PII in request logs
Summary
The API gateway forwards email addresses to a logging vendor without an approved data flow.
Evidence
Open scan report →43
44
logger.info({
email: request.user.email,
});Inth answers from product records and shows the sources your teams need to review the answer.
Ask what changed, which vendor receives data, or what needs review.
Connect the response to scans, signals, consent, policies, decisions, and cited law.
Send the answer to the person reviewing the change, fix or customer response.
Answers stay tied to product evidence and show where human judgement is still required.
Answer from code, runtime, vendors, consent, and policy history.
Link material claims to the record that supports them.
Bring cited legal sources into the answer while preserving legal judgment.
Give product, privacy, security, and legal the same evidence trail.
The useful answer shows what changed, which evidence supports it, and where judgment is required.