---
sourceDocument: Brazil Conversational Interfaces
sourceDocumentLink: https://www.servicenow.com/docs/r/conversational-interfaces

 Release :

    - brazil

ft:locale :

    - en-US

ft:publication_title :

    - Brazil Conversational Interfaces

ft:clusterId :

    - convint

bundleId :

    - convint

workflow :

    - Platform


---

# Sensitive Data Handler

# Sensitive Data Handler {#ariaid-title1}

Release version: Brazil  
Updated September 10, 2026  
![](https://www.servicenow.com/docs/portal-asset/ico-clock) 3 minutes to read
Summarize  
![AI sparkle icon](https://servicenow.com/docs/portal-asset/ai-sparkle-icon) Summarized using AI  
This content was generated using new OpenAI-powered functionality. Results are provided on an as is basis and are not guaranteed to be accurate or complete.  

## Summary of Sensitive Data Handler

The Sensitive Data Handler in ServiceNow helps detect and mask sensitive information entered during Agent Chat or Virtual Agent conversations, ensuring that sensitive data is not visible to agents or requesters.
It also supports capturing sensitive data securely during business processes like user authentication.
Although this feature is currently supported, it is slated for future deprecation and will be replaced by the Data Privacy application.
Show full answer Show less  

## Key Features

* **Detection and Masking:** Automatically identifies sensitive data such as social security numbers, credit card numbers, and confidential company information entered by either agents or requesters across chat widgets, mobile apps, and supported messaging channels (SMS, Slack, Teams, Workplace).
* **Configurable Regular Expressions:** Comes with predefined patterns for common sensitive data types and allows customization to add, edit, or remove patterns for detecting other sensitive data.
* **Message Handling:** Masks sensitive data in transcripts and displays system notifications to both agents and requesters when sensitive information is detected. If an agent attempts to send sensitive data, the message is blocked and an error is shown.
* **User Authentication Support:** Enables secure passing of authentication information collected during conversations.
* **Flexible Configuration:** Administrators can specify whether masking applies to inbound messages (from requesters), outbound messages (from agents), or both.
* **Standalone Plugin:** The Sensitive Data Handler plugin \[com.glide.sensitivedatahandling\] can be installed independently of other chat or virtual agent plugins.

## Predefined Regular Expressions

The system includes predefined regular expressions to detect various types of sensitive data accurately, such as:

* **Credit Cards:** Patterns for Visa, American Express, Mastercard, Diners Club, and Discover cards based on starting digits and length.
* **Social Security Numbers:** Validates correct number formats, excluding invalid sequences.
* **Email Addresses:** Detects standard email formats with alphanumeric characters and domain validation.

These expressions are essential for correctly identifying sensitive data and ensuring masking is applied without system performance issues. Misconfigured patterns may cause processing delays, but the system includes a timeout safeguard.

## Practical Implications for ServiceNow Customers

* Use this feature to enhance data privacy during live or virtual agent interactions by automatically masking sensitive user input.
* Configure or extend regular expressions to cover your organization's specific sensitive data types.
* Prepare for transition to the Data Privacy application since the Sensitive Data Handler will be deprecated in future releases.
* Ensure agents understand that sending sensitive data directly to requesters is blocked to maintain confidentiality.  
During an Agent Chat or Virtual Agent conversation, the agent or requester may accidentally enter sensitive data. The Sensitive Data Handler detects and masks the sensitive data so it is not viewed by the agent or requester. The Sensitive
Data Handler can also collect sensitive data as part of a business process, such as user authentication.  
Note:  
This feature is being prepared for future deprecation. It will be hidden and no longer available for installation but will continue to be supported. For details, see the [Deprecation Process \[KB0867184\]](https://hi.service-now.com/kb_view.do?sysparm_article=KB0867184) article in the Now Support knowledge base.

Install the Data Privacy application as a replacement. For more information, see [Data Privacy](https://www.servicenow.com/docs/access?context=data-privacy-landing&version=brazil&pubname=brazil-platform-security&ft:locale=en-US).  
Possible situations when the Sensitive Data Handler might detect and mask sensitive data include:

* A requester enters sensitive data, such as a social security number, during a conversation with a live agent or virtual agent.
* An agent enters company information, such as a manager's confidential email address, that the requester should not have access to.
* A requester enters sensitive data in a pre-chat or post-chat survey.
{#ac-sensitive-data-overview__ul_c25_14z_bsb}

The Sensitive Data Handler detects and masks sensitive data when the requester is conversing through the chat widget, mobile (iOS/Android), or any of the supported adapter channels (SMS/Slack/Teams/Workplace).  
You can configure the following:

* Regular expressions for each type of sensitive data (for example, social security number or credit card number).
* Whether sensitive data handling works only for inbound (from a requester) messages, outbound (from a live agent) messages, or both.
* Messages that displays to the requester or agent informing them that sensitive data has been masked.
{#ac-sensitive-data-overview__ul_uq2_b3t_gsb}

If the requester sends a message containing sensitive data to an agent, a system message is sent to the requester and agent notifying both that the message contained sensitive data. The sensitive data is masked on the transcript
and marked as sensitive on the internal transcript.

