Email redaction

Prev Next

Who can use this: Team members whose emails are imported to Gong

Available on: Any Gong plan

Gong automatically redacts recognized passwords, tokens, keys, and other machine credentials from incoming email content. This protection is enabled by default for all customers and cannot be disabled or configured.

Data that is redacted

Gong may redact the following:

  • API keys and access tokens

  • Container and messaging service credentials

  • Cloud-provider credentials, including keys, tokens, and storage or search keys

  • CRM and marketing platform credential keys

  • Generative AI and machine-learning platform keys

  • Other provider-specific secrets and machine credentials

  • Payment and communications service credentials associated with common payment or telephony providers

  • Personal access tokens, including platforms that support common repositories for software code and development for DevOps tokens or processes

Some secret types are redacted only when they appear with related business context or signals. For example, a cloud provider key ID may need to appear with its corresponding secret key, or an e-commerce platform token with the relevant e-commerce domain. This contextual matching helps avoid redacting values used in non-credential contexts.

Email content covered

Redaction applies to recognized secrets found in:

  • Plain-text email bodies

  • HTML email bodies

  • Email synopsis or preview text

Content not covered

Redaction does not apply to:

  • Subject lines

  • Sender and recipient addresses

  • Email headers

  • Attachments

  • General PII such as Social Security numbers, credit-card numbers, phone numbers, and email addresses

How redaction appears

Detected secrets are replaced with asterisks in Gong.

Frequently asked questions

Does this apply to call recordings or transcripts?

No. Credential or secret redaction applies to email content only. For redaction of data in call recordings and transcripts, see Information redaction.

Why did Gong implement this feature and make it mandatory?

Gong built these capabilities to mitigate risk for customers and as a common technical control for all customers.

Does this guarantee that no passwords or credentials will enter Gong through an email?

No. The feature reduces the risk of credentials being stored in Gong, but it cannot detect every password or credential. Customers should follow their own security policies and promptly delete any emails containing sensitive credentials.