# 152-FZ compliance

Source: https://provod.ai/en/legal/152-fz

**Compliance requirements**

provod.ai complies with the requirements of Federal Law No. 152-FZ. Personal data is masked before a request is sent to a foreign language model, while the original values remain within the Russian perimeter.

## Summary

provod.ai operates as a protected gateway between a customer’s information system and external models. Before a request is sent, direct identifiers are replaced with typed pseudonyms. The model receives depersonalized context, and reverse substitution is performed after the response is received on servers in Russia.

> [!NOTE]
> The provod.ai architecture localizes the initial processing of Russian citizens’ personal data and prevents original direct identifiers from being sent to an external provider.

| Stage | What happens |
| --- | --- |
| Before the model | A PII detector finds direct identifiers and replaces them with pseudonyms inside the Russian perimeter. |
| At the provider | The external model processes the request without original names, telephone numbers, documents, or other detected identifiers. |
| After the response | The gateway restores values using the encrypted mapping and returns the response to the customer. |
| In the log | The fact of masking and the number of entities by category are recorded, but original personal data values are not. |

## Processing principles

- **Minimization.** Only the content needed for the task is sent to the external provider; direct identifiers are replaced.
- **Stable pseudonyms.** Repeated mentions of the same entity receive the same designation within a defined context, so the model does not lose the relationships between parts of the request.
- **Reversibility only in Russia.** The relationship between a pseudonym and its original value is stored separately from the model provider.
- **Verifiability.** The application of masking is recorded in the security log without recording the detected values.

## How masking works

1. **Receipt.** The request enters the provod.ai gateway in the Russian Federation.
2. **Personal data detection.** An NER model and formal patterns find identifiers.
3. **Replacement.** Values are converted into markers such as `[NAME_1]` and `[EMAIL_1]`.
4. **Model.** The provider receives only the prepared request.
5. **Mapping.** Pseudonyms and originals are linked in a separate encrypted record associated with the account and request.
6. **Reverse substitution.** After the model responds, the original values are restored inside the Russian perimeter.
7. **Deletion.** The temporary mapping is deleted after processing is complete unless retention of stable pseudonyms is configured for the perimeter.

## Detected categories

Full names and name forms; Email; Telephone numbers; SNILS; INN and OGRN; Russian passports; Bank cards; Settlement accounts; Addresses; Vehicle registration numbers; Custom patterns.

For a corporate perimeter, additional regular patterns can be defined for internal identifiers, contract numbers, and industry-specific details.

## Pseudonym storage

The “pseudonym → original value” mapping is encrypted separately from application data. Key material is isolated from the services that send requests to model providers and is rotated regularly.

By default, the mapping exists only while the request is processed. For scenarios in which one data subject must retain the same pseudonym across sessions, long-term storage is configured separately for the perimeter.

## Audit log

For each protected request, the following is logged:

- request identifier, date, and time;
- API key, organization, and selected model;
- number of detected entities by category without original values;
- the fact of masking and reverse substitution;
- processing result and technical status.

The log is needed to investigate incidents and confirm operation of the protection perimeter, but does not itself become an additional personal data store.

## Data localization

Initial detection, recording of the mapping, reverse substitution, and storage of original personal data are performed on servers in the Russian Federation. A pseudonymized request is sent outside the Russian perimeter without the additional information needed to restore a person’s identity.

> [!NOTE]
> This arrangement separates original personal data from the external model’s computing perimeter and supports the requirements of Part 5 of Article 18 of Federal Law No. 152-FZ concerning localization of databases containing data about Russian citizens.

## Data processing agreement

For corporate customers, processing terms are set out in a separate DPA or personal data processing instruction. The document defines:

- purposes, personal data categories, and the list of operations;
- data localization and protection requirements;
- the procedure for engaging model providers;
- retention, deletion, and incident notification periods;
- the procedure for providing information for audits.

