BI: Redact PII in Query Results

Scans the content returned by Power BI's result-returning tools and rewrites high-confidence PII shapes to fixed, non-recoverable redaction tokens before the…

power-biredact-piipiidlpdaxredactionegresssoc2gdpr-ccpa

quickbooks · egress

QuickBooks: Redact Employee & Vendor PII on Read

On the read path, this policy masks sensitive identifiers in the responses of four QuickBooks Online (QBO) name-entity read tools — get employee, search…

quickbooksredact-piipiiredactiondlpegressgdpr-ccpasoc2

ms365 · ingress

Read-Only Baseline: Group-Gated Microsoft 365 Writes

The least-privilege baseline for Microsoft 365 through the gateway: every tool call is allowed only if it is a read , or the caller's IdP token carries the…

ms365role-gate-writesingressleast-privilegesoc2gdpr-ccpasox

stripe · ingress

Read-Only Stripe by Default (Role-Gate Billing Writes)

Establishes a read-only-by-default Stripe posture over the MCP path. The named write and destructive billing tools —

striperole-gate-writesingressleast-privilegerbacsoc2pci-dsssoxgdpr-ccpa

google-calendar · egress

Redact Attendee PII and Meeting Links in Calendar Reads

Scrubs sensitive fields from the responses of Google Calendar read tools before they reach the agent, for callers who lack the placeholder calendar-full-read…

google-calendarredact-piipiiphidlpredactionegresssoc2hipaagdpr-ccpa

zapier · ingress

Role-Gate All Zapier Writes

Zapier MCP is an aggregator: one connector proxies actions across 9,000+ apps, and every create/update/delete/send funnels through a small, predictable…

zapierrole-gate-writesingresssoc2gdpr-ccpa

dropbox · ingress

Role-Gate Dropbox Writes to the Writers Group

Establishes the per-app least-privilege write floor for Dropbox.

dropboxrole-gate-writesrbacleast-privilegeingresssoc2gdpr-ccpa

salesforce · ingress

Salesforce Cap Bulk Data Export

Blocks bulk PII extraction through Salesforce query tools by inspecting the free-text query arguments that are the real policy surface for these servers.

salesforcecap-bulk-exportdata-minimizationdlpingresssoc2hipaapci-dssgdpr-ccpa

salesforce · ingress

Salesforce Protect Contact Fields

Blocks Salesforce Contact updates that modify protected fields — ownership, account linkage, contact PII, name, and consent flags.

salesforcecontactspiiaccess-controlgovernanceingresssoc2gdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Query Allowlist

Restricts Salesforce SOQL queries so only Account, Contact, and Opportunity records can be retrieved.

salesforceaccess-controldata-protectiongovernanceingresssoc2pci-dssgdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Read-Only Access

Restricts the Salesforce MCP server to read-only access.

salesforceaccess-controlgovernanceread-onlyingresssoc2gdpr-ccpaiso27001-nist

salesforce · egress

Salesforce Redact PII

Redacts personal contact information from Salesforce tool responses before they reach the caller.

salesforcepiidlpredactionegresssoc2hipaagdpr-ccpaiso27001-nist

salesforce · ingress

Salesforce Role-Gated Writes

The PF-12 least-privilege baseline for Salesforce.

salesforcerole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpacrm

slack · ingress

Slack Role-Gate Writes

Gates every Slack write-class tool behind an IdP group: callers whose JWT groups claim contains slack-writers may send and schedule messages, add or remove…

slackrole-gate-writesaccess-controlleast-privilegeingresssoc2gdpr-ccpa

slack · ingress

Slack: Block Agent Posts to External Channels

Denies Slack message-write calls whose destination is an externally shared Slack Connect channel.

slackguard-external-sendslack-connectexfiltrationingresssoc2gdpr-ccpahipaa

slack · ingress

Slack: Deny DM and Private-Conversation Reads and Search

Denies the agent read reach into Slack DMs and private conversations on the paths below — the workspace's highest concentration of PII/PHI (HR issues, health…

slackprivacydmaccess-controlingresssoc2gdpr-ccpa

slack · ingress

Slack: Deny Read/Search/Summarize of Sensitive Channels

Blocks read, search, and summarize operations that target a configurable set of "sensitive" Slack channels.

slackaccess-controldata-protectioningresssoc2hipaagdpr-ccpaiso27001-nist

slack · egress

Slack: Mask Card Numbers in Message and Search Responses

Masks payment-card numbers (PANs) in Slack content returned to agents by message-read, thread-read, canvas-read, history, and search tools.

slackmask-pan-egressegresscardholder-datadlppci-dsssoc2gdpr-ccpa

slack · egress

Slack: Redact Profile PII from User Lookups

Redacts personally identifiable information — email addresses, phone numbers, and Slack custom profile fields (which commonly carry phone, title, and…

slackpiiredactionprivacyegresssoc2gdpr-ccpa

slack · ingress

Slack: Redact Sensitive Information from Messages

Redacts sensitive content from outgoing Slack message arguments before the call reaches Slack.

slackpiisecretsdlpredactioningresssoc2hipaagdpr-ccpaiso27001-nist

snowflake · egress

Snowflake: Redact PII from Query Result Sets

Scans the row content returned by the result-returning Snowflake MCP tools and rewrites personally identifiable information to fixed redaction tokens before…

snowflakeredact-piipiidlpredactionegresssoc2hipaagdpr-ccpa

stripe · egress

Stripe: Redact Customer PII from Bulk Reads

Masks customer PII in the responses of Stripe's bulk PII egress channels before they reach the agent.

striperedact-piipiidlpredactionegresssoc2gdpr-ccpa

tableau · egress

Tableau: Redact PII & Mask PANs in Query Results

Tableau is a warehouse proxy: the data-returning tools stream raw row-level content out of whatever the published datasource connects to — PII, PHI, payroll,…

tableauredact-pii-egresspiipandlpredactionegresssoc2gdpr-ccpa

zapier · egress

Zapier: Mask Card Numbers in Read Responses

Masks payment-card numbers (PANs) in Zapier MCP read responses before they reach the agent.

zapiermask-pan-egressegresscardholder-datadlpsoc2pci-dssgdpr-ccpa

zoom · egress

Zoom: Redact PII in Meeting Intelligence

Scans the responses of Zoom's meeting-intelligence read surfaces — AI summaries, verbatim transcripts, recording resources, and Zoom Docs content — and…

zoomredact-piipiidlpredactionegresshipaagdpr-ccpasoc2