๐Ÿ”’ Security & Compliance

    Enterprise-grade security
    by design, not by policy

    Privaro's privacy infrastructure is built on the principle that security controls must be architectural โ€” not application-layer afterthoughts.

    AES-256-GCM EncryptionBlockchain-Certified Audit TrailGDPR Art.5 CompliantTLS 1.3 EnforcedSOC2 Type I โ€” In PreparationISO 27001 โ€” In Preparation

    Architecture

    Security built into every layer

    Privacy controls are applied at the network layer โ€” before any data reaches an AI model. This is architecturally superior to post-processing or application-level filtering.

    ๐Ÿ”

    Zero Raw PII Exposure

    No plaintext personal data is ever transmitted to an AI provider. Tokenization occurs within Privaro's trusted boundary. Original values are stored exclusively in the encrypted vault.

    โ›“๏ธ

    Verifiable Compliance Evidence

    Audit records are cryptographically certified on Fantom Opera Mainnet. Compliance is demonstrable to regulators independently of Privaro's infrastructure.

    ๐Ÿ›ก๏ธ

    Defense in Depth

    Security controls are layered: TLS 1.3 at the network level, JWT + API key auth at the application level, Row Level Security at the database level, AES-256-GCM at the data level.

    โš™๏ธ

    Policy-Driven Governance

    Every entity type has a configurable action: tokenise, anonymise, or block. Sector presets for Legal, Healthcare, Fintech, HR, and Port Environmental are built-in.

    ๐Ÿค–

    Agent Governance

    Autonomous AI agents operate under the same privacy policies as human users. The Agent API enforces governance at every step of automated workflows โ€” EU AI Act compliant.

    ๐ŸŒ

    Agent Step Privacy

    Every agent step is intercepted before reaching the LLM. PII is detected and tokenised per step, not per session. Each interaction generates an iBS blockchain certificate โ€” immutable proof of what the agent processed and what the model never saw.

    ๐Ÿ”‘

    BYOK โ€” Bring Your Own Key

    Enterprise clients manage their own encryption keys. Privaro never stores key material โ€” only a secure reference. Keys can be rotated, revoked, and audited independently per organisation via the admin panel.

    Controls

    Implemented security controls

    Key technical controls aligned to ISO/IEC 27001:2022 Annex A and SOC2 Trust Services Criteria.

    A.8.24 / CC6.1AES-256-GCM encryption for all token originals. 12-byte random nonce per operation. Per-org key segmentation.โœ“ Implemented
    A.8.3 / CC6.3Row Level Security enforces org isolation at the database level. All queries filtered by org_id.โœ“ Implemented
    A.8.5 / CC6.1API keys stored as SHA-256 hashes. Plaintext never persisted. JWT verification on all frontend calls.โœ“ Implemented
    A.8.15 / CC7.2Immutable audit logs with blockchain certification. UPDATE restricted to ibs_* columns only via RLS policy.โœ“ Implemented
    A.8.20 / CC6.6TLS 1.3 enforced on all connections. No TLS 1.0 or 1.1 accepted. CORS configured per environment.โœ“ Implemented
    A.8.34 / CC4.1Blockchain-certified audit trail. Every PII interaction generates a tamper-evident record on Fantom Opera Mainnet.โœ“ Implemented
    A.5.2 / CC6.2Four-tier role model: viewer, developer, dpo, admin. Cumulative permissions enforced at DB level, not application layer.โœ“ Implemented
    A.8.25 / CC8.1Secure development lifecycle: GitHub-based code review, Railway deployment pipeline, automated health checks.โœ“ Implemented

    NLP Privacy Engine

    Two-tier detection pipeline

    Combines deterministic regex with neural NLP models to maximise recall on structured PII and precision on unstructured entities.

    Tier 1 โ€” Regex

    Deterministic detection of structured PII: DNI/NIE, IBAN, credit cards, phone numbers, emails, IPs, passport numbers. Zero false negatives on known formats.

