Privedge
Dashboard
Compliance · Legal

Use AI with real data
without breaking the law.

Privedge intercepts personal data before your prompt leaves for OpenAI. Compliance stops being a months-long project and becomes a one-line code change.

HIPAA Ready
GDPR Ready
PCI DSS Ready
CCPA/CPRA Ready
LGPD Ready
EU AI Act Ready
ISO 27001 Inherited
SOC 2 Roadmap
The problem

Every prompt to OpenAI is an international
data transfer

When your app sends "Patient John Doe, SSN 123-45-6789, has a diagnosis of…" to a model in the US, you just moved personal data outside the EU in plaintext. That triggers legal obligations almost nobody handles well.

They cross borders

GDPR (Art. 44-50) restricts the export of personal data to third countries. After Schrems II, contracts alone are not enough: they require supplementary technical measures.

Plaintext

The prompt travels readable. A third party —the AI provider or an attacker— can read it, store it, or use it to train. No control over where that data "resides".

Expensive paperwork

DPA with the provider, SCCs, Transfer Impact Assessment, DPIA, records of processing… Months of legal work before the first call.

Regulatory analysis

The laws, the real articles,
and how Privedge solves them

We cover the regulations that matter. Full article-by-article mapping available in the compliance brief.

HIPAA GDPR PCI DSS CCPA / CPRA LGPD ISO 27001 SOC 2 EU AI Act EHDS DORA
Download compliance brief PDF · HIPAA · GDPR · PCI DSS · ISO 27001 + 6 more
GDPR Art. 17 — Right to Erasure

The "right to be forgotten" that satisfies itself

The hardest GDPR challenge with AI: how do you delete a user from a model trained on their data? With Privedge, that problem never exists.

"Your users can't be un-forgotten from an AI model that never learned their data. Privedge satisfies Art. 17 by construction."

Questions we eliminate

The questions your DPO or lawyer will ask

Without Privedge they have no clear answer. With Privedge, almost all of them stop applying.

Is OpenAI training on our customers' data?
Irrelevant. OpenAI never receives personal data — only anonymous tokens. There is no real data that could enter any training.
What if OpenAI gets hacked?
A breach at the AI provider does not expose your customers' personal data. The GDPR Art. 33/34 notification obligation is not triggered because there was no personal data breach.
Can we use AI with medical records, legal files, or HR data?
Without Privedge the answer is "probably not". With Privedge, yes — that data is anonymized before leaving the node, or never leaves at all (Edge mode).
How do we prove it in an audit?
Privedge's dashboard is the audit log: what PII was detected, what strategy was applied, what node and what latency, for every request. Exportable.
Isn't OpenAI Enterprise with zero retention enough?
Zero retention means they don't keep logs afterward. But the data passed through their servers and their model processed it. Privedge makes the argument no provider can: the data never left your infrastructure.
Isn't Privedge just another intermediary that sees my data?
No. The proxy is a Cloudflare Worker you can self-host in your own account, and the code is MIT. In cloud mode it processes in memory and writes no prompt content to disk.
The return

What paperwork, costs, and headaches we eliminate

The client doesn't hire us to "protect data". They hire us to be able to use AI without spending three months with a lawyer first.

Paperwork / effortWithout PrivedgeWith Privedge
DPA / BAA with the AI providerMandatory negotiationNot needed — receives no PII
SCCs (Standard Contractual Clauses)Mandatory EU→USEliminated — no personal data
Transfer Impact Assessment (Schrems II)Formal risk analysisTrivial or not applicable
DPIA (Art. 35 GDPR)20-60h of senior staffRisk reduced to low category
EU AI Act — safeguards documentationHigh-risk technical fileDetection logs = the evidence
GDPR/AI specialist lawyer€5,000 - €20,000 / rolloutIncluded in the architecture
Audit evidence (ISO/SOC 2)Build logging toolingAudit dashboard included
Time-to-compliance3-6 months< 1 week of integration

Build vs buy: real 3-year cost

The DIY "savings" vanish the moment you add maintenance, infra, and risk.

ItemBuild and maintain (DIY)Privedge Pro
Initial build€15,000 - €50,000€0
Senior dev maintenance (~0.3 FTE)€15,000 - €30,000 / yearIncluded
Regulatory updates (lawyer)€5,000 - €10,000 / yearIncluded
Edge infra (NER hosting, multi-region)Variable, growingIncluded
Legal liability100% yoursShared (processor, Art. 28)
3-year total€80,000 - €150,000+≈ €1,800

Nobody builds their own Stripe to save on the fee,
nor their own power plant to avoid the electric bill.

Compliance is dynamic

Regulations shift. So does Privedge.

Compliance is never a finished project: regulations, data and models keep changing. We keep your privacy layer current with every shift — like a legal advisor, but at the level of your technical infrastructure.

Laws change

Schrems II killed the Privacy Shield overnight.

"Sensitive data" grows

New formats, languages and categories every year.

Every model differs

Different formats, limits and behavior.

Adapting never ends

And that's exactly what you delegate to us.

The technical side

How does the architecture make it impossible?

All this legal coverage rests on one technical fact: PII is intercepted at the edge before it leaves. See the flow, the two modes, and the infrastructure behind it.

See the architecture →

Notice: this document is informational material, not legal advice. The regulatory references are indicative and reflect the regulatory state known as of 2026. Specific compliance depends on the implementation, the use case, and the review of your legal advisor and DPO. Privedge is a technical measure that facilitates compliance; it does not guarantee it on its own.