DATA MASKING & PII
Account confidentiality and fixed privacy controls keep names, memos, and protected transaction detail out of the model – while safe analysis still works.
Useful analysis needs structure and relationships, not real names. Most tools force a choice between sharing everything or nothing. PipeLedger applies one clear policy at query time – the model gets what it needs, not what it shouldn't have.
Click 'Admin re-identify' in the diagram below to see how a token resolves under role-gated, logged access.
| VENDOR_NAME | AMOUNT |
|---|---|
| John Smith | $145,000.00 |
| Sarah Johnson | $98,500.00 |
| Riverside Lumber | $234,100.00 |
| Pacific Ventures | $67,200.00 |
| VENDOR_NAME | AMOUNT |
|---|---|
| CUST_8F4KQ2A1 | $145,000.00 |
| CUST_3B7PQ9R2 | $98,500.00 |
| VEND_2A9MK5P1 | $234,100.00 |
| CUST_7H2LN5K8 | $67,200.00 |
Amounts pass through unmasked — agents reason on the numbers and keep ledger integrity; only the identity is tokenized.
Standard keeps full transaction detail. Restricted removes identifying columns below clearance. Highly Restricted removes transaction grain and keeps only scoped account, period, currency, accounting book, legal entity, and organizational segment ledger totals below clearance. Explicitly assigned projects may be separated by private project tokens.
Replace Customer, Vendor, Employee, or Project identity with stable private tokens globally or for one account. Memos can be prohibited absolutely, with no credential override.
Rate-limited, role-gated, and logged to the immutable audit trail before any token resolves to a real value.