Product updates

    What's new in Privaro

    Every release, every fix, every improvement — documented here.

    September 2026

    v1.0

    Retrieval Guard & Document Ingestion Pipeline

    PII protection for RAG pipelines, asynchronous document ingestion and partner sub-account provisioning.

    FeatureInfrastructure
    • ✨ Privaro Retrieval Guard — POST /v1/proxy/protect-retrieval. PII protection for RAG pipelines. Scans retrieved chunks before they are injected into LLM context. Prevents PII from knowledge bases reaching models even when the original documents were ingested without protection. SDK: protect_retrieval() in Python SDK v0.7.0 and JS SDK v0.6.0.
    • ✨ Privaro Ingest — async document ingestion pipeline. Asynchronous ingestion worker (separate Railway service) for large document indexing. Consumes the ingestion_jobs table. Runs in an isolated process to prevent ONNX Runtime crashes from affecting the live API. Supports PDF, DOCX, XLSX, CSV, EML up to 20MB. SDK: protect_document() in Python SDK v0.6.0 and JS SDK v0.5.0.
    • ✨ Partner API — sub-account provisioning. Partners (ISVs) can now create and read sub-accounts programmatically via POST /v1/partner/sub-accounts. Permissions: partner:read_children / partner:write_children. Enables zero-touch client onboarding from a partner's backend.
    • ⚡ Web — comparison pages + badges. Two new competitor comparison pages added. AlternativeTo and LaunchNest badges added to homepage. LinkedIn added to footer. Google Analytics GA4 events on Auth and Demo flows.

    August 2026

    v0.13

    Image Document Protection & OCR

    Protect photographed or scanned documents with OCR-backed PII detection and redacted image output.

    FeatureSecurity
    • ✨ POST /v1/proxy/protect-image-document. Protect photographed or scanned documents (DNI, contracts, screenshots). Tier 1 OCR via Tesseract extracts text, detects PII, and returns both the protected text and a redacted image with PII regions blacked out. Tier 2 OCR (Google Cloud Vision) available as fallback for low-confidence results. Supports JPEG, PNG, WebP, TIFF up to 15MB.
    • ✨ New entity types: license_plate, address. License plate added as a direct identifier. Address entity type added — resolves overlap conflict with full_name when a street is named after a person.
    • 🔐 Spanish DNI/NIE checksum verification. DNI and NIE control letters now verified via the real mod-23 checksum algorithm. Confidence adjusted accordingly. Eliminates false positives on digit sequences that look like DNIs but are mathematically invalid.

    August 2026

    v0.12

    Output-Direction PII Detection & Context Optimization

    LLM responses are now scanned for PII, plus token-preserving context compression and critical performance fixes.

    FeaturePerformanceFix
    • ✨ Output-direction PII detection. LLM responses are now scanned for PII before being returned to the caller. Catches data leaks in the output direction — not just inputs. Available in /v1/agent/protect and /v1/relay/stream. SDK: protect_output() in Python SDK v0.5.0 and JS SDK v0.4.0.
    • ✨ Context Optimization — token compression. Privaro tokens are extracted before compression and restored byte-for-byte after, preserving de-tokenisation correctness. Uses Headroom/Kompress for prose compression. Reduces context size before LLM calls without breaking the token map.
    • 🐛 fix(CRITICAL) — Context Optimization event loop block. compress_protected_messages() was blocking the entire asyncio event loop. Moved to thread executor.
    • 🐛 fix(CRITICAL) — Kompress warmup checked wrong object. warmup_kompress() and the /health kompress_ready check both warmed a throwaway instance disconnected from the actual pipeline singleton. Context Optimization had silently never worked in production. Fixed by reaching into the real pipeline singleton.
    • 🐛 fix(CRITICAL) — Detector O(n²) overlap check. The overlap deduplication in detector.py was O(n²). Fixed to O(n) — 16.6x speedup measured at 1M characters in production smoke tests.
    • 🐛 fix — OpenAI o1/o3/gpt-5 compatibility. These models require max_completion_tokens instead of max_tokens and reject the temperature parameter. Both now handled automatically by the LLM router.

    July 2026

    v0.11

    n8n Community Node & JS/TS SDK

    Native n8n integration, official JavaScript/TypeScript SDK and verified integration examples.

    FeatureIntegration
    • ✨ n8n community node — n8n-nodes-privaro. Install directly from the n8n UI (Settings → Community Nodes → n8n-nodes-privaro). Operations: Detect, Protect, Chat Completion (Relay), Detokenize. Understands Privaro's token/conversation_id model natively. npm: n8n-nodes-privaro.
    • ✨ JS/TS SDK — privaro-sdk (npm). JavaScript/TypeScript SDK for Node.js and edge runtimes. Zero runtime dependencies — uses built-in fetch. Adapters for OpenAI, LangChain, Vercel AI SDK. npm install privaro-sdk.
    • ✨ Integration example repositories. Official example repositories published for LangChain, CrewAI, OpenAI Agents, and n8n. Each includes a working .env.example and verified API contract. Full Agent API guide at github.com/Maperez1972/privaro-agents.

