Privaro's privacy infrastructure is built on the principle that security controls must be architectural โ not application-layer afterthoughts.
Architecture
Privacy controls are applied at the network layer โ before any data reaches an AI model. This is architecturally superior to post-processing or application-level filtering.
No plaintext personal data is ever transmitted to an AI provider. Tokenization occurs within Privaro's trusted boundary. Original values are stored exclusively in the encrypted vault.
Audit records are cryptographically certified on Fantom Opera Mainnet. Compliance is demonstrable to regulators independently of Privaro's infrastructure.
Security controls are layered: TLS 1.3 at the network level, JWT + API key auth at the application level, Row Level Security at the database level, AES-256-GCM at the data level.
Every entity type has a configurable action: tokenise, anonymise, or block. Sector presets for Legal, Healthcare, Fintech, HR, and Port Environmental are built-in.
Autonomous AI agents operate under the same privacy policies as human users. The Agent API enforces governance at every step of automated workflows โ EU AI Act compliant.
Every agent step is intercepted before reaching the LLM. PII is detected and tokenised per step, not per session. Each interaction generates an iBS blockchain certificate โ immutable proof of what the agent processed and what the model never saw.
Enterprise clients manage their own encryption keys. Privaro never stores key material โ only a secure reference. Keys can be rotated, revoked, and audited independently per organisation via the admin panel.
Controls
Key technical controls aligned to ISO/IEC 27001:2022 Annex A and SOC2 Trust Services Criteria.
NLP Privacy Engine
Combines deterministic regex with neural NLP models to maximise recall on structured PII and precision on unstructured entities.
Deterministic detection of structured PII: DNI/NIE, IBAN, credit cards, phone numbers, emails, IPs, passport numbers. Zero false negatives on known formats.
Context-aware detection of unstructured PII: full names, organisations, locations, dates. Confidence threshold โฅ0.75 with post-NLP filters to eliminate false positives in legal and technical documents.
Every agent step runs through the full detection pipeline before reaching the LLM. PII is tokenised, the step is certified on blockchain, and an iBS signature is generated per interaction โ not per session.
Compliance
Privaro is designed to help enterprise customers meet their data protection obligations under multiple regulatory frameworks.
| Regulation | Scope | Privaro Coverage | Status |
|---|---|---|---|
| GDPR Art.5 | Data minimization, purpose limitation | Policy engine enforces minimum necessary processing. No raw PII to LLMs. | Covered |
| GDPR Art.9 | Special category data (health, biometric) | health_record entity blocked or anonymised by default in Healthcare/HR presets. | Covered |
| GDPR Art.30 | Records of processing activities | Blockchain-certified audit log per interaction. DPO report export with TX hashes. | Covered |
| EU AI Act | High-risk AI systems, human oversight | Agent API enforces governance on autonomous agents. Per-entity action in audit logs. | Covered |
| PSD2 | Payment data protection | IBAN and card numbers tokenized before any LLM call. Fintech preset built-in. | Covered |
| HIPAA | Protected Health Information | PHI tokenized/anonymised. Blockchain audit trail per PHI access. Healthcare preset. | Covered |
| ISO 27001:2022 | Information security management | 83% of Annex A controls implemented. ISMS documentation in progress. | In Progress |
| SOC2 Type I | Security, Confidentiality trust criteria | Controls implemented. Formal audit preparation in progress for Q3 2026. | In Progress |
Blockchain Audit Trail
Every audit event is cryptographically certified on Fantom Opera Mainnet โ independently verifiable by regulators, auditors, and data subjects.
Every PII detection event generates an audit record. The record's SHA-512 hash is certified on Fantom Opera Mainnet via iBS API. The resulting blockchain TX hash is stored in the audit log.
Batch certification reduces costs: up to 100 audit events are certified in a single blockchain transaction every 5 minutes.
Any certified event can be independently verified using the TX hash โ no access to Privaro's infrastructure required.
Policy Documents
Privaro maintains a complete set of security policies aligned to ISO 27001 and SOC2 requirements. Available to enterprise customers under NDA.
Our team is available to answer security questionnaires, complete vendor assessments, or schedule a technical deep-dive.