If an agent tries to send a message containing sensitive data to a requester, the message is not sent to the requester. Instead, an error is displayed to the agent and the message is tagged as sensitive in the internal
transcript.

The Sensitive Data Handler can be configured to pass user authentication information to another entity. The requester might provide sensitive data during a conversation to prove their identity (for example, social security number,
date or birth, email address).

The Sensitive Data Handler plugin \[com.glide.sensitive_data_handling\] can be installed by itself, without a Glide Virtual Agent or Agent Chat plugin. Regular expressions can be added, edited, and deleted from the Sensitive Data Handling module.

## Regular Expressions {#ac-sensitive-data-overview__section_npy_5cm_gsb}

The base system of the Sensitive Data Handler comes with pre-defined regular expressions for credit/debit card numbers, social security numbers, and email addresses. When the Sensitive Data Handler detects a regular expression,
it uses the defined masking pattern to mask sensitive data. To define your own regular expressions and patterns to mask other sensitive data, see [(Legacy) Configuring sensitive data handler](https://www.servicenow.com/docs/LctQhj~tOGW94dkePda9Yw "Detect and mask sensitive information that is shared in Agent Chat or Virtual Agent conversations."). If a regular expression is not properly configured, the system may get stuck while attempting to match the regular expression with the message. To prevent the
system from getting stuck, the system times out after one second.  
{#ac-sensitive-data-overview__table_r1n_gdm_gsb__entry__3}

| Name | Regular expression | Details |
|-|-|-|
| Credit Card - Visa | \\b4\[0-9\]{12}(?:\[0-9\]{3})?\\b | * Card number starts with 4. * New card number has 16 digits, old card number has 13 digits. {#ac-sensitive-data-overview__ul_a2x_bct_gsb} |
| Credit Card - American Express | \\b3\[47\]\[0-9\]{13}\\b | * Card number starts with 34 or 37. * Card number has 15 digits. {#ac-sensitive-data-overview__ul_kj5_2ct_gsb} |
| Credit Card - Mastercard | \\b(?:5\[1-5\]\[0-9\]{2}\|222\[1-9\]\|22\[3-9\]\[0-9\]\|2\[3-6\]\[0-9\]{2}\|27\[01\]\[0-9\]\|2720)\[0-9\]{12}\\b | * Card number starts with a number between 51-55 or 2221-2720. * Card number has 16 digits. {#ac-sensitive-data-overview__ul_rhl_gct_gsb} |
| Credit Card - Diners Club | \\b3(?:0\[0-5\]\|\[68\]\[0-9\])\[0-9\]{11}\\b | * Card number starts with 36, 38, or 300-305. * Card number has 14 digits. * Cards that start with 5 and have 16 digits should be processed like a MasterCard. {#ac-sensitive-data-overview__ul_sxn_jct_gsb} |
| Credit Card - Discover | \\b6(?:011\|5\[0-9\]{2})\[0-9\]{12}\\b | * Card number starts with 65 or 6011. * Card number has 16 digits. {#ac-sensitive-data-overview__ul_qbn_4ct_gsb} |
| Social security number | \\b(?!666\|000\|9\\d{2})\\d{3}-(?!00)\\d{2}-(?!0{4})\\d{4}\\b | * First 3 digits cannot be 000, 666, or 900-999. * Hyphen (-) * Middle 2 digits should be 01-99 and cannot be 00. * Hyphen (-) * Last 4 digits should be 0001-9999 and cannot be 0000. {#ac-sensitive-data-overview__ul_kjf_tct_gsb} |
| Email | \\b\[\\w!#$%\&'\*+/=?\`{\|}\~\^-\]+(?:\\.\[\\w!#$%\&'\*+/=?\`{\|}\~\^-\]+)\*@(?:\[a-zA-Z0-9-\]+\\.)+\[a-zA-Z\]{2,6}\\b | * Word * Period (.) * Word * @ symbol * String of alphanumeric characters at least one character long. * Period (.) * Alphabetical string 2-6 characters long. {#ac-sensitive-data-overview__ul_atk_d1c_hsb} |
[Table 1. Pre-defined Regular Expressions]

{#ac-sensitive-data-overview__table_r1n_gdm_gsb}

