mediumAI Engineering

How do you handle PII and sensitive data when calling LLM APIs?

314 views
01

Understand the problem

Data minimization, redaction, retention terms and regional processing for LLM traffic.

piiprivacycompliancesecurity
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Redact → call → restore
const { redacted, mapping } = piiRedact(ticketText);
// "Customer [NAME_1] ([EMAIL_1]) reports billing issue on [CARD_1]..."

const reply = await client.messages.create({
  model, max_tokens: 500,
  messages: [{ role: "user", content: draftReplyPrompt(redacted) }],
});

const restored = piiRestore(textOf(reply), mapping);   // [NAME_1] → actual name
await traces.write({ prompt: redacted, output: scrub(textOf(reply)) }); // never raw
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.