Back to Home

Trust Center

The answers your security review needs

What Sanitized Ai commits to, how it maps to the obligations you carry, and how to reach us. One page you can send to your security team.

Our commitments

Prompt privacy by design

Administrators see flagged event metadata only: category, count, tool, time. Prompt content is never stored and never shown.

Control before submission

Detection and redaction act before a prompt reaches the AI provider, the only point where control is still possible.

Audit-ready by default

Every policy event is logged with full audit trails, and reports export for auditors, clients, and regulators.

No infrastructure changes

Deploys as a browser extension for Chrome, Edge, and Firefox in minutes, with no network changes.

99.9% uptime target

The service is built to stay out of your team's way. Availability is a commitment, not an afterthought.

Canadian company

Sanitized AI Inc. is incorporated in Canada and built fluent in Canadian privacy law.

Mapped to the obligations you carry

Sanitized Ai is a control you deploy to help meet your own obligations. Here's where it fits:

PIPEDA

Supports the safeguards and data-minimization principles: sensitive data is redacted before disclosure to a third-party AI tool, and the event log supports breach-assessment and reporting readiness.

Quebec Law 25

Supports control over the communication of personal information and incident record-keeping, with penalties for failure reaching C$25M or 4% of worldwide turnover.

GDPR

Supports data minimization at the point of disclosure: prevention before submission, where deletion requests can no longer reach.

PHIPA

Helps keep personal health information out of public AI tools when clinicians and staff work in browser-based systems.

Professional duties

For law, accounting, and other regulated firms: a record that sensitive data was caught before submission is evidence of reasonable safeguards and demonstrable diligence.

Data-handling questions, answered

Can Sanitized Ai read our employees' conversations?

No. The admin view shows flagged event metadata only: category, count, tool, and time. Prompt content is never stored and never shown to anyone.

When does redaction happen?

Before the prompt reaches the AI provider. Once data is submitted to a public AI tool it can be retained, sub-processed, or used for training, so the control acts at the last moment it still can.

Will you complete our security questionnaire?

Yes. Send it to sales@sanitized.ai and we'll return it along with our privacy documentation. We typically respond within 24 hours.

Which AI tools are covered?

ChatGPT, Claude, Gemini, Copilot, and Perplexity, along with the other AI tools shadow-AI detection surfaces. Coverage grows as new tools appear, so we keep a current list rather than a fixed number.

Which file types are covered?

File uploads are scanned in the same pass as prompts: DOCX, XLSX, PPTX, and PDF.

Responsible disclosure

Found a vulnerability? We want to hear about it. Email sales@sanitized.ai with the details and we'll route it to the right people. First response is typically within 24 hours.

Request our security documentation