Skip to solution
mediumAI Engineering

How do you handle PII and sensitive data when calling LLM APIs?

314 views
01

Understand the problem

Data minimization, redaction, retention terms and regional processing for LLM traffic.

piiprivacycompliancesecurity
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Nudge consolestandby

Stuck? Beam a request up — the console returns a conceptual nudge that guides your logic without spoiling the implementation.

03

Study the solution

Start with the provider contract: enterprise API terms typically exclude training on your data and offer zero-or-short retention and regional processing — verify, do not assume. Then minimize: send only fields the task needs, redact or pseudonymize identifiers before the call (reversible mapping if the answer must refe

Solution ready — 2 min read

Classified // press E to declassify

04

Read the code

Redact → call → restore
const { redacted, mapping } = piiRedact(ticketText);
// "Customer [NAME_1] ([EMAIL_1]) reports billing issue on [CARD_1]..."

const reply = await client.messages.create({
  model, max_tokens: 500,
  messages: [{ role: "user", content: draftReplyPrompt(redacted) }],
});

const restored = piiRestore(textOf(reply), mapping);   // [NAME_1] → actual name
await traces.write({ prompt: redacted, output: scrub(textOf(reply)) }); // never raw
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.

Transmission complete // awaiting log

KEEP THE
STREAK ALIVE.

Dossier 49 of 80 decoded in the AI Engineering track. One more won't hurt.

Back to track