All Products
Search
Document Center

Database Autonomy Service:Sensitive data identification

Last Updated:Aug 27, 2026

Database Autonomy Service (DAS) identifies sensitive data in databases across industries such as finance, energy, and automotive. You can use built-in identification templates to detect sensitive data in your instances, or create custom templates based on them.

Supported databases and regions

Databases

Regions

  • RDS MySQL

  • PolarDB for MySQL

  • RDS PostgreSQL

  • PolarDB-X 2.0

  • PolarDB for PostgreSQL

China (Hangzhou), China (Shanghai), China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Shenzhen), China (Chengdu), and China (Hong Kong)

PolarDB for PostgreSQL (Compatible with Oracle)

China (Hangzhou) and Malaysia (Kuala Lumpur)

Models and templates

image

Identification template

An identification template classifies and grades sensitive data according to industry standards, helping you verify compliance with security and regulatory requirements.

Identification models and identification features

Concept

Description

Identification model

An identification model consists of one or more identification features. It determines the final identification result and is configurable.

DAS provides built-in identification models for typical sensitive data and supports custom identification models.

Identification feature

An identification feature detects sensitive data based on content, metadata, or dictionaries. It uses rules that combine regular expressions and operators such as 'contains' and 'does not contain' to define data characteristics. You can link multiple rules with AND/OR operators for more flexible detection.

DAS provides built-in identification features for common sensitive data types and supports custom identification features.

Template classification and task rules

  • An identification task scans data in a connected database to discover sensitive data, generates a scan report, and applies classification and grading to the results.

  • An identification task requires an enabled identification template. There are three types of enabled identification templates: primary, active, and general-purpose.

  • When you add a custom identification task, you can select only one primary template and up to two active templates.

Template type

Description

Built-in template

Select a built-in template based on your business scenario. DAS provides templates for industries including finance, internal cloud security, power, Internet of Vehicles (IoV), and the general internet industry.

Custom template

If the built-in templates do not meet your requirements, you can create up to ten custom templates by configuring identification features and identification models.

Template role

Description

Primary template

This template is used by default for system tasks. The default primary template is the classification and grading template for the internet industry. A primary template cannot be disabled.

You can have only one primary template. You can set an active template as the primary template.

Identification results in the DAS console are based on the primary template.

Active template

You can enable built-in templates or custom templates as active templates. You can enable up to two active templates.

General-purpose template

A template based on the Personal Information Security Specification GB/T 35273-2020, a standard published by the Standardization Administration of China (SAC) for protecting personal information and privacy.

This template is the default only for identification tasks that use built-in templates.

Sensitivity levels

DAS sensitive data identification supports up to 10 sensitivity levels, from S1 to S10. A higher number indicates a higher sensitivity level.

  • In a built-in template, you cannot add or delete sensitivity levels. You can only edit the description.

  • In a custom template, you can add, edit, and delete sensitivity levels.

Identification templates and models

Template management

Built-in identification templates

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Identification Settings.

    By default, you are on the template management > Template Configuration tab. The Enabled identification templates area displays enabled templates as cards. The primary template is identified by the Primary tag. Supported operations include Set as Primary, View, and Disable. The Template Library area lists all built-in classification and grading templates and their statuses. You can use the switch to enable or disable a template, and perform operations such as Create Template, View, and Copy.

  3. In the template list at the bottom of the template management tab's Template Configuration page, find the identification templates whose Type is built-in.

  4. In the Status column, click the switch image or image to enable or disable the template.

  5. Click the Primary or Deactivate switch for an enabled identification template to set it as the primary template or to deactivate it.

    Note

    If you do not configure an identification template, the default primary template is the Classification and Grading Template for the Internet Industry.

Custom identification templates

Create

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Identification Settings.

  3. On the template management > Template Configuration page, click Create Template.

  4. On the Create Template page, configure the Basic Information (Template Name and Template Description), and then click Next.

  5. In the Configure Template Node section, click Create Category. In the dialog box that appears, enter a Category for the sensitive data and click OK.

    • Click the manage image icon to the right of the added category, and then click Add Sibling Category or Add Subcategory to add a sibling or subcategory.

      This menu also includes the Add Model and Delete options.

      Note

      Repeat this step to add multiple categories.

    • Repeat the following steps to add an identification model under the sensitive data category.

      1. Click the manage image icon to the right of the added category and click Add Model.

      2. In the Add Model dialog box, select the checkbox for the target identification model, set its status to enabled image, and then click OK.

        Important

        An identification model takes effect in tasks only after you enable it in the template.

        You can use the All models, All data labels, and All sources drop-down lists, or the model name search box to find a specific identification model.

Copy

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Identification Settings.

  3. On the template management > Template Configuration page, find the built-in or custom identification template that you want to copy and click Copy in the Operation column.

  4. In the dialog box, modify the Template Name and Remarks, and then click Confirm.

    Note

    You can click Edit in the Actions column for the new template to modify its name, model categories, and identification models.

Model management

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Identification Settings.

