152-FZ and masking in provod.ai
How to use provod.ai masking as a technical safeguard and which obligations remain with the personal data operator.
Last updated on
provod.ai provides masking as an optional technical safeguard. When it is enabled for an organization, supported values in the textual request are replaced with pseudonyms before delivery to an external model, and the response is restored inside the provod.ai perimeter.
This feature supports data minimization. It does not automatically establish compliance with Russian Federal Law No. 152-FZ and does not remove the duties of the organization that determines the purposes and scope of personal data processing.
The approved public description of safeguards and localization is available on the provod.ai legal page. This article explains the product setting that is currently available and its limitations.
Protected request flow
- The request enters the provod.ai gateway.
- The detector inspects supported text fields.
- Values in enabled categories are replaced with typed pseudonyms.
- The prepared request is reused for every model-routing attempt.
- Pseudonyms returned by the model are replaced with original values before the response is returned to the client.
- The log retains only the technical outcome and aggregate category counts, never the text or detected values.
If the detector is unavailable or returns an invalid result, enabled protection fails closed: the request stops before provider delivery.
Supported categories
Organization settings allow independent selection of:
- people and full names;
- email addresses;
- telephone numbers;
- addresses;
- passport data;
- Russian tax identifiers;
- Russian individual insurance account numbers;
- bank accounts;
- payment card numbers;
- IP addresses;
- secret-like values, including API keys, tokens, and private keys.
Turning off the final category also disables the masking master mode. Enabling the master mode again selects every category. The master mode is disabled by default, so preselected categories apply only after masking is enabled separately.
Protection boundaries
- The detector processes message and instruction text, textual content parts, tool-call arguments, and textual tool results.
- Images, audio, video, binary attachments, and content behind URLs are not inspected.
- Automated recognition is probabilistic and may miss a value or classify it incorrectly.
- Pseudonymization is not the same as irreversible anonymization. Assess whether a person can still be identified from remaining context and additional information.
- Special-category and biometric data require a separate legal assessment and must not be considered protected solely because the detector is enabled.
For critical data, remove or replace values before sending and verify behavior using synthetic examples.
Customer responsibilities
An organization using provod.ai for its processing determines which duties apply to its scenario. Depending on the processing, these may include:
- a lawful basis and a defined processing purpose;
- a processing policy, internal controls, and access restrictions;
- notification to Roskomnadzor when no applicable exemption exists;
- a valid processing instruction that defines data, operations, purposes, and safeguards;
- assessment of cross-border transfer conditions and notification duties;
- retention, deletion, data-subject request, and incident procedures;
- separate rules for special-category and biometric personal data.
Part 3 of Article 6 of Federal Law No. 152-FZ defines requirements for a processing instruction and party responsibilities. Part 5 of Article 18 contains the localization requirement for collecting Russian citizens' data through the internet. Check the current official text of the law.
Log and retention
The masking log shows time, source, model, status, request identifier, and detected category counts. It does not retain original or transformed text, detected values, surrounding context, or the pseudonym restoration map.
Log records are retained for 90 days. Access is controlled by the member's permissions in the active organization.
Price
A successful request with masking enabled is charged at the selected model's actual price plus a 5% markup. The amount is calculated and charged in rubles. If protection stops the request before model delivery, neither the model cost nor the markup is charged.
Documents and contact
| Detail | Value |
|---|---|
| Organization | TRAFFIC AGGREGATOR LLC |
| Tax ID / registration reason code | 9707022118 / 772801001 |
| Primary state registration number | 1237700937429 |
| Registered address | Premises 5N, Building 1, 22 Vvedenskogo Street, Konkovo Municipal District, Moscow, 117279, Russia |
| info@provod.ai |
- 152-FZ compliance information
- Personal data processing policy
- Public offer
- Company requisites
- Roskomnadzor information for personal data operators
For contractual processing terms and questions about a specific environment, email info@provod.ai. Do not include original personal data, secrets, or a complete API key in the message.
Enable and verify
- Open Data protection for the intended organization.
- Select the required categories.
- Review the price and enable the master mode.
- Submit a request containing only synthetic test data.
- Confirm that the log contains the expected category event.
- Record the setting and its intended use in the organization's internal documentation.
See Sensitive data masking for the detailed product workflow.