Sensitive data is embedded throughout the logs, events, payloads, and other telemetry generated by modern systems. Detecting it accurately at scale is challenging, especially when false alarms create more noise for teams to investigate.
Cribl Guard background detection uses Cribl’s purpose-built AI models, trained to identify sensitive data in telemetry and continuously improved as machine data evolves.
The Cribl Guard Privacy 3.0 model family is focused on delivering a better detection experience, with fewer false alarms and more actionable findings. It adds two key advancements: per-entity thresholds and a new Pro model.
More precise detection with per-entity thresholds
An entity is a specific type of sensitive information, such as a credit card number, API key, password, email address, or phone number, that the model is trained to identify.
Previous Guard model versions applied one default threshold across all entity types. With Privacy 3.0, we introduced tailored thresholds for each entity, allowing the model to make more informed precision and recall trade-offs.
This matters because different entities have different patterns and levels of ambiguity. A single sensitivity setting may be too aggressive for one entity and too conservative for another, leading to unnecessary false alarms.
The result is a more actionable set of findings, with fewer benign values incorrectly identified as sensitive. In our benchmark comparison, precision improved across all three Privacy 3.0 tiers, increasing by 9.84 percentage points for Base, 17.69 points for Fast, and 13.16 points for Pro.
A new model for deeper detection
Privacy 3.0 also introduces Pro, a higher-accuracy model designed for workloads where deeper detection is more important than maximum scanning speed.
Teams can choose from three models:
Fast is optimized for high-volume telemetry and the highest scanning throughput.
Base provides a balanced option for mixed workloads.
Pro is designed for deeper detection and the strongest precision and F1 profile.
This gives organizations a clearer way to align model selection with workload volume, risk tolerance, and available compute.
Improved quality and performance
Compared with Privacy 2.0, precision and F1 improved across every tier:
Throughput improvement is shown for batch sizes 1 and 8 under the tested benchmark conditions.
Higher precision means a greater share of findings are likely to represent real sensitive-data detections rather than benign values that teams have to investigate or tune out. In other words, fewer false alarms and a cleaner set of findings to work from. F1 provides a combined view of precision and recall to help compare overall detection quality.
The benchmark also shows an important trade-off: recall was lower at the tested Privacy 3.0 operating points, while precision improved. For background detection, that shift is designed to reduce unnecessary noise and make the findings surfaced to teams more actionable.
Choosing the right Privacy 3.0 model
The right model depends on what matters most for each workload:
Choose Fast when scanning volume and throughput are the primary constraints.
Choose Base for a balance of quality and performance.
Choose Pro when deeper detection and higher precision are worth additional compute or lower throughput.
A more flexible foundation for protecting telemetry
Cribl Guard Privacy 3.0 improves the quality and flexibility of background detection by tuning sensitivity to the entity being detected and offering model tiers for different operational needs.
Most importantly, it helps reduce the false alarms teams have to sort through, giving them a cleaner, more actionable view of where sensitive data may be showing up across their telemetry.
Learn more about Cribl Guard background detection and how it can help you use AI to continuously uncover unknown sensitive data across your telemetry.
Want to see more ways to put AI to work across your data management workflows? Check out our Beyond the Paralysis: Practical AI Workflows in Observability session coming up at CriblCon.








