Watch it happen: only the masked form crosses the line.
This is not a diagram. It is Aavaran’s own detection and masking engine running on a support message. Sensitive values are found inline and replaced with masks that keep only a small recognisable part — the last four digits of a card or phone number, the first letter of an email’s name and of its domain, the first two and the last character of a PAN. Other fields are masked in full. Only the masked form crosses your perimeter to the model. The raw value never leaves the box.
Live — running in your browser
Hi, I'm Anita Rao. My email is a***@e***.comemail and my card ************1111card was charged twice. My PAN is AB***FPAN.
It is 11 pm in the contact centre
A customer has typed her account number, her card number and her mobile into the chat, because that is what customers do when they are worried about a double debit. The agent handling her — increasingly, an AI agent — needs to understand the problem. It does not need her account number to do that. It needs to know that there is an account, and which transaction she means.
For years the honest answer to “does the model see the raw data?” was yes, with a policy document saying it shouldn’t. The model sits at the end of the pipe; whatever went into the pipe reached it. Logs kept copies. Embeddings kept fingerprints. A vendor’s support engineer could, in principle, read it.
Aavaran moves the decision to the one place it can actually be enforced: the perimeter, before the call goes out. The customer’s message reaches the model with the account number masked in full and the card shown as ************8813, its last four digits. The model does its job. The raw values stayed home.
Classify. Mask. Enforce. Prove.
Four verbs, in the order they happen on every request.
Classify
Detect PII, financial and regulated fields inline, on every request — contacts, account and card numbers, health identifiers, and the fields your own policies designate.
Mask
Reversible tokenization, switched on per deployment, gives a deterministic token your downstream systems can keep matching on, with a format-preserving scheme available as an option. Irreversible redaction replaces the value so it cannot be recovered: in the full style nothing of it remains, and the default partial style keeps only a small part.
Enforce
Applied inline at the Gateway under Custodian policy. Not optional, not per-agent, not something a prompt can talk its way around.
Prove
Every mask and unmask becomes a Trust Receipt — signed, versioned, exportable as JSON or PDF. Change one character and the receipt fails.
Reversible when you need it back. Irreversible when you don’t.
The right kind of masking depends on who is downstream. Aavaran lets policy choose per field.
Tokenize — operations that must complete
A bank’s KYC operations agent has to look up the account after the model has understood the request. Reversible tokenization keeps a deterministic token in the model’s view and lets an authorised system — never the model — resolve it back inside your perimeter.
The unmask is itself a logged, policy-bound event. Nobody resolves a token without leaving a receipt.
Redact — data that should not exist downstream
A defence programme triaging incident reports, or a space agency sharing operational logs with an external model for summarisation: names of personnel, locations and identifiers should not survive the trip. Irreversible redaction removes them before egress, and there is no path back.
The receipt records who, what, under which policy and when, so there is a record that the redaction happened and under which rule.
Where it is doing the work
These are the deployments we are asked about most. None of them required replacing the agent or the model already in place.
Contact centres and BPOs
Chat and voice transcripts carry everything a customer chooses to type or say. Aavaran masks them before the assist model, the summariser and the QA scorer see them — and gives the client a receipt trail per interaction.
PSU and private banks
KYC operations, complaint handling and collections all want an AI assist and none of them want account or card data in a model log. Tokenize for the operations that must complete; redact for the rest.
Insurers and NBFCs
Claims documents mix health identifiers with financial ones. Field-level policy lets a claims agent reason over a masked document while the identifiers stay inside your boundary.
Defence and strategic programmes
Irreversible redaction of personnel, unit and location identifiers before any model — including one running air-gapped inside the wire — sees the document.
Space and mission operations
Operational logs and anomaly reports summarised by a model without the contractor, site and personnel details ever egressing.
Anyone with an auditor
Trust Receipts turn “we mask sensitive data” from a policy statement into an exportable record — who, what, which policy, when.
What Aavaran is not
Aavaran is not a prompt-injection shield — that is Kavach, which sits beside it on the same Gateway call. It is not a policy authoring tool — that is Custodian, which defines what Aavaran enforces. And it is not a promise that every possible sensitive field in every language will be caught on day one: classification is configured and measured with you, and the fields your policy designates are the fields Aavaran enforces.
It is also not a certification of your deployment. Aavaran is aligned with RBI FREE-AI data-protection expectations, and ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment — not certifications of your deployment or binding regulatory claims.
Start where the data is
Aavaran stands on its own in front of whatever you already run — your agents, your models, your vendor’s models — with its own masking rules and its own receipt trail. No platform migration. When you are ready, it integrates natively: Custodian defines the policy, the Gateway enforces it, Swaraj runs it air-gapped, and every receipt lands in the same audit record as the rest of the platform.
The only real prerequisite is a decision about which fields matter to you. We will help you make it, and then we will show you the receipts.
Frequently asked questions
How do you stop an AI agent from seeing customer PII?
Mask it before the call leaves your perimeter. AgentAnywhere Aavaran classifies PII, financial and regulated fields inline on every request and replaces them with masks — reversible tokens or irreversible redactions — so the model, tool or embedding service only ever receives the masked form. Enforcement happens at the Agent Universal Gateway, not inside the agent.
What is the difference between tokenization and redaction in Aavaran?
Reversible tokenization, which is switched on per deployment, replaces a value with a deterministic token that downstream systems can keep using to match records and an authorised system can resolve back inside your perimeter, with a format-preserving token scheme available as an option; every unmask is logged. Irreversible redaction replaces the value so that it cannot be recovered: in the full style nothing of it remains, and the default partial style keeps only a small part, such as the last four digits of a card. Policy chooses per field.
What is a Trust Receipt?
A Trust Receipt is Aavaran's audit artifact. Every mask and unmask is logged — who, what, under which policy, and when — then signed and versioned so it is tamper-evident. Trust Receipts can be exported as JSON and PDF for auditors.
Can Aavaran be used with the AI models and agents we already have?
Yes. Aavaran deploys standalone in front of your existing agents and models, including third-party ones, with its own masking rules and receipt trail. It also integrates natively with the AgentAnywhere platform, where Custodian defines policy, the Gateway enforces it and Swaraj runs it air-gapped.
Which compliance frameworks does Aavaran align with?
Aavaran is aligned with RBI FREE-AI data-protection expectations, and ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment, not certifications of your deployment or binding regulatory claims.
Written by
AgentAnywhere Research
The team that builds the platform and the models
AgentAnywhere Research writes about the platform, the model families and the trust layer we build and run in India. Where a figure is ours, it says what it covers; where something is a demonstration, it says so.