Gluesync Core Hub · Ships with Gluesync 2.3

PII discovery & masking

Core Hub classifies columns that look like personally identifiable information, shows a PII tag wherever you pick or inspect a field, and masks the values before Query Studio or an AI tool ever receives them. Column names are matched in twelve languages, sample scans validate national identifiers with regional checksums, and pre-built masking field functions redact the data that has to leave the pipeline.

PII discovery & masking
Query Studio / PG-Analytics
customers.sql PII visible
  1. SELECT * FROM public.customers
  2. LIMIT 20
4 rows · 38 ms · classified columns masked
idname PII:nameemail PII:emailphone PII:phonefiscal_code PII:IT CFcontact_1
C-0042••••a***@***.it••••••••78••••alice.r@gmail.com
C-1207••••m***@***.de••••••••32••••m.bianchi@mail.de
C-1984••••s***@***.pt••••••••99••••sara.c@live.pt
C-2210••••j***@***.de••••••••77••••jonas.w@gmx.de
  1. 01 Find PII by name and by value
  2. 02 Mask results before they leave Core Hub
  3. 03 Redact in transit with field functions

Why PII discovery

You cannot protect the columns you have not found

01 / What PII is

Anything that points at a person

Emails, phone numbers, national and tax identifiers, card numbers, IBANs, dates of birth, addresses, passport and licence numbers, and the secrets that unlock them. Regulations such as GDPR expect you to know where they are and who can see them.

02 / Where it hides

Spread across engines and languages

A replication platform touches every database you own. Sensitive columns are called correo_electronico in one schema, geburtsdatum in another and contact_1 in a third. Spreadsheets of column names go stale the day after they are written.

03 / The platform outcome

Classify once, enforce everywhere

Core Hub stores one verdict per column and reuses it: as a tag in every editor, as a mask on every Query Studio and AI result, and as the signal that tells you which columns need a masking function before they reach a target.

How it works

From a column name to a protected result

  1. 01

    Discover

    Name classifier, then sample scan

    Column names are normalized and matched against a multilingual dictionary with token boundaries, so name matches but username does not. Scan table for PII adds a sample-based pass that validates formats such as IBAN mod-97, card Luhn and national identifier checksums. A manual Mark as PII or Not PII always wins.

  2. 02

    Label

    One tag, every screen

    The verdict appears as a PII tag in Query Studio, the Fields Editor, entity mapping, UDF, filter and custom key screens and CDC field lists. You see what is sensitive exactly where you decide what to replicate and how.

  3. 03

    Mask

    At read time, and in transit

    Query Studio results, copies and exports are masked inside Core Hub before the response leaves. AI Studio and MCP results are always masked. For data that has to reach a target, pre-built masking field functions redact it on the wire.

Capabilities

What ships in Gluesync 2.3

PII discovery is a Core Hub service with no extra component to deploy. It changes nothing about replication, snapshots or CDC: it is a read-time overlay for people and agents, plus the discovery layer that tells you where a masking field function belongs.

Discovery and labels

Find PII where you query it

Tags in the schema tree, masked cells in the grid, scans and overrides from the same screen

Open an agent in Query Studio and the schema tree already carries tags for columns whose names match the dictionary. Result headers repeat the tag and cells arrive masked. For generically named columns, Scan table for PII or Scan schema for PII run the sample-based classifiers; Mark as PII and Not PII record a user override that wins over automation.

  • Recognized labels: email, phone, iban, pan, it.codice-fiscale, ip, national-id, date-of-birth, passport, name, address, postal-code, tax-id, bank-account, driver-license and secret
  • Structural hints such as identifier, uuid, mostly-null or constant are catalog metadata and are never masked
  • Masked shapes: a***@***.com for email, bullets plus the last two characters for phone, bullets plus the last four for IBAN and card numbers, full bullets for the rest
  • Grid, record view, copy actions and CSV, JSON, SQL, Markdown, HTML, XML and XLSX exports all see the masked values
  • Super admins and Managers can turn on PII visible for a session when they need the original values

View PII discovery docs ↗

PII discovery & masking
Query Studio / PG-Analytics
customers.sql PII visible
  1. SELECT * FROM public.customers
  2. LIMIT 20
4 rows · 38 ms · classified columns masked
idname PII:nameemail PII:emailphone PII:phonefiscal_code PII:IT CFcontact_1
C-0042••••a***@***.it••••••••78••••alice.r@gmail.com
C-1207••••m***@***.de••••••••32••••m.bianchi@mail.de
C-1984••••s***@***.pt••••••••99••••sara.c@live.pt
C-2210••••j***@***.de••••••••77••••jonas.w@gmx.de

Masking in transit

Field functions that redact on the wire

Pre-built masking functions, applied per column in the Fields Editor

Discovery tells you which columns are sensitive; the data transformation layer keeps them from reaching a target in clear. The field function catalog ships a Data masking and anonymization category that overrides the incoming value with a redacted one, and the same tags appear in the Fields Editor so you can see which mapped columns still need one.