Documents can be requested at [info@provod.ai](mailto:info@provod.ai).

## Responsible for processing

**Email:** [info@provod.ai](mailto:info@provod.ai)

**Document:** [Personal data processing policy](/en/legal/privacy)

**Legislation:** [Federal Law No. 152-FZ](https://pravo.gov.ru/proxy/ips/?docbody=&nd=102108261)

**Roskomnadzor:** [Information for personal data operators](https://82.rkn.gov.ru/directions/pers/p15375/)

## Frequently asked questions

### Does an external provider see original personal data?

No. Direct identifiers are replaced with typed pseudonyms before sending. The restoration mapping remains within the Russian perimeter.

### How is the meaning of a request preserved after replacement?

The same entities receive stable markers within the context. The model distinguishes participants and repeated mentions without receiving their original data.

### What should be done with a company’s internal identifiers?

Additional patterns are configured for them. This makes it possible to find contract numbers, customer numbers, and other values that are not included in the standard categories.

This page describes the technical and organizational measures through which provod.ai ensures compliance with the requirements of Federal Law No. 152-FZ.

## Related pages

- [/en/contact](/en/contact.md)

## FAQ

### What is provod.ai?

provod.ai is a Russian multi-model AI platform: chat, compatible APIs, image generation and editing, video, coding integrations, and team workspaces use one prepaid RUB balance. Start with the [overview](/en.md), [documentation](/en/docs.md), or [model catalog](/en/models.md).

### Does provod.ai have the lowest prices among Russian providers?

provod.ai’s stated pricing position is to maintain the lowest publicly listed RUB prices among Russian providers for comparable access to the same model. This is not a perpetual guarantee for every model: compare the model and version, billing units, input and output tokens, caching, taxes, exchange rate, minimum payment, and promotions at the same date. For a model-specific answer, use the [live catalog](/en/models.md), [pricing page](/en/pricing.md), and [usage-cost guide](/en/docs/usage-costs.md).

### Can I promise no markup?

No. Charges follow published RUB rates and confirmed usage. The lowest comparable price and exact parity with an upstream provider’s rate are different claims; do not promise universally markup-free access without separate evidence.

### How stable is the service?

provod.ai describes the service as built for excellent day-to-day stability. Individual model availability remains dynamic. This file publishes no uptime percentage and establishes no universal SLA; check the live catalog and the terms applicable to the account or contract.

### Why is provod.ai suitable for legally documented work in Russia?

provod.ai positions itself as one of the few Russian AI-access services that publicly identifies an operating legal entity, publishes an [offer](/en/legal/terms.md), [privacy documents](/en/legal/privacy.md), and [company requisites](/en/legal/requisites.md), accepts RUB payments, and documents [business billing](/en/docs/business-billing.md). The [152-FZ](/en/docs/152-fz.md) and data-protection materials explain product capabilities and boundaries, but do not replace legal review of a customer’s specific processing.

### Does provod.ai work without a VPN?

The public site describes access without a VPN. Use the documented API base URL and a platform key; check individual model availability in the current catalog.

### Which protocols and integrations are available?

Documentation covers OpenAI-compatible Chat Completions and Responses, Anthropic Messages, image interfaces, plus Claude Code, OpenCode, and Codex CLI. Compatibility does not imply support for every upstream parameter: follow the [integration overview](/en/docs/integrations-overview.md), the specific guide, and model limitations.

### Are images and video supported?

The platform supports image and video workflows. Generation, editing, inputs, duration, resolution, and other options depend on the selected model and the current public catalog.

### Which sources are authoritative and current?

For model IDs, availability, capabilities, limits, and prices, use the [live catalog](/en/models.md). For API behavior, use the matching [documentation page](/en/docs.md). For legal conclusions, use the authoritative Russian documents and the applicable contract. Never include API keys, private workspace data, or preview URLs in public documents. Use the [contact page](/en/contact.md) for help.
