> ## Documentation Index
> Fetch the complete documentation index at: https://docs.datris.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Propose field protection from a preset (HIPAA Safe Harbor)

> Classifies source fields against the preset's fixed name table (the 18 HIPAA Safe Harbor identifier classes) and proposes each recognised field's default method, clamped by the same rules as `/api/v1/pipeline/protect/suggest` (keyFields columns only hmac or none; non-string source or destination types only drop or none). Deterministic: no model call. Stateless: nothing is saved and nothing is audited. Pass `preset` with either `pipeline` (its stored source schema and constraints are used) or `fields`. At most 150 fields per call; `_json` and `_xml` are skipped. A stored JSON, XML or unstructured pipeline is refused with 400. Needs the same capability as reading a pipeline. An aid to applying Safe Harbor, not a certification.



## OpenAPI

````yaml /openapi.yaml post /api/v1/pipeline/protect/preset
openapi: 3.0.3
info:
  title: Datris API
  description: >
    REST API for the Datris AI Data Platform. Ingest, validate, transform,
    store, and retrieve data.


    For AI agent integration, use the [MCP
    Server](https://docs.datris.ai/mcp-server) instead.
  version: 1.28.0
  contact:
    name: Datris
    url: https://datris.ai
  license:
    name: Apache 2.0
servers:
  - url: http://localhost:8080
    description: Local development
security:
  - ApiKeyAuth: []
paths:
  /api/v1/pipeline/protect/preset:
    post:
      tags:
        - Pipelines
      summary: Propose field protection from a preset (HIPAA Safe Harbor)
      description: >-
        Classifies source fields against the preset's fixed name table (the 18
        HIPAA Safe Harbor identifier classes) and proposes each recognised
        field's default method, clamped by the same rules as
        `/api/v1/pipeline/protect/suggest` (keyFields columns only hmac or none;
        non-string source or destination types only drop or none).
        Deterministic: no model call. Stateless: nothing is saved and nothing is
        audited. Pass `preset` with either `pipeline` (its stored source schema
        and constraints are used) or `fields`. At most 150 fields per call;
        `_json` and `_xml` are skipped. A stored JSON, XML or unstructured
        pipeline is refused with 400. Needs the same capability as reading a
        pipeline. An aid to applying Safe Harbor, not a certification.
      requestBody:
        required: true
        content:
          application/json:
            schema:
              type: object
              required:
                - preset
              properties:
                preset:
                  type: string
                  enum:
                    - hipaa-safe-harbor
                pipeline:
                  type: string
                  description: Existing pipeline name (instead of fields)
                fields:
                  type: array
                  items:
                    type: object
                    required:
                      - name
                      - type
                    properties:
                      name:
                        type: string
                      type:
                        type: string
                      protect:
                        $ref: '#/components/schemas/FieldProtectionPolicy'
      responses:
        '200':
          description: The proposal
          content:
            application/json:
              schema:
                type: object
                properties:
                  preset:
                    type: string
                  fields:
                    type: array
                    description: One entry per recognised field, in input order
                    items:
                      type: object
                      properties:
                        name:
                          type: string
                        class:
                          type: string
                          enum:
                            - name
                            - geographic
                            - date
                            - phone
                            - fax
                            - email
                            - ssn
                            - mrn
                            - health_plan
                            - account
                            - license
                            - vehicle
                            - device
                            - url
                            - ip
                            - biometric
                            - photo
                            - other_id
                        method:
                          type: string
                          enum:
                            - hmac
                            - mask
                            - redact
                            - drop
                            - none
                          description: >-
                            `none` when a clamp leaves no method that can stand;
                            `reason` says why
                        preserve:
                          type: string
                          nullable: true
                          enum:
                            - last4
                            - domain
                            - year
                            - first3
                            - null
                        reason:
                          type: string
                        current:
                          nullable: true
                          description: The field's existing `protect`, or null
                          allOf:
                            - $ref: '#/components/schemas/FieldProtectionPolicy'
                  unclassified:
                    type: array
                    description: >-
                      Field names the table does not recognise, for a person to
                      review
                    items:
                      type: string
                  review:
                    type: array
                    description: >-
                      Notes for rules a method cannot express (ages over 89,
                      small-population ZIP prefixes, free text, unclassified
                      date-like fields)
                    items:
                      type: string
        '400':
          description: >-
            Missing or unknown preset, neither pipeline nor fields given,
            pipeline not found, more than 150 fields, or `pipeline` names a
            JSON, XML or unstructured pipeline (the preset needs a delimited
            source; pass the keys to check as `fields` instead)
          content:
            application/json:
              schema:
                type: object
                properties:
                  error:
                    type: string
        '500':
          description: Error
components:
  schemas:
    FieldProtectionPolicy:
      type: object
      description: >-
        Per-field protection applied after the preprocessor and before data
        quality, transformation, Live Read and every destination. `hmac`,
        `mask`, `redact` and `encrypt` require a `string` field on the source
        and on the destination schema; `drop` takes any type but cannot remove a
        `keyFields` column, and a `keyFields` column may only use `hmac`.
        Reserved methods (`fpe`, `tokenize`) are rejected as not yet supported.
        Empty values stay empty.
      required:
        - method
      properties:
        method:
          type: string
          enum:
            - hmac
            - mask
            - redact
            - drop
            - encrypt
          description: >-
            `hmac`: keyed HMAC-SHA256 pseudonym (lowercase hex) under the
            per-environment key; equal inputs give equal outputs. `mask`:
            replace characters with `*` (see `preserve`). `redact`: the value
            becomes `[REDACTED]`. `drop`: remove the column (or top-level JSON
            key) entirely. `encrypt`: AES-256-GCM ciphertext
            `enc:v<n>:<base64url>` bound to the pipeline and field, longer than
            the input; reversible only through `POST /api/v1/protect/reveal`
            with the `protect:reveal` capability.
        preserve:
          type: string
          enum:
            - last4
            - domain
            - year
            - first3
          description: >-
            Only with `method: mask`. `last4` keeps the last four characters,
            `domain` keeps `@` and the part after it, `year` keeps a leading
            4-digit year, `first3` keeps the first three characters (a value of
            three characters or fewer is masked entirely).
        params:
          type: object
          description: Reserved for method-specific options.
          additionalProperties:
            type: string
  securitySchemes:
    ApiKeyAuth:
      type: apiKey
      in: header
      name: x-api-key
      description: Optional API key for authentication (enabled via application.yaml)

````

This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.