Zirah Gateway
Let your people use public AI — without handing it your secrets.
Zirah Gateway sits in front of ChatGPT, Claude, Gemini and the rest. It scans every outbound prompt, redacts sensitive data before it reaches the model, and logs every time someone reveals it — so your teams keep their tools and you keep control.
Blocking public AI doesn't work
Your people are already pasting confidential data into public models — customer records, card numbers, source code. Block the tools outright and the work just moves to personal laptops, where you can't see it at all. The answer isn't to shut AI off. It's to put something in front of it.
Redacted on the way out
- Step 01
Write
The employee writes a prompt as usual.
- Step 02
Mask
Zirah scans the outbound payload and masks sensitive data before a single character reaches the external model.
- Step 03
Return
The response comes back with citations and clear provenance.
And the masking holds during streaming — redacted values are never flashed to the screen mid-response.
Four pillars, one gateway
Redacted before it leaves
A custom Presidio-based engine scans every outbound prompt and masks sensitive data before it reaches the external model.
Keep the models your teams want
Zirah runs in front of the public models people already use, and blocks only what policy forbids. Every block offers an exception path, not a dead end.
Reveals are logged, never quiet
Unmasking redacted data takes a second person's approval and produces a logged, watermarked record. No one can approve their own reveal.
Governed from one control plane
Set policy by organizational scope, test in staging, promote to production, and export every event to your SIEM.
Built for the people who answer to the regulator
Your Data Protection Officer gets a dedicated triage view, not a spreadsheet of alerts.
Triage inbox
Open cases in one place, with an audit trail on every action.
Request an unmask
Submit a reason and evidence; approval comes from a peer — never the requester.
Logged reveals
Reveals open under a standing 'logged and watermarked' banner and close with notes.
Fallback approvers
If an approver is out of office the case reroutes to a fallback approver — no case waits on a timer.

Change policy without holding your breath
IT Operations owns the rules. Start from a policy template, edit it in a two-pane diff, and see conflicts before you ship — overlapping rules block deployment with a plain explanation of what clashes and where. Deploy to staging first, promote to production when it's proven, and roll back if you need to.
An audit story that holds up
Every block, every exception, every reveal is on the record — watermarked, attributed, and pushed to your SIEM. If your SIEM goes down, events queue locally rather than dropping to the floor. When the regulator asks what happened, you have the answer.

For your people
They keep working. You keep control.
New users land in a chat with a few suggestion chips drawn from what they can access, so the first prompt just works. When redaction fires, it shows as a small marker on the message — 🛡 1 item redacted · view — not a wall. Most of the time your teams barely notice Zirah is there. That's the point.