Control the data path
A dashboard can describe a policy. The processing path has to enforce it. PrivacyGuard is being developed as privacy infrastructure between applications and the external systems that process their data.
The conceptual path is application → Gateway → inspection → sensitive-data detection → policy → transformation or denial → approved service. The transformation choices include redaction, tokenization, hashing and encryption.
State the detection scope
The current local foundation covers deterministic email and phone detection, Moroccan ID candidates, custom patterns and explicit JSON field rules. Those are scoped capabilities, not a claim that arbitrary text becomes free of every possible type of personal information.
Contextual PII classification is a future research direction through Titrit. Names, addresses and ambiguous references require careful evaluation. Detection quality must be measured rather than inferred from a compelling demonstration.
Separate recovery from forwarding
Tokenization introduces a relationship between a token and protected information. A Privacy Vault is therefore a security boundary, not just a storage feature. Controlled recovery needs its own authorization and context.
PrivacyGuard’s recovery work remains gated and under hardening. The architecture is intended to restrict which values can be recovered, for whom and in which operation. An arbitrary token should not become permission to retrieve plaintext.
Audit evidence should explain processing and control decisions without becoming another copy of the raw request payload. Destination controls should constrain outbound processing to administrator-approved services and configured data classes.
Architecture and readiness are separate
Region-aware architecture makes it possible to configure where sensitive processing, Vault data and recovery occur. It does not prove that any particular region or private deployment is already operational.
PrivacyGuard remains in technical foundation, hardening and pilot preparation. Deployment, identity, operational and applicable legal gates must be verified before a live-data pilot. Technical privacy controls can support obligations; they do not automatically guarantee legal compliance.