Prohibited
- Passwords and passcodes
- Bank usernames or login credentials
- API keys and access tokens
- Full Social Security numbers
- Full bank account numbers
- Security-question answers
- Unnecessary unredacted IDs
The no-auth stack is for metadata and factual summaries—not raw private documents, credentials, or unnecessary identity data.
Remove the value and have an authorized administrator rotate or revoke it.
Separate each client into an authorized restricted workspace.
Restrict access, review sharing history, and obtain human confirmation.
Keep the untouched source in restricted storage.
Use a separate file for naming, redaction, summaries, and context.
Remove unrelated owner, employee, customer, patient, and identity information.
Confirm exactly who can access each sensitive folder and link.