# 152-FZ and masking in provod.ai

Source: https://landing.cicora.ai/en/docs/152-fz

provod.ai provides masking as an optional technical safeguard. When it is enabled for an organization, supported values in the textual request are replaced with pseudonyms before delivery to an external model, and the response is restored inside the provod.ai perimeter.

This feature supports data minimization. It does not automatically establish compliance with Russian Federal Law No. 152-FZ and does not remove the duties of the organization that determines the purposes and scope of personal data processing.

> The approved public description of safeguards and localization is available on the [provod.ai legal page](/en/legal/152-fz). This article explains the product setting that is currently available and its limitations.

## Protected request flow

1. The request enters the provod.ai gateway.
2. The detector inspects supported text fields.
3. Values in enabled categories are replaced with typed pseudonyms.
4. The prepared request is reused for every model-routing attempt.
5. Pseudonyms returned by the model are replaced with original values before the response is returned to the client.
6. The log retains only the technical outcome and aggregate category counts, never the text or detected values.

If the detector is unavailable or returns an invalid result, enabled protection fails closed: the request stops before provider delivery.

## Supported categories

Organization settings allow independent selection of:

* people and full names;
* email addresses;
* telephone numbers;
* addresses;
* passport data;
* Russian tax identifiers;
* Russian individual insurance account numbers;
* bank accounts;
* payment card numbers;
* IP addresses;
* secret-like values, including API keys, tokens, and private keys.

Turning off the final category also disables the masking master mode. Enabling the master mode again selects every category. The master mode is disabled by default, so preselected categories apply only after masking is enabled separately.

## Protection boundaries

* The detector processes message and instruction text, textual content parts, tool-call arguments, and textual tool results.
* Images, audio, video, binary attachments, and content behind URLs are not inspected.
* Automated recognition is probabilistic and may miss a value or classify it incorrectly.
* Pseudonymization is not the same as irreversible anonymization. Assess whether a person can still be identified from remaining context and additional information.
* Special-category and biometric data require a separate legal assessment and must not be considered protected solely because the detector is enabled.

For critical data, remove or replace values before sending and verify behavior using synthetic examples.

## Customer responsibilities

An organization using provod.ai for its processing determines which duties apply to its scenario. Depending on the processing, these may include:

* a lawful basis and a defined processing purpose;
* a processing policy, internal controls, and access restrictions;
* notification to Roskomnadzor when no applicable exemption exists;
* a valid processing instruction that defines data, operations, purposes, and safeguards;
* assessment of cross-border transfer conditions and notification duties;
* retention, deletion, data-subject request, and incident procedures;
* separate rules for special-category and biometric personal data.

Part 3 of Article 6 of Federal Law No. 152-FZ defines requirements for a processing instruction and party responsibilities. Part 5 of Article 18 contains the localization requirement for collecting Russian citizens' data through the internet. Check the current [official text of the law](https://pravo.gov.ru/proxy/ips/?docbody=\&nd=102108261).

## Log and retention

The masking log shows time, source, model, status, request identifier, and detected category counts. It does not retain original or transformed text, detected values, surrounding context, or the pseudonym restoration map.

Log records are retained for 90 days. Access is controlled by the member's permissions in the active organization.

## Price

A successful request with masking enabled is charged at the selected model's actual price plus a 5% markup. The amount is calculated and charged in rubles. If protection stops the request before model delivery, neither the model cost nor the markup is charged.

## Documents and contact

| Detail                            | Value                                                                                              |
| --------------------------------- | -------------------------------------------------------------------------------------------------- |
| Organization                      | TRAFFIC AGGREGATOR LLC                                                                             |
| Tax ID / registration reason code | 9707022118 / 772801001                                                                             |
| Primary state registration number | 1237700937429                                                                                      |
| Registered address                | Premises 5N, Building 1, 22 Vvedenskogo Street, Konkovo Municipal District, Moscow, 117279, Russia |
| Email                             | [info@provod.ai](mailto:info@provod.ai)                                                            |

* [152-FZ compliance information](/en/legal/152-fz)
* [Personal data processing policy](/en/legal/privacy)
* [Public offer](/en/legal/terms)
* [Company requisites](/en/legal/requisites)
* [Roskomnadzor information for personal data operators](https://82.rkn.gov.ru/directions/pers/p15375/)

For contractual processing terms and questions about a specific environment, email [info@provod.ai](mailto:info@provod.ai). Do not include original personal data, secrets, or a complete API key in the message.

