PII scrubbing

Logs are the easiest way to collect personal data by accident: nobody decides to "log the national ID number", but an exception message carries the request body as it is. That is why Errorbird ships scrubbing on by default — KVKK (Turkey's personal data protection law) compliance cannot depend on users finding a setting and switching it on.

Two layers

1. Field name blocklist

The value is never stored for fields in Metadata with these names:

password, passwd, pwd, secret, token, accesstoken, refreshtoken,
apikey, api_key, authorization, auth, cookie, sessionid,
creditcard, cardnumber, cvv, iban, tckn, tcknumber

Why a separate layer? Because a password is a random string and matches no pattern. Relying on pattern matching means storing passwords as they are.

2. Pattern-based masking

In free text (including the message and the stack trace), these patterns are masked. The replacement tokens are literal values and are written in Turkish:

Pattern Replaced with
Credit card number [kart]
IBAN [iban]
TCKN — Turkish national ID (11 digits, checksum-validated) [tckn]
Email [eposta]
Phone [telefon]

They are applied from the narrowest to the widest: if the phone pattern ran first, it would split a card number into pieces and card masking would never match.

Masking is irreversible

The value is cut and replaced with a label; it is not hashed. A hashed TCKN is still personal data: an 11-digit number space can be brute-forced in minutes. "We'll decode it later if we need to" is a problem for your own application to solve, not for a logging system.

Extra rules per project

You can add your own sensitive patterns (customer numbers, policy numbers, internal system ids):

{
  "Errorbird": {
    "Pii": {
      "AdditionalPatterns": ["POL-[0-9]{8}", "CUS-[A-Z]{2}[0-9]{6}"]
    }
  }
}

Matching values are replaced with [maskeli] ("masked"). Regular expressions run with a 100 ms timeout: a badly written pattern (catastrophic backtracking) does not stop the ingest pipeline.

When does scrubbing run?

In the API process, before the event is written to the queue. This way the unmasked value never reaches Redis or the database. Scrubbing after queueing would mean writing raw personal data to disk, because Redis persistence (AOF) is on.

Turning it off

{ "Errorbird": { "Pii": { "Enabled": false } } }

Only for installations where you are sure no personal data is involved. Turning it off is not recorded in the audit trail — it is a configuration change and should be tracked by the installation's configuration management.