    Tier 2 โ€” Neural NLP

    Context-aware detection of unstructured PII: full names, organisations, locations, dates. Confidence threshold โ‰ฅ0.75 with post-NLP filters to eliminate false positives in legal and technical documents.

    Agent Step Mode

    Every agent step runs through the full detection pipeline before reaching the LLM. PII is tokenised, the step is certified on blockchain, and an iBS signature is generated per interaction โ€” not per session.

    Compliance

    Regulatory coverage

    Privaro is designed to help enterprise customers meet their data protection obligations under multiple regulatory frameworks.

    RegulationScopePrivaro CoverageStatus
    GDPR Art.5Data minimization, purpose limitationPolicy engine enforces minimum necessary processing. No raw PII to LLMs.Covered
    GDPR Art.9Special category data (health, biometric)health_record entity blocked or anonymised by default in Healthcare/HR presets.Covered
    GDPR Art.30Records of processing activitiesBlockchain-certified audit log per interaction. DPO report export with TX hashes.Covered
    EU AI ActHigh-risk AI systems, human oversightAgent API enforces governance on autonomous agents. Per-entity action in audit logs.Covered
    PSD2Payment data protectionIBAN and card numbers tokenized before any LLM call. Fintech preset built-in.Covered
    HIPAAProtected Health InformationPHI tokenized/anonymised. Blockchain audit trail per PHI access. Healthcare preset.Covered
    ISO 27001:2022Information security management83% of Annex A controls implemented. ISMS documentation in progress.In Progress
    SOC2 Type ISecurity, Confidentiality trust criteriaControls implemented. Formal audit preparation in progress for Q3 2026.In Progress

    Blockchain Audit Trail

    Tamper-proof compliance evidence

    Every audit event is cryptographically certified on Fantom Opera Mainnet โ€” independently verifiable by regulators, auditors, and data subjects.

    How it works

    Every PII detection event generates an audit record. The record's SHA-512 hash is certified on Fantom Opera Mainnet via iBS API. The resulting blockchain TX hash is stored in the audit log.

    Batch certification reduces costs: up to 100 audit events are certified in a single blockchain transaction every 5 minutes.

    Public verifiability

    Any certified event can be independently verified using the TX hash โ€” no access to Privaro's infrastructure required.

    Example TX:
    https://checker.icommunitylabs.com/check/
    fantom_opera_mainnet/
    0xfbe1b5163bdb4e7265e130e09b1b2b0c6b606799...
    Fantom
    Opera Mainnet blockchain
    ~60s
    Avg. certification time
    100x
    Batch efficiency (events per TX)
    SHA-512
    Hashing algorithm

    Policy Documents

    Security policies & procedures

    Privaro maintains a complete set of security policies aligned to ISO 27001 and SOC2 requirements. Available to enterprise customers under NDA.

    ๐Ÿ“‹
    Information Security Policy
    POL-001 ยท v1.0 ยท March 2026
    ๐Ÿ”’
    Data Processing & Privacy Policy
    POL-002 ยท v1.0 ยท March 2026
    โœ…
    Security Controls Register (ISO 27001 Annex A)
    POL-003 ยท v1.0 ยท March 2026 ยท 83% implemented
    ๐Ÿšจ
    Incident Response Plan
    POL-004 ยท v1.0 ยท March 2026 ยท GDPR Art.33 compliant
    โ™ป๏ธ
    Business Continuity & Availability Policy
    POL-005 ยท v1.0 ยท March 2026 ยท RTO < 4h ยท RPO < 1h
    ๐Ÿ“„
    Data Processing Agreement (DPA)
    DPA-001 ยท v1.0 ยท 2026 ยท GDPR Art.28 compliant ยท Available upon request

    Security questions?

    Our team is available to answer security questionnaires, complete vendor assessments, or schedule a technical deep-dive.