Version 1.0 · Updated July 10, 2026
Compliance requirements
provod.ai complies with the requirements of Federal Law No. 152-FZ. Personal data is masked before a request is sent to a foreign language model, while the original values remain within the Russian perimeter.
Summary
provod.ai operates as a protected gateway between a customer’s information system and external models. Before a request is sent, direct identifiers are replaced with typed pseudonyms. The model receives depersonalized context, and reverse substitution is performed after the response is received on servers in Russia.
| Stage | What happens |
|---|---|
| Before the model | A PII detector finds direct identifiers and replaces them with pseudonyms inside the Russian perimeter. |
| At the provider | The external model processes the request without original names, telephone numbers, documents, or other detected identifiers. |
| After the response | The gateway restores values using the encrypted mapping and returns the response to the customer. |
| In the log | The fact of masking and the number of entities by category are recorded, but original personal data values are not. |
Processing principles
- Minimization. Only the content needed for the task is sent to the external provider; direct identifiers are replaced.
- Stable pseudonyms. Repeated mentions of the same entity receive the same designation within a defined context, so the model does not lose the relationships between parts of the request.
- Reversibility only in Russia. The relationship between a pseudonym and its original value is stored separately from the model provider.
- Verifiability. The application of masking is recorded in the security log without recording the detected values.
How masking works
- Receipt. The request enters the provod.ai gateway in the Russian Federation.
- Personal data detection. An NER model and formal patterns find identifiers.
- Replacement. Values are converted into markers such as
[NAME_1]and[EMAIL_1]. - Model. The provider receives only the prepared request.
- Mapping. Pseudonyms and originals are linked in a separate encrypted record associated with the account and request.
- Reverse substitution. After the model responds, the original values are restored inside the Russian perimeter.
- Deletion. The temporary mapping is deleted after processing is complete unless retention of stable pseudonyms is configured for the perimeter.
Detected categories
Full names and name forms; Email; Telephone numbers; SNILS; INN and OGRN; Russian passports; Bank cards; Settlement accounts; Addresses; Vehicle registration numbers; Custom patterns.
For a corporate perimeter, additional regular patterns can be defined for internal identifiers, contract numbers, and industry-specific details.
Pseudonym storage
The “pseudonym → original value” mapping is encrypted separately from application data. Key material is isolated from the services that send requests to model providers and is rotated regularly.
By default, the mapping exists only while the request is processed. For scenarios in which one data subject must retain the same pseudonym across sessions, long-term storage is configured separately for the perimeter.
Audit log
For each protected request, the following is logged:
- request identifier, date, and time;
- API key, organization, and selected model;
- number of detected entities by category without original values;
- the fact of masking and reverse substitution;
- processing result and technical status.
The log is needed to investigate incidents and confirm operation of the protection perimeter, but does not itself become an additional personal data store.
Data localization
Initial detection, recording of the mapping, reverse substitution, and storage of original personal data are performed on servers in the Russian Federation. A pseudonymized request is sent outside the Russian perimeter without the additional information needed to restore a person’s identity.
Data processing agreement
For corporate customers, processing terms are set out in a separate DPA or personal data processing instruction. The document defines:
- purposes, personal data categories, and the list of operations;
- data localization and protection requirements;
- the procedure for engaging model providers;
- retention, deletion, and incident notification periods;
- the procedure for providing information for audits.
Documents can be requested at info@provod.ai.
Responsible for processing
Email: info@provod.ai
Document: Personal data processing policy
Legislation: Federal Law No. 152-FZ
Roskomnadzor: Information for personal data operators
Frequently asked questions
Does an external provider see original personal data?
No. Direct identifiers are replaced with typed pseudonyms before sending. The restoration mapping remains within the Russian perimeter.
How is the meaning of a request preserved after replacement?
The same entities receive stable markers within the context. The model distinguishes participants and repeated mentions without receiving their original data.
What should be done with a company’s internal identifiers?
Additional patterns are configured for them. This makes it possible to find contract numbers, customer numbers, and other values that are not included in the standard categories.
This page describes the technical and organizational measures through which provod.ai ensures compliance with the requirements of Federal Law No. 152-FZ.