Redact on the way to the model, and on the way back.
Swiftward hides personal data and secrets before a prompt leaves your environment and puts the real values back in the reply. The same rules run on what a model or a tool returns, and hide what the user should not see.
Rules that call detectors running on your own hardware.
To the model: it never sees the real value
user "Refund the card for maria.lopez@acme.com, order 88213"
|
| redact before it leaves your environment
v
model "Refund the card for <REDACTED_EMAIL_ADDRESS_1/>, order 88213"
|
| model answers
v
gateway "I've refunded <REDACTED_EMAIL_ADDRESS_1/> for order 88213."
|
| restore on the way back
v
user "I've refunded maria.lopez@acme.com for order 88213." Your application does not notice the swap. You change nothing in the agent, in the prompt, or in how you read the answer.
Back to the user: only what they should see
A model or a tool can return more than the person in front of it should read. A support assistant queries an order and gets back the full customer record. A sales assistant asks about an account and the tool returns the counterparty names on every other deal.
Counterparty names are a business secret, and a personal-data scanner does not look for them. The same mechanism hides them, with a rule written on the response instead of the request.
What it recognizes
| Kind | How |
|---|---|
| Card numbers | pattern plus a Luhn check, so a random sixteen digits is not a card |
| Addresses, phones, emails | pattern plus a validator |
| Public IPs | routable addresses only — loopback, private, link-local and reserved ranges are not personal data |
| Secrets and keys | entropy, for a credential that matches no pattern |
| Names, places, dates, identifiers, medical license numbers | a named-entity layer you switch on, running as its own container beside the engine, in English with a multilingual fallback |
It also knows what is not personal. noreply@, git@github.com, john@example.com, a placeholder local part: none of these is a person. A redaction layer that flags them teaches your team to ignore it. The list came from running this against real traffic.
In healthcare, the risk is a combination of fields
Fields that are harmless on their own identify a person together. HIPAA's Safe Harbor method removes eighteen identifiers. A diagnosis is not among them, a birth year is allowed to remain, and a ZIP code keeps its first three digits. A prompt holding all three passes a check that reads one field at a time, and re-identifies the patient anyway. A rule can act on the combination.
De-identification can miss, and you need to see where it did. The decision record shows, for every decision, what was redacted and what was not.
Streaming replies are checked too
The gateway checks a streaming answer one whole sentence at a time, before each sentence reaches the reader, so the answer still streams. Reasoning and tool-call arguments are checked when your rule buffers the response. When it does not, the decision record names what went unchecked.