DataSunrise Achieves AWS Data & Analytics Competency. Learn more →

Part ofProtection and Enforcement

Generative AI Data Masking

Protect Sensitive Data in AI Conversations

Detect protected information, apply provider-aware masking, and block risky prompts across OpenAI and ChatGPT, Anthropic Claude, Amazon Bedrock, Azure OpenAI and Azure AI, and Google Gemini.

  • Sensitive-Data Policies
  • Prompt Controls
  • Provider-Aware Masking

Keep sensitive data out of Generative AI conversations

Employees and applications can send sensitive information to Generative AI services in seconds. DataSunrise checks AI interactions against security policy before protected content reaches its destination.

When a rule finds protected data, DataSunrise can mask the matching value or block the prompt. The resulting masking or security event shows what the policy detected and what action it took.

Information Types define the personal, financial, health, credential, and other protected data that each policy should recognize.

Protect Sensitive Data on the Way to and From AI Services

Use one policy flow to inspect an interaction, find protected data, apply a control, and keep the result for review.

  1. Inspect the interaction

    DataSunrise reads the prompt or response fields available through the AI service integration.

  2. Find sensitive data

    Information Types check the content for personal, financial, health, credential, and other protected data.

  3. Mask or block

    The policy replaces matching values or stops a prompt before the AI service processes it.

  4. Review the result

    Dynamic Masking Events and Security Events show what the rule found and what action it took.

Generative AI Activity Monitoring can add the surrounding interaction and identity context for investigation.

Explore Generative AI Data Protection

1 / 4

Choose What Happens When a Policy Matches

Masking replaces the sensitive part of an interaction while allowing the rest of the content to continue. Prompt controls stop a matching request before the AI service processes it.

Mask sensitive content

Replace protected values in the prompt or response fields available through the AI service integration.

Block the prompt

Stop a request when its content violates a security rule, then record the event for review.

Protect the AI Services Your Teams Use

DataSunrise applies the same sensitive-data policy model while working with the fields and traffic format exposed by each AI service.

AI serviceAvailable controls
OpenAI and ChatGPTBlock risky prompts and mask sensitive response content
Amazon BedrockBlock prompts and mask sensitive request or response content
Azure OpenAI and Azure AIBlock risky prompts and mask sensitive response content
Anthropic ClaudeBlock risky prompts and mask sensitive Claude fields
Google GeminiInspect sensitive data, block risky prompts, and mask protected content

Define What Counts as Sensitive

Information Types tell DataSunrise what to look for. Teams can start with built-in definitions, add custom patterns and dictionaries, or tune the attributes that identify data specific to the business.

The same definition can support audit, masking, and security rules, so teams do not have to describe the same protected data again for every policy.

Review What the Policy Did

Dynamic Masking Events show when a rule replaced sensitive content. Security Events show prompts stopped by a security rule. Each record gives teams the policy, AI service, available identity context, and action needed to understand what happened.

Generative AI Activity Monitoring adds the surrounding interaction history for investigation.

FAQ

Frequently Asked Questions

How is this different from Generative AI Activity Monitoring?

Activity Monitoring records AI interactions for investigation. Data Masking and Prompt Controls can act on the interaction by replacing sensitive content or stopping a matching prompt.

Is this the same as AI-Assisted Data Masking?

No. This product protects traffic sent to Generative AI services. AI-Assisted Data Masking uses a locally configured model to generate replacement values for DataSunrise masking workflows.

Can DataSunrise block a prompt?

Yes. A security rule can block a matching prompt and record the event for review.

Can DataSunrise mask both prompts and responses?

The available direction depends on the fields exposed by the AI service. The AI services tab above shows the controls available for each integration.

See how DataSunrise works with your technology stack

View Integration Examples