Feature
Data Redaction
Remove PII, PCI, and PHI from prompts, responses, or both at the gateway. Keep a record that the rule ran, without storing the raw values.
Which entities were filtered and whether the prompt, response, or both were covered.
Scope
Prompt + response
Data
PII + PCI + PHI
Review
Events
Input
Card number
Redacted before provider request.
Output
Address
Filtered before the app receives the response.
Owner
Support key
Rule applied to this key's requests, whether a team key or personal key.
New capabilities
What your team gains with Concentrate
Strip PII before it leaves
Remove selected sensitive entities (names, emails, card numbers, health identifiers) from the prompt before the request ever reaches a model provider.
Filter what comes back
Redact sensitive fields from responses before they return to the app, so a model can't surface data into a UI or log that shouldn't have it.
Prove it ran
Keep a record that redaction fired on a request without storing the raw sensitive values, so your security team gets evidence instead of a promise.
Who Concentrate is designed for
How gateway-level redaction keeps sensitive data out of model traffic
Data redaction removes sensitive data like PII, PCI, and PHI before it reaches an AI provider, and before a response comes back to your app. Tools like AWS Bedrock Guardrails, Google Cloud DLP, and Microsoft Presidio each protect just one platform, or have to be built into every app by hand. Concentrate handles it as requests pass through, so one rule protects every model you use.
Prompt and response coverage
Rules can run on the prompt, the response, or both, so sensitive data is filtered on the way out to the provider and on the way back to the app.
Applied once, for every app
Redaction lives at the gateway, not in each codebase. New apps inherit the rules instead of each team writing and maintaining their own filtering.
Evidence without exposure
Redaction events record that filtering happened without storing the raw values, giving auditors proof while keeping the sensitive data out of logs.
Pairs with retention controls
Combine redaction with zero data retention so sensitive fields are both removed and routed only to providers that don't retain data.
Feature basics