Raw text arrives with names, IDs, phone numbers, or account references still intact.
"Draft apology for order delay. Customer: Demo Customer A, Phone: PHONE-EXAMPLE-001"
"Summarize patient discharge. Patient: Demo Patient B, ID: NID-EXAMPLE-002"
"Flag suspicious transfer. Account holder: Demo Account Holder C, IBAN: IBAN-EXAMPLE-003"
"Translate performance review. Employee: Demo Employee D, Badge: EMP-EXAMPLE-004"
"Optimize delivery route. Driver: Demo Driver E, Phone: PHONE-EXAMPLE-005"
Personal data is identified, moved into the vault, and replaced with typed placeholders the model can safely process.
"Draft apology for order delay. Customer: [[PERSON:01]], Phone: [[PHONE:01]]""Summarize patient discharge. Patient: [[PERSON:01]], ID: [[NATIONAL_ID:01]]""Flag suspicious transfer. Account holder: [[PERSON:01]], IBAN: [[IBAN:01]]""Translate performance review. Employee: [[PERSON:01]], Badge: [[EMPLOYEE_ID:01]]""Optimize delivery route. Driver: [[PERSON:01]], Phone: [[PHONE:01]]"Only the prepared payload reaches the selected model. Provider and residency choices stay bound to route policy.
Tokens are rehydrated from the vault and the user sees a natural response with the original context restored.
"Dear Demo Customer A, we sincerely apologize for the delay in your order...""Patient Demo Patient B is cleared for discharge with follow-up in 14 days...""Transaction by Demo Account Holder C flagged for analyst review...""Demo Employee D exceeded Q3 targets by 18%. Recommend promotion review...""Route optimized for Demo Driver E. Three stops consolidated, ETA reduced."Amber/red provider residency depends on operator-configured provider endpoints. DataSitr does not independently verify provider data residency. Groq and HUMAIN are independent companies with a public in-Kingdom inference partnership; the gateway routes each configured endpoint separately.
Catches ~9 in 10 of the Saudi personal data in Arabic text — where off-the-shelf detection catches ~2 in 10. · see the benchmark
177 compliance controls, each traced to a test, dated evidence, or a verifiable fact · Saudi-hosted, encrypted routing
Current test count is published in the trust report · Full technical evidence, live posture, and limits → trust page
Live posture, dated proof limits, and benchmark snapshots are published on the trust, status, and benchmark pages.
Tokenized. Sent to global AI.
PII replaced with typed placeholders before external processing.
Pseudonymized. Routed to operator-configured in-Kingdom AI paths.
Linkable tokens stay on Saudi-hosted infrastructure.
Raw. Routed only to configured in-Kingdom paths or blocked.
Sensitive data is kept on Saudi-hosted infrastructure when the configured provider path is in-Kingdom.