Security & architecture

Trust the architecture, not just the promise

To protect your data, sitr has to handle it - so here is exactly what that means, and where the lines are drawn. Every point below is a property of how the product is built, not a slogan.

The AI provider never sees raw data

Detection and masking happen before a prompt ever leaves for a model. Providers receive tokenised text like [NAME_1]; the real values are restored only in your own employee's browser.

Self-hosted detection engine

The engine that finds sensitive data runs on private infrastructure with no public access - no third-party API ever sees unmasked text. Enterprise can self-host the entire stack, so nothing leaves your network.

Encrypted token vault (AES-256-GCM)

Real values are encrypted in the app layer; the database only ever holds ciphertext. Keys are versioned and rotatable, and each value is cryptographically bound to its conversation - ciphertext copied anywhere else simply won't decrypt.

No cross-chat correlation

Tokens are scoped per conversation - the same person is a different token in every chat - so stored data can't be stitched back together into a profile of anyone.

Fails closed, by design

If the privacy layer is ever unreachable, the request simply stops - nothing is sent to a model and nothing is stored. A missed detection can never turn into a silent leak.

Deletion you can prove

Erasure and offboarding hard-delete the encrypted vault rows; once they're gone the underlying data is cryptographically unrecoverable - while the masked audit trail your regulators expect stays intact.

Your keys, your models, isolated

Each company brings its own provider credentials, encrypted and scoped to that tenant. sitr holds no shared platform key one customer's traffic could ride on - and never trains any model on your content.

Every send is reviewed and logged

Before a prompt goes out, your employee sees exactly what was detected. It's masked by default; the only value ever sent in the clear is one they explicitly mark non-sensitive - and even that choice is recorded in the audit log.

Written for your security team

Every claim on this page maps to the code that implements it. We'll share a full security-architecture document with your reviewers, so their due diligence starts from specifics - not marketing.

Built for peace of mind

The speed of AI, none of the exposure

If you're smart enough to worry about your data, you're already covered. Everything on this page adds up to one promise: your team moves at the speed of AI, and your sensitive data stays yours - masked before it reaches any model, encrypted at rest, and never used to train anyone's model.

The technical foundation for the compliance work ahead of you:

AES-256-GCM encryption Fail-closed by design Bring your own keys Audit-ready

0

raw data sent to AI models

100%

of prompts logged & auditable

16+

AI providers, one interface

Any

industry, size or region

Give your team AI - and give yourself the audit trail

See sitr masking real prompts against your own data in a 20-minute demo.

getsitr.com · No commitment