A consumer AI site
ChatGPT, Claude, Gemini or Copilot open in a tab, on a personal account.
QiD Vanguard masks personal data before a prompt leaves your network, answers the too-sensitive ones on your own model, screens what comes back, and writes one audit trail across all of it. Including the personal ChatGPT account someone opened on a company laptop.
GDPR and PDPA posture, no personal data crosses into public cloud AI
A consumer AI site open in a browser, coding tools on a laptop, your own applications, and company chat. You write the rules once. Nobody has to change how they work.
ChatGPT, Claude, Gemini or Copilot open in a tab, on a personal account.
Claude Desktop, Cursor and IDE assistants running on the laptop itself.
One OpenAI-compatible address. Change the base URL, keep the code.
The assistant your organisation already rolled out to everyone.
Nothing about your network has to change. The enforcement point closest to the person calls the control plane, and the control plane decides.
Three of them still give the person an answer. That is deliberate: a control people can work around is not a control.
Nothing sensitive in the prompt. It goes to the model the person's team is allowed to use, untouched.
Names, phone numbers, national IDs and account details are swapped out, then restored on the way back. The answer still reads naturally.
Too sensitive to leave the country, so it goes to your own model instead. The person still gets an answer, so nobody goes hunting for a workaround.
A credential in the prompt is refused outright and cannot be masked or permitted by any setting. Harmful output is withheld before anyone reads it.
All of it happens between the person pressing enter and the first words appearing. Detection covers English and Thai, including national ID checksums.
Who is asking, and which AI their team may use at all.
Names, identity numbers, account details, credentials, your own formats.
Each detail becomes a placeholder the model can still reason about.
Public model, or your own on-premise one when it must not leave.
The provider sees placeholders only. No identifier ever reaches this layer.
Harmful content is withheld before anyone reads it, on still-masked text.
Every placeholder is swapped back, including mid-stream as text arrives.
The answer goes back. The record holds masked content and a fingerprint.
The people who know your data write the detection formats themselves, in a form, and prove them in a playground before anything ships. Nothing waits on our release train.
Your employee IDs, contract numbers and internal codes are defined in a form, not in our source code. Pick one to load it into the playground.
Type below and watch the rules decide, live. Nothing you enter leaves this page.
A simplified rule set running client-side: pattern rules plus the real Thai national ID and card checksums. The product itself runs Presidio with Thai language models on the server, so it catches names and context this demo cannot.
Allow, mask, inspect or block, set for each provider and narrowed further per team. An overlay can only tighten the baseline, never loosen it.
Lifting a control takes two named approvers, expires on a clock, and lands in the audit trail as its own event.
When a provider goes down, failover stays inside the set that team was already permitted. An outage cannot promote a request.
Ninety days of records showing who used which AI, with what kind of data, and what the rules decided. The record holds masked content and a fingerprint of the original, never the value itself, so the audit trail is not a second copy of the thing you were protecting.
Route to any model. Mask what matters. Prove what happened. Bring one week of your own traffic and we will show you what it would have caught.