Learn / Security and privacy

What is PII, and how do you protect it in AI systems?

Updated 3 October 2026 · 2 min read

Short answer

PII, or personally identifiable information, is any data that can identify a person, such as a name, phone number, account number or medical record number. In an AI system you protect it by detecting it before indexing and then redacting, masking or tokenizing it, so raw values never reach the index or the model.

With troveGEN

troveGEN protects personal data before it is indexed: high-risk identifiers are replaced with tokens and the real values are kept in a separate encrypted vault, on every plan.

See what troveGEN provides ↓

What counts as PII

Direct identifiers include names, email addresses, phone numbers, government ID numbers, bank and card numbers, and medical record numbers. Indirect identifiers, such as a rare job title in a small town, can identify someone when combined. Health information is a sensitive category with its own rules in many jurisdictions.

Why PII is a RAG problem

RAG copies document text into an index, then into prompts sent to a model. Every copy is a new place where a value can leak or be retrieved by someone who should not see it. Embeddings can also carry traces of the text they encode. The safest time to deal with PII is before it enters the pipeline.

Three techniques

  • Redaction: replace the value with a fixed marker such as [REDACTED]. Safe, but the information is gone for good.
  • Masking: show part of a value, such as the last four digits, which keeps some usefulness.
  • Tokenization: replace the value with a stable placeholder, for example [ACCOUNT_1], and keep the real value in a separate, encrypted vault. Authorised users can get the real value back; everyone else sees the token.

Detecting PII

Patterns and checksums catch structured values reliably, such as card numbers that pass a Luhn check or national IDs with known formats. Names and addresses are harder and usually need a language model. Because detection is imperfect, combine it with access control rather than relying on it alone.

Restoring values safely

If users sometimes need the real value, restoration should be permission-gated and logged, and should happen only at the moment of display, never written back into the index.

Key takeaways

  • Handle PII before indexing, not after.
  • Tokenization keeps usefulness while keeping real values in a separate vault.
  • Pair detection with access control and deletion.

How troveGEN helps with protecting PII

troveGEN detects high-risk identifiers such as account numbers, card numbers, national IDs and medical record numbers before embedding and replaces them with tokens, keeping the real values in a separate encrypted vault. This applies on every plan. Restoring a value is permission-gated and audited, and deleting a document also removes its vault entries.

What troveGEN provides

  • Detection of account numbers, card numbers, national IDs and medical record numbers before embedding
  • Tokens in the index and the model prompt; real values only in an encrypted vault
  • Permission-gated, audited restoration for people who are allowed to see the value
  • Optional masking of contact details such as email and phone
  • Deletion that also removes the document's vault entries

See how data is protected Start free — 500 pages

Frequently asked questions

Is anonymisation the same as redaction?

Redaction is one way to anonymise. True anonymisation means the person cannot be re-identified even with other data, which is a higher bar than hiding a few fields.

Does masking meet privacy law?

It depends on the law and the data. Treat this as a technical control that supports compliance, and take legal advice for your situation.

Can detection miss things?

Yes. That is why access control, encryption and deletion must also be in place.

How does troveGEN help with protecting PII?

troveGEN protects personal data before it is indexed: high-risk identifiers are replaced with tokens and the real values are kept in a separate encrypted vault, on every plan. It provides: Detection of account numbers, card numbers, national IDs and medical record numbers before embedding; Tokens in the index and the model prompt; real values only in an encrypted vault; Permission-gated, audited restoration for people who are allowed to see the value; Optional masking of contact details such as email and phone; Deletion that also removes the document's vault entries.

Keep reading