Seven controls, seven sources of guidance — one map
UK guidance on AI and confidential data converges on a small set of expectations: keep identifiable data out of public tools, minimise what providers receive, stay accountable, and keep evidence. This table maps each NeutralAI control to the guidance lines it addresses. Lines are paraphrased for brevity — the verbatim quotes and source links live on each guidance page.
Mask before send
PII detected and replaced in the browser before the prompt or upload leaves the firm.
Reversible vault (15-minute TTL)
Masked tokens restore locally after the response; encrypted vault entries expire in minutes.
Audit trail
Category-level masking events logged with policy and timestamp — no raw PII in the log.
Whitelist & tenant policy
Firm-approved terms and per-tenant masking policy applied consistently across every AI tool.
BYOK
Growth/Enterprise tenants use their own LLM provider keys and contracts.
On-prem / private deployment
The gateway can run inside the firm’s own environment or VPC.
SSO & access control
OIDC/SAML SSO, MFA posture, and role-based access for admin surfaces.