VEIL · 22 SEPTEMBER 2026
Mask it before the model sees it.
Every AI agent you deploy is a new reader of your customers’ data. Veil makes sure that reader only ever sees the masked form — and leaves a signed receipt for every value it hid.
TL;DR
Veil classifies sensitive data on every call and masks it before any model, tool or embedding service sees it. Reversible tokenization when your systems need the value back; irreversible redaction when nothing downstream should ever hold it.
It is enforced inline at the Agent Universal Gateway, under policy defined by Custodian — so masking is not a setting an agent can forget. Every mask and unmask is logged as a Trust Receipt: who, what, under which policy, when — signed, versioned, exportable for auditors.
It deploys standalone in front of the agents and models you already run, or natively inside the AgentAnywhere platform, including region-pinned and air-gapped deployments.
Watch it happen: only the masked form crosses the line.
This is not a diagram. It is Veil’s own detection and masking engine running on a support message. Sensitive values are found inline and replaced with shape-preserving masks — a card keeps its last four, an email keeps its shape — and only the masked form crosses your perimeter to the model. The raw value never leaves the box.
Hi, I'm Anita Rao. My email is a***@e***.comemail and my card ************1111card was charged twice. My PAN is AB***FPAN.
It is 11 pm in the contact centre
A customer has typed her account number, her card number and her mobile into the chat, because that is what customers do when they are worried about a double debit. The agent handling her — increasingly, an AI agent — needs to understand the problem. It does not need her account number to do that. It needs to know *that there is* an account, and which transaction she means.
For years the honest answer to “does the model see the raw data?” was yes, with a policy document saying it shouldn’t. The model sits at the end of the pipe; whatever went into the pipe reached it. Logs kept copies. Embeddings kept fingerprints. A vendor’s support engineer could, in principle, read it.
Veil moves the decision to the one place it can actually be enforced: the perimeter, before the call goes out. The customer’s message reaches the model as *“my account ACCT_7f3a…0027 was debited twice on my card **** 8813”*. The model does its job. The raw values stayed home.
Classify. Mask. Enforce. Prove.
Four verbs, in the order they happen on every request.
Classify
Detect PII, financial and regulated fields inline, on every request — contacts, account and card numbers, health identifiers, and the fields your own policies designate.
Mask
Reversible tokenization gives a deterministic, format-preserving token your downstream systems keep working with. Irreversible redaction removes the value so it cannot be recovered.
Enforce
Applied inline at the Gateway under Custodian policy. Not optional, not per-agent, not something a prompt can talk its way around.
Prove
Every mask and unmask becomes a Trust Receipt — signed, versioned, exportable as JSON or PDF. Change one character and the receipt fails.
Reversible when you need it back. Irreversible when you don’t.
The right kind of masking depends on who is downstream. Veil lets policy choose per field.
Tokenize — operations that must complete
A bank’s KYC operations agent has to look up the account after the model has understood the request. Reversible tokenization keeps a deterministic, format-preserving token in the model’s view and lets an authorised system — never the model — resolve it back inside your perimeter.
The unmask is itself a logged, policy-bound event. Nobody resolves a token without leaving a receipt.
Redact — data that should not exist downstream
A defence programme triaging incident reports, or a space agency sharing operational logs with an external model for summarisation: names of personnel, locations and identifiers should not survive the trip. Irreversible redaction removes them before egress, and there is no path back.
Because the receipt records *that* a field was redacted and under which policy — not the value — the audit trail is itself safe to keep.
Where it is doing the work
These are the deployments we are asked about most. None of them required replacing the agent or the model already in place.
Contact centres and BPOs
Chat and voice transcripts carry everything a customer chooses to type or say. Veil masks them before the assist model, the summariser and the QA scorer see them — and gives the client a receipt trail per interaction.
PSU and private banks
KYC operations, complaint handling and collections all want an AI assist and none of them want account or card data in a model log. Tokenize for the operations that must complete; redact for the rest.
Insurers and NBFCs
Claims documents mix health identifiers with financial ones. Field-level policy lets a claims agent reason over a masked document while the identifiers stay inside your boundary.
Defence and strategic programmes
Irreversible redaction of personnel, unit and location identifiers before any model — including one running air-gapped inside the wire — sees the document.
Space and mission operations
Operational logs and anomaly reports summarised by a model without the contractor, site and personnel details ever egressing.
Anyone with an auditor
Trust Receipts turn “we mask sensitive data” from a policy statement into an exportable record — who, what, which policy, when.
What Veil is not
Veil is not a prompt-injection shield — that is Kavach, which sits beside it on the same Gateway call. It is not a policy authoring tool — that is Custodian, which defines what Veil enforces. And it is not a promise that every possible sensitive field in every language will be caught on day one: classification is configured and measured with you, and the fields your policy designates are the fields Veil enforces.
It is also not a certification of your deployment. ShepHertz operates a control environment credentialed for SOC 2 and ISO 27001 and independently assessed for HIPAA and GDPR; Veil’s alignment to the DPDP Act and to RBI FREE-AI data-protection expectations is designed-to-support, and exists to inform your own assessment.
Start where the data is
Veil stands on its own in front of whatever you already run — your agents, your models, your vendor’s models — with its own masking rules and its own receipt trail. No platform migration. When you are ready, it integrates natively: Custodian defines the policy, the Gateway enforces it, Swaraj runs it air-gapped, and every receipt lands in the same audit record as the rest of the platform.
The only real prerequisite is a decision about which fields matter to you. We will help you make it, and then we will show you the receipts.
FAQ
Frequently asked questions.
- How do you stop an AI agent from seeing customer PII?
- Mask it before the call leaves your perimeter. AgentAnywhere Veil classifies PII, financial and regulated fields inline on every request and replaces them with masks — reversible tokens or irreversible redactions — so the model, tool or embedding service only ever receives the masked form. Enforcement happens at the Agent Universal Gateway, not inside the agent.
- What is the difference between tokenization and redaction in Veil?
- Reversible tokenization replaces a value with a deterministic, format-preserving token that downstream systems can keep using and an authorised system can resolve back inside your perimeter; every unmask is logged. Irreversible redaction removes the value entirely so it cannot be recovered. Policy chooses per field.
- What is a Trust Receipt?
- A Trust Receipt is Veil's audit artifact. Every mask and unmask is logged — who, what, under which policy, and when — then signed and versioned so it is tamper-evident. Trust Receipts can be exported as JSON and PDF for auditors.
- Can Veil be used with the AI models and agents we already have?
- Yes. Veil deploys standalone in front of your existing agents and models, including third-party ones, with its own masking rules and receipt trail. It also integrates natively with the AgentAnywhere platform, where Custodian defines policy, the Gateway enforces it and Swaraj runs it air-gapped.
- Does Veil help with DPDP Act or RBI FREE-AI compliance?
- Veil is aligned with RBI FREE-AI data-protection expectations and designed to support the DPDP Act, and ShepHertz operates a control environment credentialed for SOC 2, ISO 27001, HIPAA and GDPR. These are advisory alignments to inform your own assessment, not certifications of your deployment or binding regulatory claims.
Mask the data before it ever leaves your boundary.
Bring one real workflow — a contact-centre transcript, a KYC queue, a claims file. We will run it through Veil in your perimeter and hand you the receipts.