Private Early Access

Privacy & Evidence

Privacy controls should leave a reviewable record.

A privacy claim states what a system is intended to do. Evidence gives a reviewer a defined way to examine what was recorded for a particular processing path.

Kayrix is designed not only to apply privacy controls, but to preserve evidence of the processing path and the transaction directed to a configured AI provider. The scope of that evidence is the gateway’s own recorded activity.

Ask four practical questions

Which policy version was associated with the request? Which detected entity categories and processing decisions were recorded? Which provider and model were associated with the transaction? Does the available integrity verification pass for the records under review?

These questions are more useful than a badge that simply says “secure”. They also make missing records or incomplete coverage visible rather than assuming them away.

Evidence without a second conversation archive

The proposed evidence model uses hashes and operational metadata instead of duplicating complete prompts and model responses in the audit ledger. Reviewers should still treat evidence as controlled information: a hash, identifier or timestamp is not automatically anonymous just because it is not plain text.

Integrity is one part of the answer

Hash-chain verification checks the integrity relationships defined by the recorded data. It does not establish that every personal detail was detected, that the original event was recorded correctly, or that an external provider deleted the content it received.

A changed hash alone does not prove successful sanitization. A hash of selected text is not automatically a fingerprint of the complete transmitted request. The verification method must define what was captured and what a reviewer can compare.

Where the boundary stops

Kayrix evidence covers the supported traffic processed through the gateway. It does not establish coverage of bypassed applications, attest to an external provider’s internal retention or training practices, or provide a legal certification.

Privacy outcomes also depend on detection quality, configuration, access controls and the surrounding deployment. Token replacement must not be treated as a guarantee of irreversible anonymization.

Start with the questions your reviewers need answered.

Define the policy, provider, evidence scope and failure cases before drawing conclusions from a pilot. Review the resulting records together with their limitations.

Request Private Pilot