02 / PRIVACY & GUARDRAILS

Sensitive data.
Deliberate boundaries.

Make data handling part of the AI request path. We engineer detection and redaction controls around the information you handle, the tasks you support and the risk you need to manage.

Discuss your engineering priorities ARCHITECTURE THROUGH TO OPERATION

A policy that can be tested and explained.

Inspection needs a defined scope, measurable detection behaviour and a clear decision when the control cannot complete.

Data policy / inspection / permitted outcomes

  1. 01

    Define scope

    Identify approved fields, data categories, formats and destinations.

  2. 02

    Detect

    Combine suitable recognisers, patterns and domain-specific tests.

  3. 03

    Decide

    Redact, replace or reject according to the application’s data policy.

  4. 04

    Inspect outputs

    Apply appropriate response controls and limit sensitive tracing.

Policy-controlled outcomes

  • TRANSFORM

    Masked content

    Contact: [PERSON_01] · email: [EMAIL_01]. Illustrative placeholders, with no real personal data.

  • REJECT

    Blocked request

    Stop content that remains outside the permitted data policy.

  • FAILURE PATH

    Control unavailable

    Follow a defined failure policy rather than silently skipping inspection.

Record policy versions and decisions with minimised metadata. Avoid copying raw sensitive content into the audit trail.

Illustrative flow. Control placement and integration boundaries are designed around your workload.

Controls shaped
around your information.

PII and secret detection

Scope personal information, identifiers and credentials separately. Test supported languages and formats, including realistic misses and ambiguous matches.

Redaction and replacement

Choose between removal, placeholders and controlled replacement. Check that the remaining context still supports the intended task.

Request and response boundaries

Decide where inspection belongs across applications, gateways and specialist services. Account for documents, tool outputs and streaming behaviour.

Evidence and operations

Version recognisers and policies, minimise payload logging and establish escalation, access and retention rules for inspection evidence.

Detection is one control
in a wider design.

No detector identifies every sensitive item in every context. We evaluate false negatives and false positives using data representative of your domain, then combine inspection with access controls, data minimisation and approved destinations.

Integration options include Kong’s PII sanitization capabilities and specialist services built with tools such as Presidio. Product edition, deployment mode, service dependencies and supported payloads are checked before choosing an implementation.

Decisions worth getting right.

Can you guarantee that no personal data reaches a model?

No. Redaction needs testing and ongoing review, and it can miss data or remove useful information. We design layered controls and clear permitted data flows rather than treating a detector as a guarantee.

Does redaction make an AI application compliant?

A technical control does not establish compliance by itself. We implement the data handling policies agreed with your security, privacy and governance teams and provide evidence of how the controls behave.

Can prompts and responses be inspected?

Yes, where the chosen integration supports the relevant formats. Streaming, attachments and tool results may need different control points. We establish those boundaries explicitly during design.

Put data boundaries
into the design.

Bring us a workload, a technical constraint or an architecture that needs a second look. We will help define a practical next step.

Discuss your engineering priorities

Architecture advice, focused implementation and support for your engineering team.