Launch Week 3: Five days of launches

Mask Sensitive Trace Data

Protect your sensitive information from traces using the masking feature

Included on the Enterprise plan. Book a demo, opens in a new tab. Included on the Team plan. Included on the Starter plan. Not included on the Free plan.

Overview

Masking allows you to automatically redact or transform sensitive data in your traces before they're sent to the observatory. Masking is essential for several reasons:

  • Security: Prevent exposure of credentials or sensitive business data
  • Regulatory Compliance: Meet requirements like GDPR, HIPAA, or CCPA

By default, confident-trace captures the full content of your spans — prompts, completions, tool arguments, retrieved chunks, and anything you set through the update helpers. If that content can contain PII, you have three controls, all configured once in init():

ControlPython init()TypeScript init()What it does
Disable capturecapture_contentcaptureContentTurn content capture off entirely — keep timing, status, model, and usage
RedactredactredactRun your own masking function over every content value before export
Size limitmax_content_bytesmaxContentBytesOptionally cap the size of each content attribute (disabled by default)

Configure Masking

To implement masking, define a masking function and pass it to init() as redact. It runs over every content value right before serialization, so nothing sensitive ever leaves your process.

main.py
import re
from confident_trace import init, span, shutdown

def masking_function(data):
    if isinstance(data, str):
        return re.sub(r'\b(?:\d{4}[- ]?){3}\d{4}\b', '[REDACTED CARD]', data)
    if isinstance(data, list):
        return [masking_function(item) for item in data]
    if isinstance(data, dict):
        return {k: masking_function(v) for k, v in data.items()}
    return data

init(redact=masking_function)

@span(type="agent")
def llm_app(query: str):
    return "4242-4242-4242-4242"

try:
    llm_app("Test Masking")
finally:
    shutdown()

The masking function is automatically applied to:

  1. Span I/O: the captured input and output of every span — function arguments and return values, as well as the messages and completions recorded by integrations
  2. Update helper fields: anything you set through update_span() / update_trace(), such as input, output, retrieval_context, and metadata

Disable Content Capture

If you'd rather not export prompts and completions at all — for example in a regulated environment where masking isn't enough — turn content capture off. You still get timing, status, span hierarchy, and the model and token usage attributes, so cost tracking and latency monitoring keep working; only the content fields are omitted.

main.py
from confident_trace import init

init(capture_content=False)

Size Limits

Content size limits are disabled by default. Unless you configure one, confident-trace does not cap content attributes.

Set max_content_bytes / maxContentBytes to enable a limit. Values above the limit are truncated or omitted, and chat message arrays keep a valid, bounded prefix where possible so the span still renders. Streamed outputs are bounded the same way and marked as truncated, while token usage keeps being tracked:

main.py
from confident_trace import init

init(max_content_bytes=8192)

Next Steps

With sensitive data masked, control which traces are sent in the first place.

Ready to monitor AI in production?Connect traces, alerts, dashboards, and evals in one production workflowBook a demo

Last updated on

Built byConfident AI