AI Data Protection
An AI Gateway That Masks Personal Data in Every LLM Request
- 01
Request from your application
- 02
Sensitive values masked
- 03
Forwarded to the AI provider
500+
Built-in detectors for personal data and secrets
45
Country packs, checksum-validated where the format has one
9
AI providers behind one gateway, plus a no-code proxy
The problem
Every application that calls a model provider sends it data: the user's message, the conversation so far, and whatever retrieval or tools pulled in. In practice that includes customer names, emails, account numbers, health details, and the occasional API key pasted into a ticket.
Fixing this inside each application means re-implementing detection in every codebase and every language, and hoping each team keeps it current. Most don't, and nobody can tell which requests carried what.
A gateway moves the control to one place. Applications keep their provider SDKs; the gateway applies one set of rules to all of them, and records what it found without recording the data.
How Maskflare AI Gateway works
Each provider has a route on the gateway, such as /v1/openai or /v1/anthropic. Applications point their SDK's base URL at it and authenticate with a Maskflare key. The gateway scans the whole request body, including system prompts and tool arguments, applies each matching rule's action, and forwards the masked request with the provider key stored in the console or passed through per request. With response restoration turned on for the API key, tokens in the answer are swapped back for the real values, streaming included.
Benefits
One base URL per provider
Keep the provider's own SDK. Only the base URL and the API key change.
Whole-body inspection
System prompts, every message, tool arguments, and tool results are scanned, along with base64, hex, and percent-encoded text inside them.
Streaming supported
Streamed responses are masked, and values can be restored in OpenAI, Anthropic, and Gemini streams, tool calls included.
Deterministic embeddings
Embeddings inputs are masked so the same value always becomes the same token, keeping search over masked text consistent.
Clear block responses
A blocked request never reaches the provider. The client gets HTTP 403 with the matching rule keys, never the values.
Your choice on failure
If masking can't run, each organization decides whether requests go through and are flagged, or are blocked.
Capabilities
Providers
OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, and self-hosted Ollama.
Provider keys
Stored encrypted in the console, or sent per request in pass-through mode. Ollama needs none.
Batch and files
OpenAI batch input files are masked line by line; files in requests go through metadata stripping and the optional malware gate.
Traffic log
Per-request metadata: provider, model, status, and which rules matched how often. Never the prompt or the values.
Explore related capabilities
See how Maskflare applies the same masking rules to related AI and data-protection workflows.
Frequently asked questions
What is an AI gateway?
An AI gateway is a service that sits between applications and model providers, so policies such as masking, blocking, and logging apply to all AI traffic in one place instead of in each application.
Which providers does the Maskflare gateway support?
OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, and self-hosted Ollama, each on its own route.
Do I have to change my code?
Only the client setup: the base URL points at your Maskflare gateway, and the API key is a Maskflare key. Calls to the SDK stay the same.
Are prompts stored?
No. Prompts and responses are processed in memory. Masked values are kept encrypted for 30 days so they can be restored, and only for the API key that created them.
Can the gateway restore the real values in the answer?
Yes, when response restoration is turned on for the API key. Tokens in the response are swapped back before your application receives it, streamed responses included.
See it on your own data
Book a 30-minute demo.
Bring your hardest prompts.
We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.