Frequently asked questions
Which values can Sensitive Data Scanner identify?
Configured rules can target common patterns such as phone numbers, identity values, accounts, tokens, credentials, payment data, IP addresses, and business-specific fields. Coverage depends on the enabled rules and selected data scope.
What should a team do after finding sensitive data?
Choose a treatment based on the risk: masking, replacement, Pipeline processing, tighter access, reduced collection, or a retention change. Validate the result in queries, exports, snapshots, and downstream systems.
Does scanning alone establish compliance?
No. Scanning is one control for discovering potential exposure. Compliance also depends on lawful collection, data minimisation, identity and access management, retention, audit, incident response, and the organisation’s applicable requirements.