Security and privacy

Protect Australian data before it reaches a model

Practical controls for organisations that handle personal, client and regulated information.

Australian and New Zealand identifiers

Detects Medicare numbers, tax file numbers (TFN), ABNs, driver licence numbers and passport numbers, New Zealand IRD, NHI and bank account numbers, dates of birth and card numbers, as well as names, emails, phone numbers and addresses.

Four handling modes

Monitor to observe only. Redact to mask. Tokenise to swap in a reversible placeholder restored on the response. Block to stop the request. Set per policy and per entity type.

Response scanning

The same detection runs on model output, so sensitive data in context or tool results is caught on the way back.

Secrets detection

API keys, tokens, passwords and private key blocks are recognised before they leave your network edge for a third party.

Prompt-injection detection

Instruction-override and prompt-extraction attempts are flagged, then blocked when you enforce.

Key isolation

Provider keys are stored only in the gateway. Applications use revocable gateway keys with their own models, budgets and rate limits, so a leaked app key is not a leaked provider account.

Audit logging

Who used which model under which policy, and what the gateway did. Administrative changes are written to an append-only, tamper-evident audit log visible to staff. Prompt content logging is configurable.

Sign-in and access

Customers sign in at the customer login with the account their organisation administrator invites (email and password) and see only their own organisation. Microsoft Entra single sign-on is used for the platform's staff console.

Australian-hosted gateway; you choose where inference runs

The gateway and its data are hosted in Australia, and prompts and responses are not stored by default. AI processing happens at whichever provider you choose. OpenAI is the default and is offshore, unless you connect an Australian-hosted provider or model.

Choose how each risk is handled

Monitor, redact, tokenise or block

Begin in monitor mode to learn what your people actually send. Then tighten policy by data type, team or key.

  • Tokenisation keeps answers useful: the model sees a placeholder, you see the real value
  • Redaction suits data that never needs to come back
  • Block suits identifiers that must never leave

Example (illustrative)

PromptDraft a letter for ABN 51 824 753 556 about TFN 123 456 782.
Sent to the modelDraft a letter for ABN <ABN_1> about TFN <TFN_1>.
Returned to your appOriginal values restored in the reply.

What we do and do not claim

Tokard is a control layer. It helps you enforce policy and see what is happening. It does not by itself make an organisation compliant with the Privacy Act 1988, the Australian Privacy Principles, New Zealand privacy law or sector rules, and detection is never perfect.

We rely on sound security practices and make no third-party certification claims on this site. Where audio is sent for transcription, the audio itself reaches your chosen provider unredacted; only the returned transcript is scanned. For a security questionnaire or architecture discussion, contact us.

Keep every AI interaction within bounds

Request access and we will help you set up your first policy, key and budget.