AI
Privacy & Safety
Evidence is scrubbed before any provider. Output is validated. Insights never invent missing impact or remediate systems.
Privacy filter
Before provider input, Mydle redacts tokens, passwords, cookies, card-like digits, emails, and other sensitive keys. Untrusted telemetry is wrapped so log/error text is treated as data, never as instructions.
Validation
Provider output must match the structured insight schema ( observed, hypotheses, evidence refs, unknowns, recommended actions). Malformed JSON and dangerous remediation phrases are rejected.
Authorization
Insights require workspace membership and the ai_insights feature gate. Evidence queries stay scoped to the active workspace and incident.
Limitations
- Scrubbing reduces risk — it is not a guarantee that every secret pattern is caught. Prefer not to log secrets.
- Pipeline overview: AI Insights.