intentic
Download the app
Download the app
Agent setup

Privacy shield

What personal data is kept from model providers, and the record of what was masked

On this page(8 sections)

The shield replaces names, numbers and other personal data with tokens before a request reaches a provider you have not trusted, and puts the real values back on the way out. These routes read its state and replace its policy, which only the owner may do; read the log of what it masked; look a word up in the name dictionary; and list, teach and forget the datasets of known values it masks wherever they appear.

8 calls. Pick one to open it, or use the list on the right.

GET/privacy/shieldThe privacy shield and what it covers

Whether personal data is kept from untrusted model providers, which providers are trusted, which local readers are installed, and how many values it has learned.

What you send

Nothing. Call it as it is.

What comes back

FieldType
policyobject
modeWhether the shield is off, only…"off" | "watch" | "on"
trustedProviders that may read personal data…string[]
classesWhich kinds of personal data are…"person-name" | "national-id" | "tax-id" | "identity-document" … (9)[]
imagesWhat an image bound for an…"mask" | "allow"
namesHow names are found"dictionary" | "model"
allowValues never masked: your own company,…string[]
conversationsProviders that may read one conversation's…object[]
conversationIdstring
providerProvider id, as the trusted list…string
knownValues taught from your datasets, matched…integer
tokensValues the shield has given a…integer
readersobject
ocrThe local text reader (PaddleOCR) that…boolean
modelA local named-entity model for names…boolean
providersobject[]
idProvider id, as the trusted list…string
labelstring
shieldableIts runtime can be put behind…boolean
localIt runs on this machine, so…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/privacy/shield" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.status();
POST/privacy/shieldChange the privacy shield

Replaces the policy whole. Turning the shield on puts every turn that starts from then on, whose runtime can be shielded, behind the gateway, and refuses the turns that cannot be shielded on an untrusted provider; a turn already running keeps the route it started with. A change to what is masked or trusted holds from the next model request.

What you send

FieldTypeWhere
modeWhether the shield is off, only…"off" | "watch" | "on"body
trustedProviders that may read personal data…string[]body
classesWhich kinds of personal data are…"person-name" | "national-id" | "tax-id" | "identity-document" … (9)[]body
imagesWhat an image bound for an…"mask" | "allow"body
namesHow names are found"dictionary" | "model"body
allowValues never masked: your own company,…string[]body
conversationsProviders that may read one conversation's…object[]body
conversationIdrequiredstringbody
providerrequiredProvider id, as the trusted list…stringbody

What comes back

FieldType
okAlways truetrue
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/privacy/shield" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"mode":"off","trusted":["…","…"],"classes":["person-name","national-id"],"images":"mask","names":"dictionary","allow":["…","…"],"conversations":[{"conversationId":"nightly-changelog","provider":"claude"},{"conversationId":"release-notes","provider":"claude"}]}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.setPolicy({
  "mode": "off",
  "trusted": [
    "…",
    "…"
  ],
  "classes": [
    "person-name",
    "national-id"
  ],
  "images": "mask",
  "names": "dictionary",
  "allow": [
    "…",
    "…"
  ],
  "conversations": [
    {
      "conversationId": "nightly-changelog",
      "provider": "claude"
    },
    {
      "conversationId": "release-notes",
      "provider": "claude"
    }
  ]
});
GET/privacy/logWhat the privacy shield did lately

Each model request the gateway handled: which provider, whether it was trusted, how many of each kind of personal data it found, and the tokens it gave with the masked text around them. Never the values.

What you send

Nothing. Call it as it is.

What comes back

FieldType
atWhen, as an ISO timestampstring
conversationIdstring
providerstring
trustedboolean
action"masked" | "watched" | "passed" | "refused"
countsHow many of each kind were…object
imagesImages the shield changed: personal data…integer
documentsDocuments replaced by their masked textinteger
protocolWhich wire format the request spokestring
detailWhy it was refused, when it…string
replacementsThe first values replaced in what…object[]
tokenThe token the value became, as…string
class"person-name" | "national-id" | "tax-id" | "identity-document" … (9)
excerptThe masked text around the token…string
imageFound in an image's text, so…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/privacy/log" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.log();
POST/privacy/revealRead tokens back to their values

The value each token stands for, from the vault, so the owner can check what the shield masked and spot a value it should have left alone. Only the owner may ask; a token the vault never gave out is left out.

