Stop personal data leaking into foreign model APIs.
The headline AI-specific risk under Indian law is personal data leaving the country inside a prompt to a foreign large language model. Praman detects personal data in AI pipelines and raises a prominent verdict whenever it egresses to a foreign model API — so platform teams catch the leak before it becomes a cross-border transfer violation.
The problems we hear from ai / ml platform teams
- ▹PII silently included in prompts to foreign LLM endpoints
- ▹No inventory of which pipelines touch personal data
- ▹Classifier tools that themselves ship data to foreign APIs — defeating the purpose
- ▹AI egress invisible to the compliance team
What Praman does for you
PII-in-prompt detection
An in-region classifier detects Indian identifiers — Aadhaar (with Verhoeff checksum), PAN, phone, email — in pipeline text and schemas.
Foreign-model-API verdicts
Personal data egressing to a foreign model API gets a block-recommended verdict, a reason and an audit event.
Swappable, never foreign
The classifier sits behind an interface so a self-hosted model can replace the regex layer — without ever calling a foreign API.
Pipeline registry
Register AI pipelines and model endpoints as first-class assets with their own data flows.
Obligations you’ll see covered
Each maps to an automated check with its statutory citation and tamper-evident evidence.
Frequently asked
Does the classifier send data anywhere?
No. The MVP classifier is pure in-region regex/validators. Any future model-based classifier must remain self-hosted or in-region — that constraint is built into the design.
What counts as a foreign model API?
Endpoints whose controller resolves to a foreign large-language-model provider. Praman ships a labelled classification dataset of common ones and you can extend it.