> For the complete documentation index, see [llms.txt](https://docs.nullify.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.nullify.ai/capabilities/code-reviews/secrets-detection/confidential-data-detection.md).

# Confidential Data Detection

Nullify inspects every diff for sensitive personal information that should never live in source control. When detected, the finding appears in the secrets channel with the relevant PII category and rotation guidance.

## Categories We Classify

* Personal information: email addresses, phone numbers, postal addresses, dates of birth, and US Social Security Numbers.
* Financial information: payment card numbers.
* Location and identity data sourced from structured dumps or seed files.

All detections currently focus on English-language datasets.

## Example Workflow

1. A developer commits a seed file containing realistic user records (`create.sql`).
2. Nullify analyses the diff, labels the exposure as **Personal Information**, and posts the finding to the dashboard.
3. The reviewer can remediate, suppress with justification, or convert the event into a campaign task.

![Sample SQL seed file](/files/8RokOd71wJ1yIb5Q6hup) ![Example PII alert](/files/r6AbpTP3eHeSP4NaEqzb)

> 💡 PII detection is available to enterprise tenants on request. Contact your Nullify representative to enable it for your environment.