What you send

FieldTypeWhere
tokensrequiredstring[]body

What comes back

A plain value rather than an object. The example below is the whole of it.

Try itanswered in this tab
curl
curl -X POST "$SANDBOX/privacy/reveal" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"tokens":["ict_9wQ4rTz8kLmN3pXbV7hJ","ict_9wQ4rTz8kLmN3pXbV7hJ"]}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.reveal({
  "tokens": [
    "ict_9wQ4rTz8kLmN3pXbV7hJ",
    "ict_9wQ4rTz8kLmN3pXbV7hJ"
  ]
});
GET/privacy/dictionaryThe name lists the shield finds names by

Every list the dictionary holds (first names, surnames, words that are names only beside other evidence, titles), how many words each has and where they come from. With a query, what the dictionary makes of it as a name, and for one word the listed words starting with it.

What you send

FieldTypeWhere
queryA word, the start of one,…stringquery

What comes back

FieldType
listsobject[]
idStable id of the liststring
kindWhat a word on it says…"first-name" | "surname" | "ambiguous" | "title" … (5)
languagesThe languages its words come from"pl" | "en"[]
countHow many words it holdsinteger
matchinginflected: matched in every grammatical form…"inflected" | "as-written"
sourceWhere the words come from: the…string
urlThe source's page, where it has…string
licensestring
totalsDistinct words across the first-name lists,…object
firstNamesinteger
surnamesinteger
matchesobject[]
wordstring
listsIds of the lists holding itstring[]
lookupobject
textThe query as a name is…string
foundWhether the dictionary alone masks it…boolean
wordsobject[]
wordstring
firstNameA listed first name, in this…boolean
surnameA listed surname, in this form…boolean
surnameFormShaped like a Polish surname (-ski,…boolean
ambiguousAlso an ordinary word, so found…boolean
neverNever taken as part of a…boolean
Try itanswered in this tab
curl
curl "$SANDBOX/privacy/dictionary" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.dictionary();
GET/privacy/knownThe datasets taught to the shield

Each source values were taught from, and how many. The values themselves are never sent back.

What you send

Nothing. Call it as it is.

What comes back

FieldType
sourceWhere the values came from, as…string
countinteger
atWhen they were last taughtstring
Try itanswered in this tab
curl
curl "$SANDBOX/privacy/known" \
  -H "x-intentic-control: $INTENTIC_TOKEN"
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.sources();
POST/privacy/knownTeach the shield a dataset's values

Each value is masked wherever it appears from now on, in every form it is written, whether or not the detectors would have found it. Teaching only ever masks more, so the agent may do it.

What you send

FieldTypeWhere
sourcerequiredWhere the values came from: a…stringbody
valuesrequiredobject[]body
valuerequiredstringbody
classrequired"person-name" | "national-id" | "tax-id" | "identity-document" … (9)body

What comes back

FieldType
addedinteger
knowninteger
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/privacy/known" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"source":"…","values":[{"value":"…","class":"person-name"},{"value":"…","class":"national-id"}]}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.learn({
  "source": "…",
  "values": [
    {
      "value": "…",
      "class": "person-name"
    },
    {
      "value": "…",
      "class": "national-id"
    }
  ]
});
POST/privacy/known/forgetForget a taught dataset

Stops matching the values taught from one source. Tokens already given to them still resolve, so earlier conversations keep reading right.

What you send

FieldTypeWhere
sourcerequiredstringbody

What comes back

FieldType
forgotteninteger
Try itanswered in this tab
curl
curl -X POST "$SANDBOX/privacy/known/forget" \
  -H "x-intentic-control: $INTENTIC_TOKEN" \
  -H "content-type: application/json" \
  -d '{"source":"…"}'
TypeScript
import { sandbox } from "@intentic/sandbox-client";

const result = await sandbox.privacy.forget({
  "source": "…"
});
More in Agent setup

Type to search every page, in the docs and the API reference.