Sensitive-data inspection
The current local foundation covers email, phone and Moroccan ID candidates, custom patterns and explicit JSON field rules.
02 / Privacy infrastructure · Pilot Preparation
PrivacyGuard is infrastructure for controlling sensitive information before it reaches external cloud, SaaS, API or AI services.
Privacy Gateway
Applications route supported requests through inspection and executable policy. The result is transformed, permitted or denied before forwarding.
Text or structured JSON
Inspect the request
Find supported sensitive information
Evaluate configured rules
Redact · Tokenize · Hash · Encrypt · Deny
Only permitted data and destinations
Conceptual flow. Protection applies to supported detectors and configured fields; it does not guarantee that arbitrary text is free of all sensitive information.
Infrastructure, not just a dashboard
The dashboard configures the system. The Gateway and regional data-processing components implement the privacy boundary.
The current local foundation covers email, phone and Moroccan ID candidates, custom patterns and explicit JSON field rules.
Published policies determine how detected and configured information is handled, including denial and transformation.
A distinct boundary for encrypted token mappings and credential handling, with scoped access.
Recovery is a separate, restricted operation. Response restoration is gated and remains under hardening; it is not an unrestricted lookup.
Record processing and control events without storing raw request payloads in the evidence stream.
Use administrator-approved destinations and configured data-class and region constraints rather than arbitrary outbound URLs.
Deployment direction
Keep sensitive processing, Vault data and recovery within configured regional boundaries.
The architecture separates control-plane administration from data-plane processing. Hosting and deployment controls must be verified before any live-data pilot.
Private, VPC and on-premise deployments are future directions, subject to supported packaging, operational readiness and customer requirements. Multi-region availability is not a current production claim.
Contextual intelligence
Titrit detects and classifies.
PrivacyGuard decides and enforces.
Contextual PII detection could eventually use a private Titrit model through a clear service or library boundary. Sending sensitive context to external general-purpose AI would undermine part of the privacy objective.
That integration is a research direction. PrivacyGuard keeps policy and enforcement deterministic; a classifier does not get authority to change the rules.
Explore Titrit researchLet’s build what comes next
Talk to us about your sensitive-data workflows and requirements for a future controlled pilot.