Security

Your data never reaches the model.

Server-side enforcement, self-hosted detection, and an audit trail for every decision. Built so your security team can verify it instead of taking our word for it.

Try Now
The Trust Boundary

Enforcement that lives on the server and not in the browser

Every message takes the same path. Detection, masking, and the encrypted map all run inside our boundary, so protection never depends on the client doing the right thing.

Raw text stops at our server. It is scanned and masked there, before a single token reaches the model provider, so only placeholders ever leave our boundary. An encrypted map, kept per chat, restores the real values when the conversation renders back to you.

Detection is self-hosted. The model that reads raw text runs on our own infrastructure, cached locally, and is never called out to a third-party inference API. It sits inside the same boundary as the database.

~ zerosight
$ detector endpoint
http://127.0.0.1:8111 · self hosted
$ outbound inference calls
none. placeholders only leave.
$ replacement map
encrypted at rest, per chat
$ raw text after scan
overwritten. masked form persists.
$
Built for Governance

Security controls that ship with every workspace

The real surfaces admins use to govern a workspace, working exactly as they do in the product.

Replacement map

Detected values become stable tokens the model can reason with.

json
{"[NAME-1]": "Jane Example","[EMAIL-1]": "jane@example.com","[SSN-1]": "000-00-0000","[CARD-1]": "4242 4242 4242 4242"}

PII audit logs

Every decision the gate makes lands in an append-only log. Review it, filter it, and export it when the audit asks.

ActionModeActorEntitiesRiskChatModel
MaskedSmart Mask
Jane Examplejane@example.com
NAMEEMAIL
18Q3 refund threadclaude-fable-5
BlockedBlock
Sam Cartersam@example.com
SSNDOB
42Vendor contract reviewgpt-5.6-sol
WarnedWarn
Mina Patelmina@example.com
CARDPHONE
27Payment support notesgrok-4-5
AllowedHighlight
Alex Morganalex@example.com
NAMEPHONEADDRESS
11Customer renewal plangpt-5.6-terra

Admin enforced policies

Admins decide which models and modes a workspace may use.

ModelEffortPrice / MSelect
GPT-5.6 Sol
Low to High$5.00 / $30.00
GPT-5.6 Terra
Low to High$2.50 / $15.00
GPT-5.6 Luna
Low to High$1.00 / $6.00
GPT-5.5
Low to High$5.00 / $30.00

Workspace labels

Choose which entity groups the scanner enforces, workspace-wide.

GroupEntitiesSelect
Financial
CARDBANK ACCOUNTROUTING+1
Health
MRNDIAGNOSISMEDICATION+1
Identity
SSNPASSPORTDOB+2
Contact
EMAILPHONEADDRESS+1
Digital
API KEYPASSWORDACCESS TOKEN+1
Employment
EMPLOYEE IDSALARYJOB TITLE+1
Legal
CASE NUMBERATTORNEYCOURT+1
PII Modes

Pick how strictly every chat is enforced

Each chat runs in one mode, locked at creation and set by workspace policy. The same message, handled four different ways.

Smart Mask

Values become stable tokens before the message leaves. The reply is restored on screen for the reader.

Process a refund for Jane Cooper, card 4242 4242 4242 4242.
Refund processed for Jane Cooper, card 4242 4242 4242 4242.
generated using GPT-5.6 Sol
Email the receipt to jane@example.com.
Done. The receipt went to jane@example.com.
generated using GPT-5.6 Sol

Block

Sending pauses when sensitive data is found. Nothing leaves until it is redacted or removed.

Process a refund for Jane Cooper, card 4242 4242 4242 4242.
Refund processed for Jane Cooper, card 4242 4242 4242 4242.
generated using GPT-5.6 Sol
Email the receipt to jane@example.com.

Sensitive data detected

This message contains sensitive data.

EditDeleteSend Redacted

Warn

The send pauses and the user decides. The original text goes through only after Send Anyway.

Process a refund for Jane Cooper, card 4242 4242 4242 4242.
Refund processed for Jane Cooper, card 4242 4242 4242 4242.
generated using GPT-5.6 Sol
Email the receipt to jane@example.com.

Review before sending

This message contains sensitive data.

EditDeleteSend RedactedSend Anyway

Highlight

Values are highlighted for visibility and the message goes through unchanged. The model sees it verbatim.

Process a refund for Jane Cooper, card 4242 4242 4242 4242.
Refund processed for Jane Cooper, card 4242 4242 4242 4242.
generated using GPT-5.6 Sol
Email the receipt to jane@example.com.
Done. The receipt went to jane@example.com.
generated using GPT-5.6 Sol
Controlled Data Protection

Built for the people accountable when AI meets data

IT leadership, data protection, compliance, security operations, and the teams doing the work. Each gets the control their role answers for.

IT Leadership

Adopt AI without surrendering control. Policy, models, and modes stay decided at the top and apply to every chat the same way.

Data Protection Officers

Detection runs on our own infrastructure and raw text is purged after masking. Replacement maps stay encrypted and retention windows stay yours.

Compliance and Legal

Every masking decision lands in an append-only log with CSV and PDF exports ready for review. Audit answers come from records, not recollection.

Security Operations

Enforcement runs server-side where it cannot be clicked away. Role-based access and usage logging cover every workspace surface.

Workspace Admins

Model allowlists, enforced modes, and label groups apply workspace-wide from one settings surface. No member can opt out.

Department Teams

Members just chat. Masking, placeholders, and restores happen around the conversation, so everyday work keeps its pace.

Maximum security

Productive AI, without the data leaks.

Get Started Today