DeepSeek integration
Mask personal data before it reaches DeepSeek
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results
- Streaming responses
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
DeepSeek's pricing makes it attractive for high-volume workloads such as classification, extraction, and summarisation, which are also the workloads that process the most customer records. DeepSeek is based in China, so what you send its hosted API is a data-transfer question as well as a privacy one.
Maskflare lets you use the model without sending it the data. Requests go through your gateway, names, identifiers, and secrets become tokens, and the model works on the masked text.
Set up DeepSeek with Maskflare
Requests go to /v1/deepseek on your Maskflare gateway instead of the provider.
from openai import OpenAI
client = OpenAI(
base_url="https://YOUR_GATEWAY_HOST/v1/deepseek",
api_key="mf_live_...", # a Maskflare key
)
reply = client.chat.completions.create(
model="deepseek-chat",
messages=[{"role": "user", "content": "Extract the order number from: Hi, I'm Ana Lopez, IBAN ES91 2100 0418 4502 0005 1332"}],
)What gets masked
- Every text field in the request body: user and system messages, tool and function-call arguments, and tool results
- Streaming responses
- Base64, hex, and percent-encoded text inside the request is decoded and checked too
Good to know
- A rule set to block stops the request before it reaches the provider and returns HTTP 403 with the matching rule keys, never the values.
- To keep a model provider entirely out of reach for some data types, set those rules to block rather than mask.
- Store the provider key once in the Maskflare console, or keep sending it per request in pass-through mode.
- No code change option: the Maskflare forward proxy inspects traffic to api.deepseek.com with the same rules.
Frequently asked questions
Is it safe to use DeepSeek with customer data?
That is your organisation's decision. Maskflare lets you send DeepSeek masked text only, so the personal data and secrets your rules cover never reach the provider.
Can we block DeepSeek for some teams only?
Yes. Rules apply per environment, and each API key belongs to one environment, so different teams can run different policies.
Does the OpenAI SDK work with DeepSeek through Maskflare?
Yes. DeepSeek's API is OpenAI-compatible; set the base URL to your gateway's /v1/deepseek route.
Other providers
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.