Enterprise AI Gateway

Your people keep the AI they like.
You keep the data.

QiD Vanguard masks personal data before a prompt leaves your network, answers the too-sensitive ones on your own model, screens what comes back, and writes one audit trail across all of it. Including the personal ChatGPT account someone opened on a company laptop.

GDPR and PDPA posture, no personal data crosses into public cloud AI

One request, end to end
What the person typed
Book a ticket for John Doe at 555-0199.
Masked in flight
What the model receives
Book a ticket for [PERSON_A1] at [PHONE_B2].
What the person reads back
Booked for John Doe. Confirmation sent to 555-0199.
The audit record keeps [PERSON_A1] and a fingerprint. Never the name.
4ways staff reach AI, all held to one rulebook
100+models through one address, swappable without code changes
~100msadded before the answer starts coming back
0bytes of personal data written to disk, anywhere
Coverage

Four ways in. One rulebook.

A consumer AI site open in a browser, coding tools on a laptop, your own applications, and company chat. You write the rules once. Nobody has to change how they work.

A consumer AI site

ChatGPT, Claude, Gemini or Copilot open in a tab, on a personal account.

Browser extension

Coding tools

Claude Desktop, Cursor and IDE assistants running on the laptop itself.

Desktop agent

Your own applications

One OpenAI-compatible address. Change the base URL, keep the code.

API proxy

Company chat

The assistant your organisation already rolled out to everyone.

Browser extension
Architecture

One control plane, three enforcement points

Nothing about your network has to change. The enforcement point closest to the person calls the control plane, and the control plane decides.

Where the person is Enforcement points Control plane Where it runs
Consumer AI sitesPlus company chat
Browser extensionPEP-3
Coding toolsIDE and desktop assistants
Desktop agentPEP-2
Your own applicationsOpenAI-compatible
API proxyPEP-1
QiD VanguardDecides once, for every route in.
Policy Inspection Tokenizer Vault Guardrails Audit
Identifiers leave here as[PERSON_A1]
Added on the round trip~100 ms
Public cloud AISees placeholders only
Your on-premise AINever leaves the building
Original text, inside your network Masked, safe to send abroad Too sensitive to leave, answered in-house
Decisions

Every prompt ends one of four ways

Three of them still give the person an answer. That is deliberate: a control people can work around is not a control.

Allowed

Straight through

Nothing sensitive in the prompt. It goes to the model the person's team is allowed to use, untouched.

Masked

Sent as placeholders

Names, phone numbers, national IDs and account details are swapped out, then restored on the way back. The answer still reads naturally.

Rerouted

Answered in-house

Too sensitive to leave the country, so it goes to your own model instead. The person still gets an answer, so nobody goes hunting for a workaround.

Refused

Stopped at the gate

A credential in the prompt is refused outright and cannot be masked or permitted by any setting. Harmful output is withheld before anyone reads it.

How it works

Eight steps, about a tenth of a second

All of it happens between the person pressing enter and the first words appearing. Detection covers English and Thai, including national ID checksums.

01

Identify

Who is asking, and which AI their team may use at all.

02

Scan

Names, identity numbers, account details, credentials, your own formats.

03

Mask

Each detail becomes a placeholder the model can still reason about.

04

Route by sensitivity

Public model, or your own on-premise one when it must not leave.

05

Execute

The provider sees placeholders only. No identifier ever reaches this layer.

06

Screen the answer

Harmful content is withheld before anyone reads it, on still-masked text.

07

Restore

Every placeholder is swapped back, including mid-stream as text arrives.

08

Deliver and record

The answer goes back. The record holds masked content and a fingerprint.

Controls

Your team designs the rules. No code from us.

The people who know your data write the detection formats themselves, in a form, and prove them in a playground before anything ships. Nothing waits on our release train.

Rule builder

Your employee IDs, contract numbers and internal codes are defined in a form, not in our source code. Pick one to load it into the playground.

DispositionReplace with a placeholder
Applies toAll teams
Edited byYour security team
Ships with, no configuration needed
NamesEmailsPhone numbers Thai national IDCard numbersBank accounts Passport numbersCredentials

Playground

Runs in your browser

Type below and watch the rules decide, live. Nothing you enter leaves this page.

Allowed goes to gpt-4o-mini
What the model would receive

A simplified rule set running client-side: pattern rules plus the real Thai national ID and card checksums. The product itself runs Presidio with Thai language models on the server, so it catches names and context this demo cannot.

Per provider, per team

Allow, mask, inspect or block, set for each provider and narrowed further per team. An overlay can only tighten the baseline, never loosen it.

Break-glass, witnessed

Lifting a control takes two named approvers, expires on a clock, and lands in the audit trail as its own event.

Outage never loosens

When a provider goes down, failover stays inside the set that team was already permitted. An outage cannot promote a request.

Audit

Answer the auditor in one place

Ninety days of records showing who used which AI, with what kind of data, and what the rules decided. The record holds masked content and a fingerprint of the original, never the value itself, so the audit trail is not a second copy of the thing you were protecting.

Active users, request volume and blocked attempts, live
Any single request reconstructable end to end from its traces
Ninety-day retention, meeting the PDPA floor
Last 24 hours Live
Active users1,284
Requests96,410
Refused2,892
Disposition mix
Allowed 61% Masked 27% Rerouted 9% Refused 3%
TimeTeamProviderOutcome
14:02:11Customer Supportgpt-4o-miniMasked
14:02:04Financeonprem-qwenRerouted
14:01:58Engineeringclaude-sonnetRefused
Specifications
Client API formatOpenAI-compatible
AuthenticationOIDC / OAuth2, RBAC
Added latencyAbout 100 ms total, in and out
Audit retention90 days
Personal data at restNone
Detection languagesEnglish and Thai
ScalingStateless, Kubernetes HPA
DeploymentCloud, on-premise or hybrid

Put every AI call behind one gate

Route to any model. Mask what matters. Prove what happened. Bring one week of your own traffic and we will show you what it would have caught.