PII detection
Automatic recognition of email, phone, IBAN and other sensitive fields.
Rationify protects personal data before it reaches external AI providers. PII pipeline, encrypted mappings, audit trails and conversation replay for compliance teams.

Companies want AI but risk GDPR fines when staff paste customer data into generic chatbots. Ad-hoc tools offer no central PII protection or audit trail.
Rationify includes a dedicated gdpr-guard service: PII detection and pseudonymisation before external LLM calls, encrypted mapping storage, fail-closed on errors and full conversation replay — configurable per tenant.
Book a demo and discover the business value for your team.
GDPR Compliant AI means personal data is systematically detected, pseudonymised or blocked before reaching an external AI provider — with traceable audit logs and safe restoration after the LLM response.
IT and compliance owners choose Rationify when AI must be productive without losing control over personal data.
Automatic recognition of email, phone, IBAN and other sensitive fields.
Placeholders to external providers; depseudonymisation only inside the guard.
External calls blocked on encryption or mapping failures.
Conversation replay shows GDPR steps in the SSE timeline.
Multi-tenant with separate policy settings per organisation.
Optional pseudonymisation of tool-call arguments before external providers.
Tenant erasure endpoint for GDPR deletion requests.
Platform designed for European businesses; private/on-premise deployment available.
PII detectors scan chat, RAG context and optionally tool arguments.
Sensitive values replaced by deterministic placeholders; mappings stored encrypted.
Only pseudonymised content goes to external providers.
Response restored inside the guard after integrity checks.
Central pseudo/depseudo layer when GDPR_ENABLED is active.
gdpr_strict enforces pseudonymisation for external providers.
Deterministic replay of GDPR steps for QA and compliance.
Post-response validation without raw PII in audit events.
Observability events contain no raw personal data.
Fernet AEAD with tenant/request-scoped additional data.
Staff paste a customer email in chat. GDPR guard pseudonymises it before OpenAI; the answer shows the real address only after safe depseudonymisation.
Billit tool calls with invoice numbers can be scanned; external routing may be blocked in favour of local model when PII is detected in tool args.

Enterprise-Sicherheit als unterstützende Basis — nicht als Hauptverkaufsargument
The platform implements technical GDPR measures (PII pipeline, erasure API, audit). SOC2/ISO certification is not claimed — your DPA remains required.
PII is detected, pseudonymised before external LLM calls and mappings stored encrypted. Depseudonymisation is fail-closed inside the guard.
Yes — Kubernetes/Docker deployment keeps data within your perimeter.
Routing to OpenAI, Anthropic and local models — always via GDPR filtering when active.
Yes — SSE timeline and conversation replay show GDPR steps per request.
Via tenant erasure API and configurable retention on PII mappings.
Rationify offers central governance, tenant policy and PII pipeline.
Yes — RAG context goes through the same GDPR filtering.
Optional pseudonymisation of tool-call arguments; blocking external calls when PII in tools is possible.
[email protected] or /trial-activatie.
Rationify provides GDPR Compliant AI via dedicated gdpr-guard: PII detection, pseudonymisation before external LLM providers, encrypted mappings, fail-closed depseudonymisation, conversation replay and tenant erasure. No SOC2/ISO certification claimed — technical measures built in.
Vereinbaren Sie eine Demo und entdecken Sie, wie Echtzeit-Digitallösungen Ihre betrieblichen Prozesse verbessern.
Durch das Absenden stimmen Sie unserer Datenschutzerklärung zu.