Skip to content

AI Data Protection

An AI Gateway That Masks Personal Data in Every LLM Request

Change one base URL and your OpenAI, Anthropic, Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, or Ollama calls go through Maskflare: personal data and secrets are masked before they reach the provider.
mask path
  1. 01

    Request from your application

  2. 02

    Sensitive values masked

  3. 03

    Forwarded to the AI provider

500+

Built-in detectors for personal data and secrets

45

Country packs, checksum-validated where the format has one

9

AI providers behind one gateway, plus a no-code proxy

The problem

Every application that calls a model provider sends it data: the user's message, the conversation so far, and whatever retrieval or tools pulled in. In practice that includes customer names, emails, account numbers, health details, and the occasional API key pasted into a ticket.

Fixing this inside each application means re-implementing detection in every codebase and every language, and hoping each team keeps it current. Most don't, and nobody can tell which requests carried what.

A gateway moves the control to one place. Applications keep their provider SDKs; the gateway applies one set of rules to all of them, and records what it found without recording the data.

How Maskflare AI Gateway works

Each provider has a route on the gateway, such as /v1/openai or /v1/anthropic. Applications point their SDK's base URL at it and authenticate with a Maskflare key. The gateway scans the whole request body, including system prompts and tool arguments, applies each matching rule's action, and forwards the masked request with the provider key stored in the console or passed through per request. With response restoration turned on for the API key, tokens in the answer are swapped back for the real values, streaming included.

Benefits

One base URL per provider

Keep the provider's own SDK. Only the base URL and the API key change.

Whole-body inspection

System prompts, every message, tool arguments, and tool results are scanned, along with base64, hex, and percent-encoded text inside them.

Streaming supported

Streamed responses are masked, and values can be restored in OpenAI, Anthropic, and Gemini streams, tool calls included.

Deterministic embeddings

Embeddings inputs are masked so the same value always becomes the same token, keeping search over masked text consistent.

Clear block responses

A blocked request never reaches the provider. The client gets HTTP 403 with the matching rule keys, never the values.

Your choice on failure

If masking can't run, each organization decides whether requests go through and are flagged, or are blocked.

Capabilities

Providers

OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, and self-hosted Ollama.

Provider keys

Stored encrypted in the console, or sent per request in pass-through mode. Ollama needs none.

Batch and files

OpenAI batch input files are masked line by line; files in requests go through metadata stripping and the optional malware gate.

Traffic log

Per-request metadata: provider, model, status, and which rules matched how often. Never the prompt or the values.

Explore related capabilities

See how Maskflare applies the same masking rules to related AI and data-protection workflows.

Frequently asked questions

What is an AI gateway?

An AI gateway is a service that sits between applications and model providers, so policies such as masking, blocking, and logging apply to all AI traffic in one place instead of in each application.

Which providers does the Maskflare gateway support?

OpenAI, Anthropic, Google Gemini, Mistral, xAI, DeepSeek, Groq, Together AI, and self-hosted Ollama, each on its own route.

Do I have to change my code?

Only the client setup: the base URL points at your Maskflare gateway, and the API key is a Maskflare key. Calls to the SDK stay the same.

Are prompts stored?

No. Prompts and responses are processed in memory. Masked values are kept encrypted for 30 days so they can be restored, and only for the API key that created them.

Can the gateway restore the real values in the answer?

Yes, when response restoration is turned on for the API key. Tokens in the response are swapped back before your application receives it, streamed responses included.

See it on your own data

Book a 30-minute demo.
Bring your hardest prompts.

We'll show detection, masking, and restoration on your providers and data types,
and how it fits your stack.

Book a demo