Skip to content

Enterprise: DLP — classification-aware response redaction for search/MCP results #205

Description

@RichardHightower

Search/MCP results can surface secrets, PII, or content above a caller's clearance. Add data-loss prevention on the response payload: classify indexed content by sensitivity tier, filter/redact results the caller isn't cleared for (the data_classification dimension of the authz decision), redact secret-pattern snippets, and emit an audit event on redaction. Prereq: MCP authz + audit (GCP phase 4); ideally the in-house policy engine.


Follow-up from design doc docs/plans/2026-06-09-enterprise-hardening-and-cloud-deployment.md (enterprise hardening, GCP-first).
Local TODO: .planning/todos/pending/2026-06-09-enterprise-dlp-classification-aware-redaction.md

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or requestmcpModel Context Protocol relatedroadmapPlanned future work tracked from a design docsecuritySecurity-relevant change

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions