GCPExpandedEvidence: Low25/100

Deloitte & Google Cloud: Redacting PII in Dialogflow CX via Contact Center AI Security Settings and Cloud DLP

Deloitte Canada and Google Cloud describe a production-ready approach to prevent sensitive information from being stored in Dialogflow CX logs. The article explains that contact center conversations can include PII, PHI, PCI, and other confidential information in intent/form parameters, session parameters, webhook data, and fulfillment response messages, and that these values can propagate into Google Cloud Logging unless redacted at the source.

Organization
Deloitte
Location
Canada
Published
November 2022

Reported outcomes

Strategic outcomes

Risk & compliancePrevented sensitive data leakage into logsRisk & complianceRedacted sensitive conversation data at sourceNew product / capabilityEnabled safe use of sensitive data in responses
Why do we believe this deployment?Customer identity, provider attribution, maturity, and source checks
Customer
Deloitte
Provider
GCP
Maturity
Unknown
Linked source
Google Cloud Blog

No explicit deployment-stage evidence found.

Customer identity supportedSource describes one deploymentMaturity evidence evaluated

Primary read

Use case focus

Showing 3 of 3

  • 1Data Privacy
  • 2Security
  • 3Contact Center Automation
  • Protect PII, PHI, PCI, and other sensitive customer data from being stored in Dialogflow CX logs.
  • Prevent sensitive data from propagating into downstream logging, analytics, and monitoring systems while still allowing it to be used in virtual agent responses.
  • Use built-in Dialogflow CX parameter redaction for intent and form parameters.
  • Use Cloud Data Loss Prevention inspection templates with Google Cloud Contact Center AI Security Settings to redact session parameters, webhook data, and fulfillment response messages before they reach Google Cloud Logging.
  • Use SSML mark tags to delimit sensitive spans so they can be redacted without affecting TTS behavior.
  • Implement the configuration through the Google Cloud Console, APIs, and Terraform.
  • Provides a production-ready way to stop sensitive information leakage into logs and monitoring systems.
  • Preserves the ability to use sensitive information in response generation while keeping non-sensitive log data intact.
Architecture

Dialogflow CX redaction is applied at multiple stages: built-in redaction for intent/form parameters, and CCAI Security Settings that reference a Cloud DLP inspection template to redact session parameters, webhook payloads, and fulfillment messages before they are published to Google Cloud Logging. SSML <mark> tags are used to preserve speech output while identifying sensitive spans. The configuration can be managed in Google Cloud Console or provisioned with Terraform using infrastructure-as-code.

Sources & evidence1
Evidence: Low25/100Evidence strength
  • Customer explicitly identified
  • Technical implementation details available
ExpandedExpanded

The same organization appears in newer AI deployment evidence.

  • Same organization re-documented as recently as 2026.

Measures whether this deployment's public evidence persists — not whether the system is still in production.

Type: Blog PostPublished: Nov 12, 2022Publisher: Google CloudEvidence: VendorConfidence: Medium

AI-generated summary. Verify important details with the linked sources before relying on this case.

Explore related AI use cases

Was this useful?

Community

Comments

No published comments yet.