Solutions / AI & ML Engineering
AI / ML Platform

Stop personal data leaking into foreign model APIs.

The headline AI-specific risk under Indian law is personal data leaving the country inside a prompt to a foreign large language model. Praman detects personal data in AI pipelines and raises a prominent verdict whenever it egresses to a foreign model API — so platform teams catch the leak before it becomes a cross-border transfer violation.

The problems we hear from ai / ml platform teams

  • ▹PII silently included in prompts to foreign LLM endpoints
  • ▹No inventory of which pipelines touch personal data
  • ▹Classifier tools that themselves ship data to foreign APIs — defeating the purpose
  • ▹AI egress invisible to the compliance team

What Praman does for you

PII-in-prompt detection

An in-region classifier detects Indian identifiers — Aadhaar (with Verhoeff checksum), PAN, phone, email — in pipeline text and schemas.

Foreign-model-API verdicts

Personal data egressing to a foreign model API gets a block-recommended verdict, a reason and an audit event.

Swappable, never foreign

The classifier sits behind an interface so a self-hosted model can replace the regex layer — without ever calling a foreign API.

Pipeline registry

Register AI pipelines and model endpoints as first-class assets with their own data flows.

Obligations you’ll see covered

Each maps to an automated check with its statutory citation and tamper-evident evidence.

DPDP-CROSSBORDERCross-border transfer of personal dataDPDP-PURPOSEPurpose limitationDPDP-SECURITYSecurity safeguards

Frequently asked

Does the classifier send data anywhere?

No. The MVP classifier is pure in-region regex/validators. Any future model-based classifier must remain self-hosted or in-region — that constraint is built into the design.

What counts as a foreign model API?

Endpoints whose controller resolves to a foreign large-language-model provider. Praman ships a labelled classification dataset of common ones and you can extend it.