  3. Click the Identification Model tab, and then click Add Model.

  4. In the Add Model panel, configure the model parameters, and then click OK.

    Type

    Parameter

    Description

    Basic Information

    Model name

    The name of the model. The name must be unique.

    Model Description

    The description of the model.

    Tag

    Select a data label for the model. Valid values: sensitive personal information, Personal Information, and General Information.

    Data Category

    In the drop-down list, associate the new model with an identification template, a sensitive data category, and a risk level.

    You can associate the model only with custom identification templates.

    Model Rule

    Identification Features

    From the drop-down list, select the identification features for the model.

    • You can select built-in and custom identification features.

    • If you select multiple features, they are combined with OR logic.

    Identification Scope

    From the drop-down list, select the asset types where the model applies. By default, the model applies to authorized and accessible DAS assets.

    If you select multiple asset types, they are combined with OR logic.

    Advanced Settings

    Optional.

    1. From the drop-down list, select the asset type that you want to configure.

    2. Select how the conditions take effect. Valid values: AND and OR. To create multiple condition groups, click Add Group. The new group is a subset of the first group.

    3. Configure the identification conditions. To add more conditions, click Add Condition.

    Identification Threshold

    Minimum Hits (Unstructured Data)

    For unstructured data (such as NoSQL files), set the minimum number of times an identification feature must be found in a single file.

    If the match count in a single file meets this threshold, the file is classified as sensitive data.

    Hit Ratio (Structured Data)

    Set the hit rate for structured data (for example, RDS).

    If the percentage of matching records in a 200-record sample meets the specified hit rate, the data is classified as sensitive.

Other operations

  • View template details: Click Details in the Actions column for a template to view its rule configuration and identification threshold.

  • Delete an identification template: You can only delete custom identification templates, not built-in ones. In the Operation column of the target template, click the manage image icon, and then click Delete.

  • Manage model categories: You can only set model categories for custom templates. In the Actions column of the target template, click Edit.

  • Switch the enabled identification model: Switching the enabled identification model does not affect running tasks. The change takes effect for the next task execution.

Manage sensitive data identification

Prerequisites

Grant asset authorization to the target instance in the instance list.

Click the Cloud Instances tab, find the target instance, and click Enable in the Security Center column.

Identification tasks

System default task

When you authorize a database and select the default sensitive data identification scan task, DAS creates a default scan task for the database using the primary identification template.

Parameter

Description

Identification template

The system default task uses the primary identification template. This cannot be modified.

Note

If the primary identification template is a built-in identification template, the task also uses the general-purpose identification template.

Scan period (default)

If you select the default sensitive data identification scan task during instance authorization, the task runs immediately after you confirm.

Note

You can configure the scan period for the system default task. The minimum interval between two scans is 24 hours.

Scan scope

For authorized instance, database, and table names:

Note
  • The first scan of a database is a full scan of all authorized data.

  • Subsequent scans scan only incremental and modified data.

If you switch the primary identification template, a scan is not immediately triggered. The next scan uses the new identification template.

Scan limits

  • For structured data (such as ApsaraDB RDS for MySQL, ApsaraDB RDS for PostgreSQL, and PolarDB): By default, the first 200 rows of a table are sampled. You can manually change this value to a maximum of 1,000 rows. It scans only the first 10 KB of data in each field of each sampled row.

  • For large databases with more than 1,000 tables, the scan speed is 1,000 columns per minute.

Scan result

The scan result is the sensitivity level of the identification template. N/A indicates that the scan found no sensitive data.

Custom identification task

You can add a custom identification task to scan a specified database table using an enabled identification template. If the template you want to use is not enabled, enable it first.

  • Based on the custom scan scope and scan period, the first scan and any rescans are full scans. Periodic scans cover only new or modified data objects.

  • The scan result is the sensitivity level of the identification template. N/A indicates that the scan found no sensitive data.

image

Manage system default tasks

View default task

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Task Management.

  3. On the Task Management page, click the Identification Task tab, and then click System Default Task.

  4. On the Identification Task Monitoring page, view the list of default tasks.

  5. In the Actions column, you can perform the following operations on a system default task.

    • Rescan: Rescans all data. Use this action if the identification model is upgraded, you change the primary identification template, or the database content changes.

    • Pause: If a database service experiences problems, click Pause in the Actions column to temporarily stop the system default task that is running.

    • Stop: Prevents the task from running in the next period. If the task is currently running, stopping it does not affect the current run.

    • Enable: Re-enables a stopped task.

Adjust scan settings

System default tasks support periodic scanning. Set the scan period to match your database update frequency to detect sensitive data in new records. The minimum configurable scan period is 24 hours.

On the Discovery Task Monitoring page, select the checkbox for the desired task, click Scan settings above the task list, and configure the period and scan time.

Important
  • To minimize the impact of scanning on your database, set the scan start time to off-peak hours.

  • If you observe a spike in CPU or memory usage during a scan, pause or stop the task immediately. You can go to the Task Management page and click Pause or Stop in the Actions column to stop the scan.

Create custom task

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Task Management.

