Privacy-preserving logging

Keep The Evidence. Not The Exposure.

See how logging tier, supported redaction, exceptions, retention, read access, and policy changes become explicit and auditable choices.

What this answers

Transcript

The record that makes an A.I. problem easiest to debug can become the most sensitive dataset the company owns. Retain every prompt and tool payload, and observability creates a second exposure. Retain nothing, and teams lose the evidence they need to investigate. PrivacyFirst makes that tradeoff an explicit policy instead of an accidental property of a log pipeline. Three tiers state exactly what is captured. Metadata-only retains tokens, cost, latency, provider, model, identity, tags, finding types, policy decisions, and tool names without writing message bodies. Redacted bodies add prompt, response, and tool content after detected personal data is removed fail-closed. Raw bodies preserve full fidelity and are marked sensitive. Meridian's workspace default is redacted bodies. The interface says what that means before an administrator changes anything: redacted content is encrypted, expires automatically, is restricted to workspace admins, and every read is audited. Unredacted content is excluded because detection runs before the retained body is written. A scoped exception handles pre-production debugging without changing the whole workspace. The clinician-notes project currently uses raw bodies for thirty days. Precedence is visible: a key override wins over a project override, which wins over the workspace default. The persistent warning names the active exception so sensitive capture cannot disappear into a settings page. Raw logging is not one casual click. It requires an explicit risk acknowledgement and a fixed seven- or thirty-day retention class. The raw tier uses its dedicated encryption path, limits body access to admins, and audits each read. This film never displays raw medical content. It shows the control around the exception. When retained evidence is needed, PrivacyFirst shows the active retention period and keeps redacted replacement markers obvious. The reader can connect the evidence to a request without receiving the patient value that triggered the detector. The earlier session film showed one such redacted body; this policy explains why that was the body available. Change history preserves who changed the tier, the affected scope, and when. Reverting an override prevents future raw capture after the policy takes effect; it does not pretend that earlier retained bodies were retroactively erased. That boundary matters. PrivacyFirst helps teams retain useful evidence without making a promise the storage lifecycle cannot support. Bring us one sensitive debugging workflow. We will map exactly what must be kept, what can stay metadata-only, how long bodies may exist, and who may read them. Book a live demo at PrivacyFirst dot A.I.