Data masking shall be used in accordance with the organization’s topic-specific policy on access control and other related topic-specific policies, and business requirements, taking applicable legislation into consideration
All customer information stored or processed within our systems is handled according to our internal *Confidential* data classification standard. Sensitive fields—including names, emails, VAT IDs, and addresses—are masked in non-production environments, logs, and documentation. Data retention policies ensure that confidential data is only stored for the minimum required duration and is securely deleted when no longer needed.
Our logging stack (Fluent Bit and Loki) masks or removes personally identifiable information (PII) before logs are stored or forwarded, ensuring safe observability without exposing sensitive customer data.