Platform Platform
System
ConceptsEnginePolicy as codeDeclarationsSafe changeGatewaysIntegrationsObservabilityAdministrationSecurityHuman reviewAudit and evidenceData retentionSecrets and data classification
Controls
Registries and documentationAuthentication and authorizationInjection detectionData redactionCode fingerprintingRole and judge checksContent classificationSpend and loop limitsBusiness rules
Solutions Solutions
By what you do
Sell into the enterpriseControl the AI you run
By industry
Financial servicesDigital assetsInsuranceHealthcareLegalUser-generated content
By discipline
AI governanceTrust and safetyRisk and compliance
Cases Cases Embedded control planeSource-code leakTrading agents over MCPLive firehoseRefund assistant
Compare Compare LiteLLMNVIDIA NeMo GuardrailsOPAROOSTAgent Governance Toolkit
Resources Resources
Guides
Enterprise review questionsPrompt injectionAgent and control layerAgent architecturesDecision system mapAI control maturity model
Standards
Standards OWASP Agent Control StandardEU AI ActPMI AI standardNIST AI RMFERC-8004
Book a demo
Platform · Controls

Redact on the way to the model, and on the way back.

Swiftward hides personal data and secrets before a prompt leaves your environment and puts the real values back in the reply. The same rules run on what a model or a tool returns, and hide what the user should not see.

Rules that call detectors running on your own hardware.

To the model: it never sees the real value

one prompt, out and back
user      "Refund the card for maria.lopez@acme.com, order 88213"
             |
             |  redact before it leaves your environment
             v
model     "Refund the card for <REDACTED_EMAIL_ADDRESS_1/>, order 88213"
             |
             |  model answers
             v
gateway   "I've refunded <REDACTED_EMAIL_ADDRESS_1/> for order 88213."
             |
             |  restore on the way back
             v
user      "I've refunded maria.lopez@acme.com for order 88213."

Your application does not notice the swap. You change nothing in the agent, in the prompt, or in how you read the answer.

Back to the user: only what they should see

A model or a tool can return more than the person in front of it should read. A support assistant queries an order and gets back the full customer record. A sales assistant asks about an account and the tool returns the counterparty names on every other deal.

Counterparty names are a business secret, and a personal-data scanner does not look for them. The same mechanism hides them, with a rule written on the response instead of the request.

What it recognizes

KindHow
Card numberspattern plus a Luhn check, so a random sixteen digits is not a card
Addresses, phones, emailspattern plus a validator
Public IPsroutable addresses only — loopback, private, link-local and reserved ranges are not personal data
Secrets and keysentropy, for a credential that matches no pattern
Names, places, dates, identifiers, medical license numbersa named-entity layer you switch on, running as its own container beside the engine, in English with a multilingual fallback

It also knows what is not personal. noreply@, git@github.com, john@example.com, a placeholder local part: none of these is a person. A redaction layer that flags them teaches your team to ignore it. The list came from running this against real traffic.

In healthcare, the risk is a combination of fields

Fields that are harmless on their own identify a person together. HIPAA's Safe Harbor method removes eighteen identifiers. A diagnosis is not among them, a birth year is allowed to remain, and a ZIP code keeps its first three digits. A prompt holding all three passes a check that reads one field at a time, and re-identifies the patient anyway. A rule can act on the combination.

De-identification can miss, and you need to see where it did. The decision record shows, for every decision, what was redacted and what was not.

Streaming replies are checked too

The gateway checks a streaming answer one whole sentence at a time, before each sentence reaches the reader, so the answer still streams. Reasoning and tool-call arguments are checked when your rule buffers the response. When it does not, the decision record names what went unchecked.

Related: source code is a different mechanism · healthcare · classifying the fields once
Book a demo