New at Intercom
New
Security & Settings

Redact sensitive data in conversations with custom rules

Thibault avatar
Shared by Thibault • March 12, 2026

Incoming messages are now automatically scanned and redacted before they're stored — so sensitive data never reaches your database or your teammates' screens.

What's new:

  • Built-in rules for common identifiers — credit card numbers (last 4 digits preserved) and SSNs (fully masked), ready to enable out of the box.
  • Custom regex rules — Create up to 10 rules to redact business-specific data like policy numbers or account IDs. Custom matches are fully masked.
  • Works across channels — Web Messenger, mobile SDKs, inbound email, and call transcripts.

Redaction happens at ingest and is irreversible — matched content is overwritten before it's stored, so the original data is never retained.