
SecurePrompt provides a privacy gateway that automatically detects and replaces personal data, such as names, PINFL numbers, and card details, before requests are sent to AI models like ChatGPT, then restores the original values in responses. The solution deploys inside a customer's own infrastructureeb ensuring sensitive information never leaves their network while preserving full functionality of existing AI tools.
Funding
Funding not disclosed
Founders
Product
Problem
Organizations increasingly rely on AI models like ChatGPT for tasks involving sensitive data, but sending this data to external services creates serious privacy and compliance risks. Employees may inadvertently expose personal information such as names, national ID numbers, and financial details when prompting AI tools, leaving the organization vulnerable to data breaches and regulatory penalties.
Solution
SecurePrompt offers a gateway that sits between existing applications and AI model APIs, automatically replacing personal data with placeholders before any request is sent externally. When the response returns, the platform restores the original values, so staff get complete answers without ever exposing sensitive information. The system operates in watch-only mode initially, logging all activity without blocking anything, until administrators enable enforcement rules. Deployed within the customer's own infrastructure, the gateway preserves existing application workflows while adding a privacy layer that requires no changes to how staff interact with AI tools.
Target Audience
Primary customers are banks, financial institutions, and other organizations in regulated industries that use AI tools for tasks like credit risk analysis, document summarization, and internal reporting while handling sensitive customer data.
Features
- Automatic detection and replacement of personal identifiers including PINFL, Uzcard and Humo card numbers, local names, and mixed-script text
- Bidirectional placeholder mapping that restores original names and details in AI responses without manual intervention
- Configurable rule engine that allows certain data types (e.g., amounts, dates, account balances) to remain readable by the model
- Watch-only mode for initial deployment that logs all requests without blocking, enabling organizations to review behavior before enforcing rules
- On-premises deployment model where the full engine runs inside the customer's network, ensuring no data leaves the building
- Unified gateway address that replaces direct API endpoints with a single internal URL, requiring no changes to existing applications