← Professional Cloud Security Engineer: controls and evidence
06 / 8 · 40 MIN

Minimization, secrets, and AI

Preserve data utility without confusing transformation, authorization, and blocking.

Concept and mechanism

Pseudonymization replaces sensitive values with tokens that can retain analytical utility. Choice depends on permitted correlation and reversibility. A deterministic token can support joins, but that correlation is also a privacy property to evaluate. Reversible methods require key protection and reidentification authorization; pseudonymizing does not guarantee anonymity of the entire dataset. Referential integrity depends on key and context. A new transient key per request does not justify assuming consistent tokens across calls. Before choosing transformation, inventory fields, free text, and other identifiers. Tokenizing customer_id while retaining name and email does not remove identifying content.

Guided application

In a fictional APS assistant, the application receives tickets containing data that must not leave authorized scope. Minimize submitted content and limit identity access to genuinely required secrets. Model Armor has distinct modes: Inspect only observes and logs without blocking; Inspect and block provides the decision the integration or enforcement point must apply. If code always delivers the response, recording the verdict does not meet the requirement. Test prompts and responses, including alternative paths and failures. A textual model refusal can come from its own protections and does not prove a Model Armor block. Retain suitable evidence without turning logs themselves into another unnecessary copy of sensitive data.

IN PRACTICE

A stored verdict and delivered response can coexist in an integration missing enforcement.

Common pitfalls

Token as anonymity; transient key as lasting correlation; one field as whole dataset; detection as blocking.

Related topics: Federation and temporary access · IAM, deny, and inheritance · IAP, WAF, and perimeters

Take this idea with you

Validate residual data and the decision’s actual effect on the application path.

Create account

Reference: Sensitive Data Protection pseudonymization · Current linked guide; edition date unconfirmed (2026-09-30 inspection)