Anonymization
Vulnotes masks recognized sensitive text before sending AI requests. It replaces values with placeholders and restores them in the response, so you can keep working with the original report information.
What gets anonymized
The anonymization engine uses report context and pattern detection to recognize:
- The company name, contacts, and scope entries available in the report context
- IP addresses, hostnames, URLs, and email addresses
- Recognized phone number formats and common credential or token patterns
For example, a recognized client name is replaced with [CLIENT_NAME]. When the response contains that placeholder, Vulnotes restores the name.
Review text and screenshots
Automatic detection cannot identify every confidential detail. A person's name written only in free text, an unusual credential format, or business information may remain in the request. Review your input before using an external provider and check the result for any unrestored placeholders.
Images are handled separately. In screenshot generation, cover sensitive areas with the redaction editor before generating the finding. The redacted copy goes to AI; the original image remains available for the report.
Fully local alternative
To keep AI requests on your infrastructure, configure a self-hosted provider. Check the image analysis settings too, as screenshots can use a different provider from text.
See AI provider setup for the connection and image analysis settings.
