PromptVault AI security

PromptVault. Use AI. Expose nothing.

Sensitive data is tokenized before the model sees it. What comes back is decided by trust.

Compliance & fit
  • SOC 2 Certified
  • GLBA
  • PCI DSS
  • SOX
  • NIST 800-207
  • Native Entra ID
Prompt gpt-4o · support agent · L1 claude-sonnet · finance analyst · verified gemini-1.5 · contractor · trust low
raw prompt detecting sensitive fields tokenized prompt model response authorizing return returned to user

Summarize the claim for Maria Delgado[NAME_01], DOB 04/12/1981[DOB_01], policy HX-88213[POLICY_01].

Reconcile wire from acct 4471-9902[ACCT_01] for $182,400[AMT_01] against invoice INV-2291[INV_01].

Export patient list with SSNs[SSN_*] and diagnoses[PHI_*] for the oncology ward[UNIT_01].

reading prompt… detecting PII / PHI / financials… swapping values for tokens… model runs on tokens only… checking role + trust… disclosure decided

  1. detect
  2. tokenize
  3. model
  4. authorize
Disclosure Tokens only Revealed to role Denied Deciding… Raw data left 0 fields 0 fields 0 fields
The question

What is this agent
allowed to reveal?

  • without PromptVault — PII, PHI, financials leave on send
  • with PromptVault — tokens leave, trust decides what returns

Every prompt to an external model is a potential disclosure. PromptVault governs what enters the model and what leaves it.

How it works

Detect. Tokenize. Authorize.

Raw data never leaves. Any model — OpenAI, Azure, Gemini, Anthropic — only ever sees tokens.

  1. 01

    Detect & tokenize

    Sensitive values are found and swapped for secure tokens before the LLM sees them.

    PII · PHI · PCI · secrets → [TOKEN]
  2. 02

    Process

    The tokenized prompt runs on any model. Raw data never leaves.

    openai · azure · gemini · anthropic
  3. 03

    Authorize

    Role-aware policy plus live trust decides what is revealed on the way back.

    reveal | keep tokenized | approve | deny
Four pillars

Control, with a record.

  • 01 Control Policy enforced before the model sees anything.
  • 02 Visibility Every AI interaction traceable, prompt to response.
  • 03 Evidence Immutable audit trails built for auditors and regulators.
  • 04 Enablement Authorized users see raw data; everyone else works safely with tokens.
Audit Record aud_71c2e aud_2f9a0 aud_c410b
Interaction Claims summary · support agent Wire reconciliation · finance analyst Patient export · contractor
  • 01 Control 3 fields tokenized pre-send. Account and amount tokenized. SSNs and diagnoses tokenized. pass pass pass checking
  • 02 Visibility Prompt, tokens and response logged. Reveal event logged with approver. Denial logged with reason. pass pass pass checking
  • 03 Evidence Signed record written. Signed record written. Signed record written. pass pass pass checking
  • 04 Enablement Agent worked on tokens; task done. Verified role saw raw values. Trust too low — nothing revealed. pass pass fail checking
Outcome Compliant Revealed · logged Denied Reviewing… Fields tokenized 3 3 3
The loop-back

Disclosure follows trust.

Redaction is a feature. The moat is trust-conditioned disclosure: TIM uses live trust state to decide whether data stays tokenized, is revealed, needs approval, or is denied. When trust drops, access contracts automatically.

agent://claims-assist-01
Live trust state · from TIM
  • Customer name Maria Delgado[NAME_01]
  • Account number 4471-9902[ACCT_01]
  • Diagnosis Stage II · oncology[PHI_01]
  • SSN •••-••-4410[SSN_01]
Built for

Regulated teams.

AI adoption without a compliance breach.

  • Healthcare
  • Finance
  • Legal
  • Life sciences
  • Insurance
  • Government
Your data PromptVault The model

Put trust between
your data and the model.