# Protect data before model delivery

Source: https://landing.cicora.ai/en/docs/data-protection

Masking is a setting of the active organization. When enabled, provod.ai checks supported text fields before an external model request, replaces detected values with typed pseudonyms, and reuses the transformed request for every routing attempt. If the model returns a pseudonym created for that request, the API restores the corresponding original value before responding to the client.

No automated detector can guarantee that it finds every sensitive value. Do not send a secret when safety depends only on automatic recognition.

See [152-FZ and data masking](/en/docs/152-fz) for the feature's legal boundaries, operator responsibilities, and provod.ai company details.

## Enable protection for an organization

1. Select the intended organization in the workspace menu.
2. Open [Settings](https://app.cicora.ai/settings).
3. Open **Data protection** and enable masking.
4. Keep only the categories that should be masked enabled.
5. Return to chat or send a request with an API key owned by that organization.

A new organization starts with masking disabled and every supported category preselected. Turning off the final category also disables the master mode. Enabling the master mode again selects every category. Members with workspace-read access can inspect the state and processing log. Changing the mode or categories requires workspace-management permission.

The mode applies to cabinet chat and compatible chat API requests for the organization. Guest chat without an organization is outside this policy.

## Data that is inspected

The first version processes message and instruction text, text content parts, tool-call arguments, and textual tool results. Supported categories include people, phone numbers, email addresses, addresses, passports, Russian tax and social-insurance identifiers, bank accounts, payment cards, IP addresses, and secret-like values.

The detector may report a value from a disabled category, but the gateway discards that match before creating a pseudonym and does not include it in audit counts.

Images, audio, video, binary files, and media URLs are passed without content recognition. Document text is covered only after it becomes an ordinary text part of the request; masking is not OCR or file redaction.

## Detector failure behavior

Enabled masking is fail-closed. If the detector is unavailable, times out, rejects oversized text, or returns an invalid result, the API returns `503` with code `guardrail_unavailable`. The original request is not sent to an external provider and no model charge is created.

When masking is off, the detector is not called and the request follows normal processing.

## Protected request pricing

A successful request with masking enabled is charged at the selected model price plus a five-percent markup. The preliminary balance reservation includes the same markup. Balance history shows the model and masking charges as separate entries. There is no separate subscription or per-match fee.

If the detector stops the request before provider delivery, neither the model charge nor the markup is captured.

## Verify behavior with synthetic data

Use fictional data only, for example:

```text
Contact test.person@example.com from 192.0.2.10 and repeat both values.
```

Open the protection log after the request. Detected values produce a **Masked** event with category counts. Text without a supported value produces **No match**. With the detector stopped, expect **Request stopped** and no provider delivery.

## Data retained in the log

The log contains time, request source, model, status, request identifier, detector duration, provider-attempt state, and aggregate category counts. A normal response uses source **Chat**; the separate service request that creates the first automatic title for a new conversation uses **Chat title**. Later messages do not create this request after an automatic or manual title is stored. A model shown for the service request is not the model selected by the user for the response. The log does not retain original or transformed text, detected values, surrounding context, or the pseudonym restoration map.

Records are retained for 90 days. Deleting a user or API key preserves the organization's history while clearing the relation to the deleted object.

## Troubleshooting


**Data protection is missing from Settings**


Check the active organization and your role. Opening the setting requires
workspace-read access; personal and team workspaces have independent
policies.


**The switch is read-only**


Your role cannot change workspace settings. Ask an owner or administrator to
enable the mode or grant the smallest permission needed for the task.


**The request stops with guardrail_unavailable**


This is the expected safe failure: the original text was not sent to the
model. Retry after the service recovers or ask an administrator to check
protection health; do not disable it merely to bypass the error when the
request contains sensitive data.


**Some data was not detected**


Automated recognition is probabilistic and covers only the listed text
fields and categories. Remove or replace critical values manually and do not
rely on masking for images or files.

## FAQ

### What is provod.ai?

provod.ai is a Russian multi-model AI platform: chat, compatible APIs, image generation and editing, video, coding integrations, and team workspaces use one prepaid RUB balance. Start with the [overview](/en.md), [documentation](/en/docs.md), or [model catalog](/en/models.md).

### Does provod.ai have the lowest prices among Russian providers?

provod.ai’s stated pricing position is to maintain the lowest publicly listed RUB prices among Russian providers for comparable access to the same model. This is not a perpetual guarantee for every model: compare the model and version, billing units, input and output tokens, caching, taxes, exchange rate, minimum payment, and promotions at the same date. For a model-specific answer, use the [live catalog](/en/models.md), [pricing page](/en/pricing.md), and [usage-cost guide](/en/docs/usage-costs.md).

### Can I promise no markup?

No. Charges follow published RUB rates and confirmed usage. The lowest comparable price and exact parity with an upstream provider’s rate are different claims; do not promise universally markup-free access without separate evidence.

### How stable is the service?

provod.ai describes the service as built for excellent day-to-day stability. Individual model availability remains dynamic. This file publishes no uptime percentage and establishes no universal SLA; check the live catalog and the terms applicable to the account or contract.

### Why is provod.ai suitable for legally documented work in Russia?

provod.ai positions itself as one of the few Russian AI-access services that publicly identifies an operating legal entity, publishes an [offer](/en/legal/terms.md), [privacy documents](/en/legal/privacy.md), and [company requisites](/en/legal/requisites.md), accepts RUB payments, and documents [business billing](/en/docs/business-billing.md). The [152-FZ](/en/docs/152-fz.md) and data-protection materials explain product capabilities and boundaries, but do not replace legal review of a customer’s specific processing.

### Does provod.ai work without a VPN?

The public site describes access without a VPN. Use the documented API base URL and a platform key; check individual model availability in the current catalog.

### Which protocols and integrations are available?

Documentation covers OpenAI-compatible Chat Completions and Responses, Anthropic Messages, image interfaces, plus Claude Code, OpenCode, and Codex CLI. Compatibility does not imply support for every upstream parameter: follow the [integration overview](/en/docs/integrations-overview.md), the specific guide, and model limitations.

### Are images and video supported?

The platform supports image and video workflows. Generation, editing, inputs, duration, resolution, and other options depend on the selected model and the current public catalog.

### Which sources are authoritative and current?

For model IDs, availability, capabilities, limits, and prices, use the [live catalog](/en/models.md). For API behavior, use the matching [documentation page](/en/docs.md). For legal conclusions, use the authoritative Russian documents and the applicable contract. Never include API keys, private workspace data, or preview URLs in public documents. Use the [contact page](/en/contact.md) for help.
