PDM

Fort Knox, not a hotel safe.

Verifiable and Transparent Due Diligence

Here's how a file moves through the system:

Your file

TLS 1.2+ encrypted

Google Cloud Organization Perimeter

SOC 2 Type II · ISO 27001 · VPC Service Controls

Private VPC

No public IP address

App server

Cloud Run

Masking engine

Sealed

Private storage

Cloud SQL + GCS

Deletion Audit Log

Independent of application code

TLS 1.2+ encrypted

Masked file

Destroyed after delivery — logged independently

Control Boundaries

What each boundary does

ControlMechanismVerification
Data cannot leave the environmentVPC Service Controls, org-level perimeterEnforced at platform level, not application config
No public network exposureNo public IP on database or storageNo route from the open internet
No LLM in the pipelineGoogle Cloud DLP + deterministic algorithms onlyNo LLM ever processes values
Deletion is enforcedGCS Lifecycle Management rule, 48-hour maxEvery deletion independently logged
Infrastructure is independently auditedGoogle Cloud, SOC 2 Type II, ISO 27001Platform-level certification

The bottom line

Files are encrypted, hidden, protected, processed, and deleted. No unauthorized access, either direction.

Detection accuracy is tested and published, including known limits — see /accuracy.

Ready to mask your data?

Upload a file, get an upfront price, pay only if you proceed.

Upload My File