    July 2026

    v0.10

    Streaming Relay & SDK v0.3

    SSE streaming from any LLM provider with PII protection on both directions.

    FeatureFix
    • ✨ Streaming relay — POST /v1/relay/stream. Server-Sent Events (SSE) streaming from any LLM provider. PII tokenised before the request, output scanned post-stream for leaks. Token map resolved on stream close.
    • ✨ Python SDK v0.3.0. relay() and relay_stream() methods added. Critical auth bug fixed in AgentRun (both sync and async). PyPI publish workflow via OIDC Trusted Publishing.

    May 2026

    v0.9

    AI Risk Assessment, Leads Dashboard & NLP Fixes

    New conversion landing, admin leads dashboard and NLP false-positive fixes.

    FeatureFixSecurity
    • ✨ AI Risk Assessment page — /ai-risk-assessment. New conversion landing. Lead capture with role, company size and AI tools fields. Leads stored in demo_requests and notified to contact@privaro.ai.
    • ✨ Admin Leads dashboard — /app/admin/leads. View, filter and act on leads from AI Risk Assessment and Beta forms. Detail drawer with mailto actions. Accessible to admin and DPO roles.
    • ✨ Home conversion update. Hero rewritten: "Control what your team sends to AI". Primary CTA redirected to /ai-risk-assessment.
    • 🐛 NLP engine — false positive fixes. Confidence threshold raised 0.65 → 0.75. Added post-NLP full_name filter: ≥ 2 consecutive capitalised tokens required. Fixed DNI span with capturing groups, ALL_CAPS stop set, flexible phone regex.
    • 🔐 Supabase explicit GRANTs. Adopted new Supabase default privileges model ahead of the October 2026 enforcement deadline. New tables in public schema now require explicit GRANT statements.
    • 🐛 DPO Report — period filter fixed. Reports now scoped to the selected date range. Previously all reports returned the same all-time dataset.
    • 🐛 Dashboard — Requests & PII chart fixed. PII Detected was always 0. PII Protected equalled total requests. Both now correctly reflect tokenised and anonymised events only.

    May 2026

    v0.8 — SDK JS

    JavaScript / TypeScript SDK published

    Full-featured SDK for Node.js and browser environments. Drop-in adapters for OpenAI, LangChain and Vercel AI SDK.

    SDKFeature
    • privaro-sdk published to npm — zero runtime dependencies, native fetch
    • PrivaroClient: protect(), detect(), relay() and AgentRun for multi-step sessions
    • wrapOpenAI() adapter — same API surface, PII protected automatically
    • PrivaroCallbackHandler for LangChain and privaroMiddleware() for Vercel AI SDK

    April 2026

    v0.7 — Webhooks + ISV

    Outbound webhooks and ISV / white-label model

    Privaro can now push real-time events to your stack. ISVs can embed Privaro in their own products with revenue share.

    FeatureSecurity
    • Webhook dispatcher — 4 events: high_risk, run_completed, pii_blocked, pii_detected
    • Tables org_webhooks + webhook_deliveries with delivery history and retry logic
    • Partners page /partners with embedded and white-label model
    • ISV pricing model with 20% recurring monthly discount

    March 2026

    v0.6 — Multi-provider

    Multi-provider routing and BYOK

    Route tokenised prompts to any LLM provider using your own API keys. Privaro never sees them.

    FeatureInfrastructure
    • Multi-provider routing /v1/relay/complete — OpenAI, Anthropic, Mistral, Groq
    • BYOK: customer API keys stored encrypted (AES-256-GCM), decrypted only at request time
    • Token Vault UI at /app/admin/vault for admin and DPO roles

    March 2026

    v0.5 — MFA + DPO

    MFA enforcement and DPO Report

    Mandatory two-factor for privileged roles and exportable compliance reports for DPOs.

    FeatureSecurity
    • TOTP MFA enforced for admin and DPO roles via enforce-mfa edge function
    • DPO Report with date range selector and exportable PDF
    • Top Risk Events widget — 7-day window, risk score ≥ 0.4
    • Dashboard timeseries — PII Detected vs PII Protected over time

    February 2026

    v0.4 — Agents

    AI agent support and Python SDK

    Protect every step of your agent pipeline. Python SDK v0.2 with LangChain and CrewAI integrations.

    Feature
    • AgentRun and AsyncAgentRun with shared token scope across turns
    • CrewAIPrivaroTool and LangChain callback handler
    • /use-cases/agents page with ISV framing

    February 2026

    v0.3 — Core proxy

    Hybrid PII detection engine

    Tier 1 regex + Tier 2 Presidio NLP. Blockchain certification on every audit log entry.

    InfrastructureSecurity
    • 10 entity types: DNI, IBAN, email, phone, full_name, credit_card, IP, SSN, health_record, date_of_birth
    • iBS blockchain certification — tamper-proof hash per event via iCommunity Blockchain
    • ISMS ISO 27001:2022 documentation — 6 control documents

    Want to be the first to know about new features?

    Start your free trial and get product updates