The problem

Your staff are already pasting company data into AI

Customer names, ID numbers, contracts, financials - copied into public chatbots with no visibility and no control. Blocking AI outright just pushes it into the shadows.

Data leaves the building

Sensitive PII (personally identifiable information) and business data flow straight to third-party providers, outside any policy or region you control.

Zero visibility

Management has no record of who asked what, when, or with which data - impossible to audit or govern.

Bans don't work

Prohibiting AI kills the productivity gains and drives usage to personal devices where you have even less control.

How it works

Six steps, one quick check for your team

1

Employee writes a prompt

They chat exactly as they would in any AI tool - no new tool, no new habits.

2

sitr detects & masks

Names, IDs, IBANs and more are found - in Arabic and English - and swapped for safe tokens before anything leaves your environment.

3

Employee reviews & confirms

They see exactly what was caught before it's sent. They can reveal a value they've decided is safe to share, or mask extra text - and every such choice is logged.

4

sitr enforces your policies

The skills and rules you set for that employee, department or the whole company are applied to the request.

5

The model answers

The provider only ever sees the masked, policy-shaped prompt and responds to that.

6

sitr restores & logs

Real values are re-inserted for the employee, and the full exchange - including anything they chose to reveal - is recorded for audit.

The same prompt, three points of view

Employee sees

"Contract for Ahmed Al-Falasi, ID 784-1990-…"

AI model sees

"Contract for [NAME_1], ID [EID_1]"

Management sees

Logged: user, model, applied policy, time, and every unmask event.

What sitr does

Governed AI access, without slowing anyone down

Connect every model, control who can do what, and shape the AI to your policies and your industry - all from one place.

One router, every model

Every major AI model behind a single interface. Switch providers without changing how your staff work.

Admin & employee roles

Company admins configure policies, models and credentials; employees just chat. Department-level skills and rules included.

Attach a document - it is masked before the model reads it

Employees can attach a contract, invoice or payroll sheet. sitr extracts the text, masks it the same way it masks a typed message, and sends only the masked version. The file itself never reaches the AI provider and is not stored.

PDF, Word, Excel, CSV and plain text. Images and scans are not supported - masking works on text, and a picture would have to reach the model unmasked. Long documents are truncated, and both you and the model are told where.

Spend you can see, and cap

Every request records its tokens and cost against the employee who made it. Set a monthly limit for the whole company or for one person - it is enforced before the request ever reaches a provider, so a runaway bill cannot happen quietly.

Skills & policies at every level

Shape what your AI will and won't do using skills from a ready-made library, or write your own policies and enforce them for a single department or the whole company. And your employees can turn on any skill they need on the fly, right inside the chat.

Ready-made skills

Start from a predefined library of policy skills, no setup required.

Your own policies

Write custom rules and enforce them per department or company-wide.

Employee-picked in chat

Staff add any skill they need for the task, right in the conversation.

Tailored to your industry

Every business has its own sensitive data and its own rules. We work with you to adapt sitr's detection, policies and terminology to what your field cares about, so the protection fits how you actually operate - not a generic one-size-fits-all filter.

Finance
Healthcare
Legal
Government
Retail
& yours

One layer, every kind of team

The same protection, whatever your size

From your first hire to your ten-thousandth, sitr scales to how your business already works - no rip-and-replace, no change to how your people use AI.

Startups

Move fast without leaking what matters. Get governed AI from day one - no security team, and nothing for your engineers to build or maintain.

Set up in minutes Pay for what you use

Small & medium business

Give the whole team the AI they want while customer and financial data stays under your control - and keep the audit trail on hand for whenever a client or regulator asks.

Per-team policies Full audit trail

Enterprise

Enforce policies across every department, bring your own models and keys, and self-host the entire stack so nothing leaves your environment - meeting the compliance bar your business is held to.

Self-hosted option Department controls

Any industry · Works with the AI models your team already uses

One catalogue, every major provider

Connect the models your team already trusts

Enable any of these from your admin dashboard, bring your own key, and let each team pick from what you've approved.

A Anthropic
O OpenAI
G Google Gemini
V Google Vertex AI
Az Azure OpenAI
B Amazon Bedrock
x xAI (Grok)
Gq Groq
M Mistral
C Cohere
DS DeepSeek
Ce Cerebras
P Perplexity
T Together AI
F Fireworks
DI DeepInfra

Self-hosted & any OpenAI-compatible model

Running your own model on your own servers? If it speaks the OpenAI API, sitr routes to it - your infrastructure, your weights, nothing leaving your network. Point sitr at the endpoint and it works alongside every provider above.

Questions, answered

The things buyers ask us first

If sitr redacts my data, isn't it still seeing it?

In our hosted deployment, sitr's app processes each value only long enough to encrypt it - the database stores only AES-256-GCM ciphertext, the AI provider only ever sees tokens, and we never train on your data. If even that transient handling is more than your policy allows, run sitr fully self-hosted so raw values never leave your network at all.

What if the detector misses something sensitive?

Detection is deliberately tuned to over-mask rather than under-mask, and combines fixed patterns (IDs, IBANs with checksum validation, cards) with an AI model, in Arabic and English. Your employee also reviews exactly what was caught before anything is sent. And if the privacy layer is ever unavailable, the request fails closed - nothing goes out unmasked.

Does masking make the AI's answers worse?

No. Each entity becomes a consistent placeholder, so the model keeps full context - "draft a contract for [NAME_1] due Thursday" reads and reasons exactly like the real sentence. The real values are stitched back into the answer for your employee automatically.

Where is our data stored, and can we keep it in-region?

You choose. sitr supports regional hosting - Core42's UAE-hosted models are available out of the box - and a fully self-hosted deployment, so regulated data can stay inside your country and inside your control.

How do we get our data out, or delete it?

Company data can be exported and hard-deleted on request. Once the encrypted vault rows are purged, the underlying values are cryptographically unrecoverable - while the masked audit log remains intact for your own compliance obligations.

Give your team AI - and give yourself the audit trail

See sitr masking real prompts against your own data in a 20-minute demo.

getsitr.com · No commitment