PRIVACY CONSOLE · INTEGRATION

Protect your first AI application

Create an app, choose a privacy policy and keep its key in your backend. The console provides a preview and synthetic test suite before you connect production traffic.

  1. 1. Login and open Privacy Console. Create an application using the mask-sensitive policy.
  2. 2. Create a key with protect access. Copy it once to your backend's secret manager.
  3. 3. Try Protection preview, then run the regional detector tests and inspect audit events.
  4. 4. For AI gateway calls, create a gateway key and save your provider key. Your deployment operator must enable the provider endpoint and exact model first.
  5. 5. Review policy allowlists and test a blocked request, a revoked key and your actual application flow.

Text protection

curl "$PRIVONEST_BASE_URL/v1/platform/protect" \
  -H "X-API-Key: $PRIVONEST_PROTECT_KEY" \
  -H "Content-Type: application/json" \
  -d '{"text":"Mera email sana@example.org hai.","country":"PK"}'

Checked AI requests and responses

curl "$PRIVONEST_BASE_URL/v1/chat/completions" \
  -H "Authorization: Bearer $PRIVONEST_GATEWAY_KEY" \
  -H "Content-Type: application/json" \
  -d '{"model":"provider-id/model-name","stream":false,"max_tokens":256,
       "messages":[{"role":"user","content":"Reply to sana@example.org: thank you."}]}'

This release supports non-streaming text chat only. Files, images and tool calls are rejected by the gateway. Existing document protection remains on the original API. Provider/model compatibility must be tested; this is a subset of the chat-completions contract.

Reveal is a separate permission

Use a tokenize policy to create encrypted PV2 tokens. Only a reveal key for the same company and app can restore them before expiry. If you supply X-PrivoNest-Subject, protection and reveal must use the same authorized end-user identifier. Your backend must authenticate that user; never expose a reveal key in browser code. Old unscoped PV1 tokens are rejected by the public reveal API.

Test and review

Detector tests run synthetic cases against your saved policy. Gateway/target tests require explicit authorization and 1–3 custom cases. Exact canary checks do not establish complete AI security. Governance reports organize your evidence; they are not legal certification. Audit events omit raw prompts and secrets. Daily operator maintenance enforces the configured metadata retention.