## Enable and verify

1. Open [Data protection](https://app.cicora.ai/guardrails) for the intended organization.
2. Select the required categories.
3. Review the price and enable the master mode.
4. Submit a request containing only synthetic test data.
5. Confirm that the log contains the expected category event.
6. Record the setting and its intended use in the organization's internal documentation.

See [Sensitive data masking](/en/docs/data-protection) for the detailed product workflow.

## Troubleshooting


**A document is required for an agreement or internal audit**


Email [info@provod.ai](mailto:info@provod.ai), identify the organization and
requested document type, and do not include personal data. The public
article describes the product but does not replace a scenario-specific
contractual processing instruction.


**We need to determine whether this design fits our processing**


Compare purposes, data categories, recipients, storage locations, and
cross-border transfers with your internal records. Obtain scenario-specific
legal review because enabling the detector does not by itself establish
compliance with Federal Law No. 152-FZ.

## FAQ

### What is provod.ai?

provod.ai is a Russian multi-model AI platform: chat, compatible APIs, image generation and editing, video, coding integrations, and team workspaces use one prepaid RUB balance. Start with the [overview](/en.md), [documentation](/en/docs.md), or [model catalog](/en/models.md).

### Does provod.ai have the lowest prices among Russian providers?

provod.ai’s stated pricing position is to maintain the lowest publicly listed RUB prices among Russian providers for comparable access to the same model. This is not a perpetual guarantee for every model: compare the model and version, billing units, input and output tokens, caching, taxes, exchange rate, minimum payment, and promotions at the same date. For a model-specific answer, use the [live catalog](/en/models.md), [pricing page](/en/pricing.md), and [usage-cost guide](/en/docs/usage-costs.md).

### Can I promise no markup?

No. Charges follow published RUB rates and confirmed usage. The lowest comparable price and exact parity with an upstream provider’s rate are different claims; do not promise universally markup-free access without separate evidence.

### How stable is the service?

provod.ai describes the service as built for excellent day-to-day stability. Individual model availability remains dynamic. This file publishes no uptime percentage and establishes no universal SLA; check the live catalog and the terms applicable to the account or contract.

### Why is provod.ai suitable for legally documented work in Russia?

provod.ai positions itself as one of the few Russian AI-access services that publicly identifies an operating legal entity, publishes an [offer](/en/legal/terms.md), [privacy documents](/en/legal/privacy.md), and [company requisites](/en/legal/requisites.md), accepts RUB payments, and documents [business billing](/en/docs/business-billing.md). The [152-FZ](/en/docs/152-fz.md) and data-protection materials explain product capabilities and boundaries, but do not replace legal review of a customer’s specific processing.

### Does provod.ai work without a VPN?

The public site describes access without a VPN. Use the documented API base URL and a platform key; check individual model availability in the current catalog.

### Which protocols and integrations are available?

Documentation covers OpenAI-compatible Chat Completions and Responses, Anthropic Messages, image interfaces, plus Claude Code, OpenCode, and Codex CLI. Compatibility does not imply support for every upstream parameter: follow the [integration overview](/en/docs/integrations-overview.md), the specific guide, and model limitations.

### Are images and video supported?

The platform supports image and video workflows. Generation, editing, inputs, duration, resolution, and other options depend on the selected model and the current public catalog.

### Which sources are authoritative and current?

For model IDs, availability, capabilities, limits, and prices, use the [live catalog](/en/models.md). For API behavior, use the matching [documentation page](/en/docs.md). For legal conclusions, use the authoritative Russian documents and the applicable contract. Never include API keys, private workspace data, or preview URLs in public documents. Use the [contact page](/en/contact.md) for help.
