Introducing Maskflare: Use AI Without Sending It Your Customer Data
Every team now sends text to AI models: support tickets, contracts, code, clinical notes, spreadsheets. Most of that text carries personal data or secrets that were never meant to leave the company, and the usual responses are a policy nobody can enforce or a ban nobody follows.
Maskflare takes a third route. It sits between your applications and employees and the AI providers they use, finds personal data and secrets in each request, replaces them with tokens before the request leaves, and can put the real values back in the answer. The model gets the context it needs. It doesn't get the data.
There are three ways in. Applications change one base URL to send OpenAI, Anthropic, Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, or Ollama traffic through the Maskflare gateway. Employees' AI traffic, including prompts typed into ChatGPT on the web, goes through the forward proxy with no code change. Pipelines that don't call a model directly, such as logs or tickets, call mask and unmask through the API or the Python SDK.
Detection is deterministic: 500+ built-in detectors across 45 country packs, with IBANs, payment cards, and national IDs checked against their real checksums, plus health identifiers, person names, and 230+ API-key and credential formats. Your own rules, dictionaries, and Exact Data Match on your customer records sit on top. Each rule decides what happens to a match: mask, redact, partially show, hash, encrypt, alert, or block.
Maskflare is hosted in the EU. Prompts and responses are never stored; the traffic log records which rules matched and how often, never the values. If you'd like to see it on your own providers and data, book a demo.
— The Maskflare Team