  • Mask Credit Card keeps only the last block of digits and preserves separators in place
  • Mask Email keeps the domain and the first character of the mailbox name
  • Mask Phone keeps the prefix and the last four digits, across international formats
  • Mask IBAN keeps the first four and last four characters; Mask String keeps the first letter of each word
  • For anything else, a UDF can drop or rewrite the field, and a Custom Field Function can hash or tokenize it with your own Java

View masking field functions ↗

PII discovery & masking

Overlay versus transformation

Read-time masking protects what people and agents see inside Gluesync and does not change replicated data. A masking field function changes what the target receives. Use discovery to decide where each one belongs.

Integrations

One verdict across the platform

Query Studio, AI Studio and MCP, Visualize, the pipeline editors and a platform-wide switch

The stored classification is read by every surface that shows or executes SQL. Query Studio masks by default and lets authorized roles unmask per session. AI Studio, Query Studio AI helper traces and MCP execute_sql results stay masked even when the platform toggle is off. Visualize runs its queries under the same policies as Query Studio.

  • Settings > Global settings > Mask PII platform-wide, stored as PII_MASKING_ENABLED and writable by Super admins only
  • MCP read tools classify_table and classify_schema return labels and confidence, never raw cells; the AI helper suggests Scan this schema for hidden PII
  • Pipeline editors show the tag in the Fields Editor, entity mapping, UDF, filter and custom document key screens and CDC field lists
  • Query Forge is a separate federated SQL path for JDBC clients: masking does not apply there, so treat those credentials as production-grade
  • Not column-level encryption or tokenization in the source or target, and not a replacement for a dedicated DLP product

View Core Hub MCP docs ↗

PII discovery & masking
Settings / Global settings / PII masking

Global settings

Super admin
PII masking

Mask classified PII in Query Studio results, copies, and exports for every user of this Core Hub. Enabled by default.

Mask PII platform-wide

Stored as PII_MASKING_ENABLED. Managers and super admins can still reveal values per session with PII visible.

Who sees what

CapabilitySuper adminManagerViewer
See PII tags
Scan, mark, dismiss columns
Toolbar PII visible—
Disable platform-wide masking——

Languages and regions

Column names in twelve languages, identifiers from a dozen countries

A global dictionary and regional value checks, with language-neutral labels

The name dictionary is intentionally global: English plus common aliases in Spanish, Portuguese, Italian, French, German, Dutch, Polish, Turkish, Chinese, Japanese and Korean. Labels stay language-neutral, and the detector that fired is kept in the source rule for audit. Sample scans then validate high-confidence formats instead of treating every long number as PII.

  • Name matches such as correo_electronico, téléphone, geburtsdatum, endereço, tc_kimlik, 身份证, 郵便番号 and 주민등록번호
  • Global detectors: email, E.164 phone, IPv4 and IPv6, IBAN mod-97 and payment-card Luhn
  • Regional checks: Italian codice fiscale, US SSN and Canadian SIN, Brazilian CPF, Indian Aadhaar, Chinese resident identity, South African identity number, Turkish TCKN, Spanish NIF and NIE, French NIR and Australian TFN
  • Confidence is typically 0.82 for a name match and 0.95 for secrets; schema scans are capped so a large catalog cannot stall the hub

View supported languages and detectors ↗

PII discovery & masking
Query Studio / CRM-Oracle / Scan schema for PII
Scan schema for PIIcrm · 13 classified columns · sampled: true
Dictionary
ColumnLabelConfidenceSource rule
geburtsdatumcrm.kunden · GermanPII:date-of-birth0.82name/de
correo_electronicocrm.clientes · SpanishPII:email0.82name/es
郵便番号crm.顧客 · JapanesePII:postal-code0.82name/ja
tc_kimlikcrm.musteri · TurkishPII:national-id0.97checksum/tr.tckn
cpfcrm.clientes_br · PortuguesePII:national-id0.97checksum/br.cpf
주민등록번호crm.회원 · KoreanPII:national-id0.82name/ko
contact_1crm.customers · EnglishPII:email0.90sample/email
codice_fiscalecrm.clienti · ItalianPII:IT CF0.97checksum/it.cf
téléphonecrm.clients · FrenchPII:phone0.82name/fr
adrescrm.klanten · DutchPII:address0.82name/nl
peselcrm.klienci · PolishPII:national-id0.82name/pl
身份证crm.客户 · ChinesePII:national-id0.97checksum/cn.id
api_keycrm.accounts · EnglishPII:secret0.95name/secret

Resources

PII discovery and masking documentation and resources

Roadmap

Public Roadmap

What we're building next. Submit feature requests.

View roadmap ↗
Support

Support

Access technical support and operational assistance.

Get support →
Status

Service Status

Real-time platform availability and incident history.

Check status ↗

Know where the personal data is. Decide who sees it.

Request a free trial or talk with the MOLO17 team about PII discovery, read-time masking and masking field functions on your own schemas.