02 / Privacy infrastructure · Pilot Preparation

A privacy boundary for your data flows.

PrivacyGuard is infrastructure for controlling sensitive information before it reaches external cloud, SaaS, API or AI services.

InspectEnforceTransformControl

Privacy Gateway

Before the data
crosses the boundary.

Applications route supported requests through inspection and executable policy. The result is transformed, permitted or denied before forwarding.

  1. 01

    Application

    Text or structured JSON

  2. 02

    PrivacyGuard Gateway

    Inspect the request

  3. 03

    Detect

    Find supported sensitive information

  4. 04

    Apply policy

    Evaluate configured rules

  5. 05

    Transform or deny

    Redact · Tokenize · Hash · Encrypt · Deny

  6. 06

    Approved service

    Only permitted data and destinations

Conceptual flow. Protection applies to supported detectors and configured fields; it does not guarantee that arbitrary text is free of all sensitive information.

Infrastructure, not just a dashboard

Controls in the processing path.

The dashboard configures the system. The Gateway and regional data-processing components implement the privacy boundary.

01

Sensitive-data inspection

The current local foundation covers email, phone and Moroccan ID candidates, custom patterns and explicit JSON field rules.

02

Executable policy

Published policies determine how detected and configured information is handled, including denial and transformation.

03

Privacy Vault

A distinct boundary for encrypted token mappings and credential handling, with scoped access.

04

Controlled recovery

Recovery is a separate, restricted operation. Response restoration is gated and remains under hardening; it is not an unrestricted lookup.

05

Audit evidence

Record processing and control events without storing raw request payloads in the evidence stream.

06

Destination controls

Use administrator-approved destinations and configured data-class and region constraints rather than arbitrary outbound URLs.

Deployment direction

Regional processing.
Provider-neutral design.

Keep sensitive processing, Vault data and recovery within configured regional boundaries.

The architecture separates control-plane administration from data-plane processing. Hosting and deployment controls must be verified before any live-data pilot.

Private, VPC and on-premise deployments are future directions, subject to supported packaging, operational readiness and customer requirements. Multi-region availability is not a current production claim.

Contextual intelligence

AI without surrendering
the privacy boundary.

Titrit detects and classifies.
PrivacyGuard decides and enforces.

Contextual PII detection could eventually use a private Titrit model through a clear service or library boundary. Sending sensitive context to external general-purpose AI would undermine part of the privacy objective.

That integration is a research direction. PrivacyGuard keeps policy and enforcement deterministic; a classifier does not get authority to change the rules.

Explore Titrit research

Let’s build what comes next

Keep control when your applications connect.

Talk to us about your sensitive-data workflows and requirements for a future controlled pilot.

Contact Base Workers