Who can use this: Team members whose emails are imported to Gong
Available on: Any Gong plan
Gong automatically redacts recognized passwords, tokens, keys, and other machine credentials from incoming email content. This protection is enabled by default for all customers and cannot be disabled or configured.
Data that is redacted
Gong may redact the following:
API keys and access tokens
Container and messaging service credentials
Cloud-provider credentials, including keys, tokens, and storage or search keys
CRM and marketing platform credential keys
Generative AI and machine-learning platform keys
Other provider-specific secrets and machine credentials
Payment and communications service credentials associated with common payment or telephony providers
Personal access tokens, including platforms that support common repositories for software code and development for DevOps tokens or processes
Some secret types are redacted only when they appear with related business context or signals. For example, a cloud provider key ID may need to appear with its corresponding secret key, or an e-commerce platform token with the relevant e-commerce domain. This contextual matching helps avoid redacting values used in non-credential contexts.
Email content covered
Redaction applies to recognized secrets found in:
Plain-text email bodies
HTML email bodies
Email synopsis or preview text
Content not covered
Redaction does not apply to:
Subject lines
Sender and recipient addresses
Email headers
Attachments
General PII such as Social Security numbers, credit-card numbers, phone numbers, and email addresses
How redaction appears
Detected secrets are replaced with asterisks in Gong.
Frequently asked questions
Does this apply to call recordings or transcripts?
No. Credential or secret redaction applies to email content only. For redaction of data in call recordings and transcripts, see Information redaction.
Why did Gong implement this feature and make it mandatory?
Gong built these capabilities to mitigate risk for customers and as a common technical control for all customers.
Does this guarantee that no passwords or credentials will enter Gong through an email?
No. The feature reduces the risk of credentials being stored in Gong, but it cannot detect every password or credential. Customers should follow their own security policies and promptly delete any emails containing sensitive credentials.