I don't know that there's necessarily a wrong answer here (well, there probably are, but wrong only in the sense that a given solution might be prohibited by the regulation), just want to see how y'all have thought through the prompt.
I don't know that there's necessarily a wrong answer here (well, there probably are, but wrong only in the sense that a given solution might be prohibited by the regulation), just want to see how y'all have thought through the prompt.
We also provide configuration option to specify additional fields are needed to be anonymised
HAR can already be recorded in middleware (e.g. loadmill/har-recorder) and replayed in multiple CI compatible ways.
> What do you mean by "live, regulated data into non-prod environments" exactly? Could you provide some examples?
Credit card numbers, card verification codes, protected health data/electronic medical records... list goes on.
Every environment that has live data in it functionally increases the valuable attack surface for most adversaries. I.e why bother attacking production when they can slurp up production data from test environments that are less likely to be well protected?
As for the "AI," I think the op was just commenting on the TLD used by the startup.