Zirah Gateway

Let your people use public AI — without handing it your secrets.

Zirah Gateway sits in front of ChatGPT, Claude, Gemini and the rest. It scans every outbound prompt, redacts sensitive data before it reaches the model, and logs every time someone reveals it — so your teams keep their tools and you keep control.

The problem

Blocking public AI doesn't work

Your people are already pasting confidential data into public models — customer records, card numbers, source code. Block the tools outright and the work just moves to personal laptops, where you can't see it at all. The answer isn't to shut AI off. It's to put something in front of it.

How it works

Redacted on the way out

  1. Step 01

    Write

    The employee writes a prompt as usual.

  2. Step 02

    Mask

    Zirah scans the outbound payload and masks sensitive data before a single character reaches the external model.

  3. Step 03

    Return

    The response comes back with citations and clear provenance.

And the masking holds during streaming — redacted values are never flashed to the screen mid-response.

Why Zirah Gateway

Four pillars, one gateway

Redacted before it leaves

A custom Presidio-based engine scans every outbound prompt and masks sensitive data before it reaches the external model.

Keep the models your teams want

Zirah runs in front of the public models people already use, and blocks only what policy forbids. Every block offers an exception path, not a dead end.

Reveals are logged, never quiet

Unmasking redacted data takes a second person's approval and produces a logged, watermarked record. No one can approve their own reveal.

Governed from one control plane

Set policy by organizational scope, test in staging, promote to production, and export every event to your SIEM.

Compliance workspace

Built for the people who answer to the regulator

Your Data Protection Officer gets a dedicated triage view, not a spreadsheet of alerts.

Triage inbox

Open cases in one place, with an audit trail on every action.

Request an unmask

Submit a reason and evidence; approval comes from a peer — never the requester.

Logged reveals

Reveals open under a standing 'logged and watermarked' banner and close with notes.

Fallback approvers

If an approver is out of office the case reroutes to a fallback approver — no case waits on a timer.

Triage → Unmask → Reveal
Compliance workspace — Triage, Unmask, Reveal
Control plane

Change policy without holding your breath

IT Operations owns the rules. Start from a policy template, edit it in a two-pane diff, and see conflicts before you ship — overlapping rules block deployment with a plain explanation of what clashes and where. Deploy to staging first, promote to production when it's proven, and roll back if you need to.

Proof

An audit story that holds up

Every block, every exception, every reveal is on the record — watermarked, attributed, and pushed to your SIEM. If your SIEM goes down, events queue locally rather than dropping to the floor. When the regulator asks what happened, you have the answer.

SIEM integration
SIEM-ready audit trail

For your people

They keep working. You keep control.

New users land in a chat with a few suggestion chips drawn from what they can access, so the first prompt just works. When redaction fires, it shows as a small marker on the message — 🛡 1 item redacted · view — not a wall. Most of the time your teams barely notice Zirah is there. That's the point.

Deployment & trust
Works with your identity provider (SAML / OIDC)Governed by organizational scopeSIEM exportBuilt for regulated industries

Ready to put something in front of it?