  3. On the Identification Tasks tab, select the asset type for which you want to create an identification task, and click Create.

    The navigation tree on the left groups asset types by data category, such as structured data. The groups include sub-items such as RDS, PolarDB, and PolarDB-X 2.0. Select the target asset type and click Create Identification Task on the right.

  4. In the Create panel, configure the task parameters, and then click Confirm.

    Category

    Parameter

    Description

    Identification Scope

    Identification Scope of Structured Data

    Select the scan scope for structured data, such as ApsaraDB RDS and PolarDB. Options:

    • Global Scan: Scans all your structured data assets.

    • Specify Scan Scope: Configure Instance Name, Database Name, and Scan Limit.

      • Configure the instance name and database name. To add multiple instances, click Add Identification Scope.

      • Configure Scan Limit. The first 200 rows are scanned by default, with a maximum of 1,000 rows.

    Other configurations

    Tagging Result Overwriting

    Specify how to handle detected sensitive data that has been previously corrected. Options:

    • Skip manual tagging results: Retains the original manual correction results. This option is recommended.

    • Overwrite manual tagging results: Overwrites the manual correction results with the new identification results.

  5. In the Operation column, you can perform the following operations on a custom identification task.

    • Rescan: Rescans all data. Use this action if the identification model is upgraded, you change the primary identification template, or the database content changes.

    • Suspend: If a database service experiences problems, click Pause in the Actions column to temporarily stop the task that is running.

    • Terminate: Prevents the task from running in the next period. If the task is currently running, stopping it does not affect the current run.

    • Enable: Re-enables a stopped task.

Manage custom tasks

You can create a custom identification task to scan a specific database with any enabled template, not just the primary template.

Important

The system supports a maximum of five active identification tasks. Each periodic scan task occupies one active task slot. After you configure five periodic tasks, you cannot create new identification tasks.

Correct results

The recovery operation restores the identification model to its state before correction.

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Task Management.

  3. On the Task Management page, click the Revision Tasks tab.

  4. In the left-side data type navigation pane, click the asset type that you want to correct.

  5. Click Correct or Recover in the Actions column for the target sensitive data. Follow the on-screen instructions to modify the Corrected model, and then click OK.

Identification results

After a sensitive data identification task completes, you can view and export the results on the Asset Overview page. Scan results refresh every 5 minutes.

View results

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Asset Insights.

  3. On the Asset Type tab, click the data type that you want to view.

    After you click the data type, sensitive data statistics for that asset type are displayed on the right, including Sensitive instances, Sensitive databases, Sensitive tables, and Sensitive columns, along with week-over-week changes. The data table below shows information for each instance, such as Instance ID/Name/UID, Region, Database type, Total DBs | Sensitive DBs, Sensitivity level, and Data label. You can expand an instance to view database-level sensitive data details and the last scan time. You can filter data by Region, Sensitivity level, and Instance ID, and click Table Details to view table-level information.

  4. To view the details of sensitive data in a data asset instance, click Table Details in the Actions column.

  5. In the details panel on the right, view the sensitive data statistics.

    The sensitive data statistics include: a Data classification and grading statistics donut chart (showing the proportion of each sensitivity level, such as S2 and S3), a Sensitive data label statistics donut chart (showing the distribution of categories such as Sensitive Personal Information, Personal Information, and General Information), a Data identification rate bar chart (showing the total number of columns, sensitive columns, and their ratio), and a Top 5 hit models horizontal bar chart (such as Personal Phone Number, Passport Number, and Mobile Number). Below the charts are Hit model and Sensitivity level drop-down filters and a search function. At the bottom, a data details table lists columns such as Table Name, Total Rows, Total Columns, Sensitive Columns, Data Labels, Hit Data, and Actions. You can click Column Details to view specific sensitive column information.

  6. In the sensitive data list, you can click Column details in the Operation column to view the rule details for data that was identified as sensitive in each column.

    If the Revision option is available in the Operation column, you can correct the sensitive data identification results.

    Taking the audit_log table as an example, the Column Details page displays information such as Column name, Data label, Identification result, Sensitivity level, Correction status, and Data sampling result. For example, the identification result for the id column is "Primary key", the sensitivity level is S1, and the correction status is "Not corrected". The Correct and Recover actions are available on the right side of each row.

Export results

  1. Log on to the DAS console.

  2. In the left-side navigation pane, choose Security Center > Sensitive Recognition > Task Management > Export Tasks.

  3. Click Create. Configure the export task, and then click OK.

    1. In the Basic information section, enter a task name and select the template used for the identification task. You can select only enabled templates.

    2. In the Export dimension section, select Asset type or Asset instance.

      • Asset type: Select all engine instances.

      • Asset instance: Select the engine instances whose data you want to export.

After you create an export task, you can view its status in the export task list. Larger datasets take longer to export.

Download results

Wait until the Export Status changes to Completed, and then click Download in the Actions column of the target export task.

Important

You must download the exported data within three days of task completion. After this period, the task expires and the data is no longer available for download.