Every string on the ticket is redacted after it is trimmed and before it is stored. The same projection is what the model sees. The pre-redaction ticket is not stored.
subject, customerMessage, externalId, message text, and string values in metadata go through that replacement. Email is replaced first, then payment-like numbers, then phone numbers. Metadata numbers, booleans, and nulls stay as they are. createdAt and message at are times, and they are not rewritten.
A SHA-256 hex hash of the redacted JSON is stored with the evaluation. Simulations list that hash as ticketHash.
Redaction is a fixed set of patterns. It does not detect names, addresses, account ids, or free-text secrets that do not match those patterns. Keep those out of the ticket when they are not required to judge it.
Completion webhooks send the evaluation id and the result. They do not send the ticket. Stats do not include ticket text.