Mask personal data before it reaches AI agents.
How Vordix inspects every request and response inline, acts on sensitive fields before they reach the model or tool, and turns each decision into audit evidence you own.
Example: useful Jira results without email addresses
A support assistant may need an issue summary and status without needing the email address of the assignee or reporter. Configure the policy for the response fields used by your integration.
Identify the fields the task needs
Keep the issue summary and status. Decide whether names, email addresses and free-text comments are necessary for this use case.
Apply field-level policies
Mask identifiers where a substitute is useful, or redact fields that should not reach the agent. Review free-text fields separately; sensitive data may appear inside comments too.
Inspect the actual response
Run a representative request and check the result delivered to the AI client, as well as the audit record. Repeat after changes to the integration or its policies.
Why turning a tool off isn’t data protection
Every tool response flows into a model’s context, your audit log and your exports, and sensitive data hides in the free text.
- 01
PII flows straight into the model
A Confluence page, a Jira comment or a database row can each carry personal data right into an LLM’s context window.
- 02
On/off can’t minimise a field
Switching an operation off is all-or-nothing; it can’t strip a salary or mask an email while keeping the rest of the response useful.
- 03
Redacting only the log is too late
If you clean the audit record but not the agent-facing response, the model has already read the PII.
- 04
A cloud detector breaks residency
Sending data to a third-party PII service defeats self-hosting, and injected text in a tool response can try to hijack the agent.
Not a connector list. A governance layer per tool.
- Jira
Locked to approved projects; assignee & reporter emails masked.
- GitHub
Scoped to approved repos; merges and writes can require approval.
- Confluence
Limited to approved spaces; author names masked.
- Notion
Limited to approved databases & pages; author names masked.
- Slack
Approved channels only; agent messages treated as inert text.
- Discord
Approved channels only; member details masked.
- MS Teams
Approved channels only; agent messages treated as inert text.
- Trello
Scoped to approved boards; member details masked.
- Databricks
No raw SQL; queries are built from approved tables, read-only and row-capped.
- Web Search
Domain-allowlisted, read-only; results returned as inert text.
- Gmail
Scoped mailboxes; recipient PII redacted per field.
- Outlook
Scoped mailboxes; recipient PII redacted per field.
- Azure DevOps
Scoped to approved repos and pipelines; write operations fully audited.
Every integration listed here is available today. More are on the way.
How Vordix solves it
- 01
Field-level data policies
Mask, redact, drop or block any response field, minimising sensitive data while keeping the rest of the response useful. When rules overlap, the strictest action wins.
- 02
Enforced on the agent’s copy first
Minimisation runs on the response the agent sees; the stored and exported record is derived from that same cleaned copy.
- 03
Prompt injection treated as inert text
Strings injected into a tool response are stored and returned as data, never interpreted, with an optional detector you can set to flag or deny.
- 04
Human approval for high-risk calls
Route sensitive operations through a hold-and-approve gate before they are allowed to execute.
- 05
Deterministic, offline detection In progress
Recognisers that verify by checksum: cards by Luhn, IBANs by mod-97, and DACH national IDs (Austrian SVNR, German Steuer-ID, Swiss AHV), running entirely in your network, with nothing sent out to classify.
- 06
Your own term lists Planned
Upload employee, customer or codename lists so your specific entities are matched and protected too.
- 07
Evidence, not raw logs
Every block and redaction is audited and tagged to the EU AI Act data-governance article, so the record shows what was protected and why.
See it on your own stack.
A short walkthrough on your tools, your rules, your audit log. Nothing leaves your network.