Skip to content
KavachLab

Privacy

Data Privacy & Residency for AI

Keep AI monitoring data inside your own tenant with a customer-hosted data plane, customer-owned encryption keys, and jurisdiction-aware capture.

In short

AI data residency means the prompts, files, and monitoring data generated by AI governance never leave the jurisdiction or tenant you control. KavachLab is architected so this is structural rather than contractual: the entire data plane is deployed inside your own cloud, on-premises, or air-gapped environment, and the vendor never takes custody of content. Content is field-level encrypted with keys held in your own KMS or HSM, and analytics are metadata-first, meaning they operate without decrypting content.

What it gives you

  • Customer-hosted data plane

    Deployed in your AKS, EKS, GKE, or OKE cluster, on-premises, or fully air-gapped.

  • Customer-owned keys

    Field-level encryption with a key hierarchy rooted in your own KMS or HSM.

  • Metadata-first analytics

    Dashboards and reporting run on metadata and never decrypt content to produce a number.

  • Watch the watchers

    Every content read by an administrator is itself logged to the immutable audit trail.

Why a vendor-hosted AI security tool is a problem

A tool that inspects AI prompts sees the most sensitive text in the organisation by definition. If that tool ships content to a vendor cloud, you have not reduced exposure — you have added a second, highly concentrated copy of it:

  • A new data processor to assess, contract with, and disclose in your privacy notices.
  • A cross-border transfer to justify, with the transfer mechanism to document and defend.
  • A single aggregation point that is now a high-value target for an attacker.
  • A dependency: if the vendor is breached, your prompt content is in scope for your own breach notification.

What customer-hosted actually means here

The distinction that matters is between a vendor who promises not to look and an architecture where there is nothing to look at. KavachLab is the second: content never transits vendor infrastructure at any point, so the privacy guarantee does not rest on vendor policy or good behaviour.

Jurisdiction-aware capture

Capture is minimised and jurisdiction-aware, with a documented lawful basis for each category of data collected. Retention windows, legal-hold, and right-to-erasure workflows are enforced within your tenant, and role-scoped access (RBAC plus ABAC) governs which administrators can see what.

FAQ

Data Privacy & Residency for AI: questions we get asked

Straight answers to what security, privacy, and compliance teams ask us first.

Does KavachLab ever see our prompt content?

No. The data plane runs entirely inside your tenant and content never transits vendor infrastructure. Content is field-level encrypted with keys you own, so it is not technically accessible to the vendor even in principle.

Can it run air-gapped?

Yes. The data plane supports fully air-gapped deployment, alongside on-premises and customer-cloud (AKS, EKS, GKE, OKE) options.

How does this help with GDPR and PDPL?

Keeping processing inside your own tenant removes the cross-border transfer and third-party processor questions entirely for prompt content. Combined with data minimisation, documented lawful basis, retention controls, and right-to-erasure support, it directly addresses the obligations that AI monitoring would otherwise complicate.

Ready to see every AI interaction?

Talk to our team for a guided demo and a scoped, monitor-only discovery pilot.

Request a Demo

Fields marked with an asterisk are required.

Which AI tools are in use?

By submitting, you agree to our Privacy Policy.