PDM
Trust & security

Fort Knox, not a hotel safe.

Verifiable and Transparent Due Diligence

In ten seconds

Your file is encrypted in transit, processed inside a sealed cloud perimeter with no public internet exposure, and our copies are destroyed within 48 hours. No third-party consumer AI ever sees it — and every control below is stated with the mechanism that enforces it and how that enforcement can be checked.

Architecture

Here’s how a file moves through the system

Your file
TLS 1.2+ encrypted
Google Cloud Organization Perimeter
SOC 2 Type II · ISO 27001 · VPC Service Controls
Private VPC
No public IP address
App server
Cloud Run
Masking engine
Sealed
Private storage
Cloud SQL + GCS
Deletion Audit Log
Independent of application code
TLS 1.2+ encrypted
Masked file

Our copies destroyed — logged independently

Controls

Data Protection Controls

Data cannot leave the environment
MechanismVPC Service Controls, org-level perimeter
VerificationEnforced at platform level, not application config
The database has no public network exposure
MechanismPrivate IP only — no public IP address on the Cloud SQL instance
VerificationNo route from the open internet
Stored files cannot be made public
MechanismUniform bucket-level access, so IAM is the only grant path, plus public access prevention enforced on the bucket
VerificationPublic access cannot be granted, even by mistake
No third-party consumer AI service sees your file
MechanismLayered detection, each layer doing a different job: Google Cloud DLP does the bulk of the work — structured columns and shape-based identifiers such as Social Security numbers, account numbers, dates, emails and IP addresses. Our own validators add format-specific checks. Our self-hosted model specialises in the cases shape can’t reach: names and locations written into ordinary prose.
VerificationOur model runs on our infrastructure, with its weights built into the container image; DLP is a Google Cloud service covered by Google’s data-processing terms
Deletion is enforced
MechanismGCS Lifecycle Management rule, 48-hour max
VerificationEvery deletion independently logged
Infrastructure is independently audited
MechanismGoogle Cloud, SOC 2 Type II, ISO 27001
VerificationPlatform-level certification
A partially processed file is never delivered
MechanismFail-stop batch architecture — the job halts on any file it cannot process correctly
VerificationPayment automatically refunded; no partially-masked file released
Logging

What we log

Our logs are PHI-clean. We record the coverage decision and the counts — how many identifiers were found and masked, and of which kind — never the values of your cells. The evidence we keep describes what we did, not what your data says.

Documentation

What you keep

Every completed job comes with a downloadable processing receipt — a verifiable record for your files: the job reference, the coverage class applied, per-category masking counts, SHA-256 hashes of your original and masked files, and the deletion schedule. For a clinical file, it also carries the Business Associate Agreement version and the timestamp you attested.

The symmetry is the point: the receipt is your record, and our logs are PHI-clean — neither ever contains the values from your file.

Healthcare & HIPAA

Supports Safe Harbor workflows

PDM supports the Safe Harbor de-identification method under a Business Associate Agreement attestation — no “HIPAA certified” badge exists for any tool, and we don’t claim one. The BAA is a standing agreement you can read here.

Full Safe Harbor coverage table →

GDPR & CCPA

Supports EU and California privacy practices

Masking supports GDPR pseudonymisation and data-minimisation practices — the safeguards Articles 25 and 32 call for when sharing personal data.

Masking supports CCPA deidentification and data-minimization practices — reducing what your shared files carry under California and similar state privacy laws.

The bottom line

Files are encrypted, hidden, protected, processed, and deleted. No unauthorized access, either direction.

We test our detection against pre-assessed, scored datasets and analyze every exception. Full methodology and benchmark results are available on request. Detection results are published on the Safe Harbor detection page.

Next step

Ready to mask your data?

Upload a file and get an immediate estimate.

Upload My File →