Prove what your
AI agents did —
and what they never saw.
CloakPipe is the verifiable privacy & policy control plane for AI-agent traffic. Every hop — prompt, tool call, tool result — gets a deterministic policy decision made outside the model, and every decision produces cryptographic evidence anyone can verify without trusting us. Redaction is just the first policy type.
Everyone's audit trail is self-attested. CloakPipe anchors evidence outside operator control — a regulator, insurer, or opposing counsel checks it themselves, offline, without trusting CloakPipe or you.
Verifiable evidence ledger
Hash-chained, signed records of every hop — PII types detected, what was masked, the policy applied, the decision made. Never the raw value.
Externally anchored
Chain heads anchored outside our control via Sigstore Rekor and RFC-3161 timestamps, Merkle-batched for flat cost at volume. Not just "immutable" — independently checkable.
Open verifier CLI — free forever
Auditors verify chain integrity, signatures, and anchors themselves, offline. One command exports a sealed auditor pack for a date range — the thing you hand a regulator.
Every other tool replaces sensitive entities with dead tokens like
[PERSON]
— the original information is gone forever. CloakPipe replaces them with
deterministic fake entities the LLM can still reason about,
then restores the real values on the way back. This masking layer is the foundation
everything above it — policy, evidence, verification — is built on.
Format-preserving. Replacement credit cards pass the Luhn checksum. Replacement IBANs pass mod-97. Replacement emails are still emails. The model — and any downstream system that consumes its output — keeps working exactly as before.
The Rust proxy is the foundation — open source under Apache 2.0. The Vault, Agent-Hop Policy, and Evidence Ledger layers are the commercial platform: the part that closes enterprise deals in regulated industries.
- OpenAI-compatible API — change one base URL, your app keeps working
- Streaming SSE rehydration without buffering or breaking the contract
- Routes to OpenAI, Anthropic, Google, Bedrock, Azure, self-hosted
- Native MCP server for agent integrations
- AES-256-GCM at rest
- Customer-managed keys via KMS
- Format-preserving — cards pass Luhn
- Per-tenant isolation
- Automatic key rotation
- Cedar — formally-verified, sub-millisecond decisions
- Ingress/egress · tool/parameter · conduct rules
- RBAC + SAML / OIDC · IdP role mapping
- Hash-chained + externally anchored (Rekor / RFC-3161)
- Open verifier CLI, free forever · auditor pack export
- HIPAA · GDPR · SOC 2 · PCI-DSS · EU AI Act exports
CloakPipe speaks the OpenAI API dialect and ships native middleware for the frameworks you're already using. One line of config. Zero rewrites.
CloakPipeRunnable middleware. Drop-in for any chain or agent. Streaming-safe.Same Rust binary. Same detection pipeline. Same vault encryption. Pick the topology that matches your security posture.
The Rust proxy, detection, and pseudonymization are free forever, Apache 2.0 — including the verifier CLI. You pay when you want anchoring, auditor packs, agent-hop policy, and unmask RBAC — the things that make CloakPipe production-ready for regulated industries.
- Rust proxy & CLI
- Full detection pipeline
- Pseudonymization vault
- MCP server
- Streaming rehydration
- Everything in Community
- Managed cloud hosting
- Web dashboard & metrics
- 250K API calls
- Audit logs · 30 day
- Policy engine & RBAC
- SSO · SAML / OIDC
- HIPAA BAA available
- 2M API calls
- 99.9% SLA · priority
- Everything in Growth
- VPC / on-prem / air-gapped
- Customer-managed KMS
- CBAC + custom policies
- 99.99% SLA · TAM
- Embedded integration
- White-label option
- Per-request licensing
- Co-marketing
- Dedicated engineering