SentinelGateway PII Scrubbing — Zero-Trust In-Flight Redaction

SentinelGateway scrubs SSNs, credit card numbers, email addresses, and API keys from LLM prompts in memory before any payload leaves the gateway. Redaction runs by default for every tenant, requires no external service like Microsoft Presidio, and supports zero data retention: raw prompts are never persisted unless audit logging is explicitly configured. Controls align with GDPR, CCPA, and SOC 2 Type II.

🛡️ ZERO-TRUST DATA PERIMETER — In-Flight Redaction

PII never leaves your perimeter.

Sentinel scrubs SSNs, credit cards, emails, and API keys in memory — before a single byte reaches OpenAI, Anthropic, Gemini, or Groq. No external redaction service. No retained raw prompts.

No credit card required · Drop-in OpenAI SDK compatible · Live in 60 seconds.

Live redaction engine

0 / 4 entities scrubbed

① Raw user prompt

My SSN is 078-05-1120 and card 4111 1111 1111 1111. Email me at jane.doe@acme.com — my key is sk-proj-a8f3…

② Forwarded upstream

My SSN is [SSN_REDACTED] and card [CREDIT_CARD_REDACTED]. Email me at [EMAIL_REDACTED] — my key is [API_KEY_REDACTED]
in-memory · <1ms · zero retention AUTO-REPLAY

How it works

Redaction is a property of the pipe, not a plugin — it runs on every request, by default, in microseconds.

1

Ingest & Normalize

Prompt messages are parsed in memory inside the gateway process. Nothing is written to disk, and raw payloads are never persisted unless you explicitly enable audit logging.

2

In-Flight Redaction

Regex and entropy scanners mask SSNs, 13–19 digit card PANs, emails, and API keys — while 11 prompt-injection patterns block jailbreak attempts. Scrubbed text is what gets cached, embedded, and forwarded.

3

Upstream Delivery & Audit

Only the sanitized payload reaches the provider. The trace records pii_applied: true with a redaction count — inspect raw vs. redacted side by side in the Command Center.

Compliance posture, quantified

The controls your security review will ask about — already answered.

100%

PII elimination

SSNs, cards, emails, and keys masked pre-transmission.

0

External services

Native in-memory engine — no Presidio API to operate.

11

Injection patterns

Jailbreak and DAN detection built into the same pass.

SOC 2

Type II aligned

GDPR / CCPA ready — DPA available on Team tier.

Pass your next security review in days, not quarters.

Sign up in 60 seconds. PII scrubbing is active on your very first request.

Explore the platform