Kestryl · Security & Data Residency
Your data never leaves. That is the starting point, not a feature.
Kestryl is designed to run entirely inside your own environment. It reads your data where it already sits, makes no outbound calls, and leaves an auditable record of everything it does.
Posture at a glance
Built for a controlled local deployment, not an external model queue.
The PIIScan engine, OCR, and the NER model run locally inside the customer-controlled deployment environment. Sensitive content is not sent to a public model endpoint for detection.
Inside your environment, against data already staged there. No component reaches the public internet during a scan.
None outbound. Kestryl does not transmit records, findings, or documents to any external service — including for optical recognition, which runs locally.
Preserved before masking in a single controlled quarantine store under separate access from the working data. They never appear in any report or extract.
Every run and every masking action is written to a chained log. Altering one entry invalidates those after it, so tampering is detectable.
The rule set carries a deterministic fingerprint. Re-running the same rules yields the same fingerprint on any machine — the basis for defensible, repeatable evidence.
Permissively licensed open-source components only. No restrictive copyleft in the deployed engine.
Change control
OCR, localized NER, and detection rules remain transparent and controlled.
The complete rule set is human-readable and version-controllable. Any change to a rule changes the fingerprint, so a modified configuration can never be mistaken for the one that ran before it. A configuration the engine does not understand does not run — it stops and names the line, because a system that can mask data should never guess at intent.
Scope we state plainly
Kestryl is a data-processing engine deployed inside your environment; it inherits the certifications and controls of the environment you run it in rather than carrying its own external attestations. PDI works with your security team to place it within your existing compliance boundary. Specific control mappings are provided during scoping.
RULESET SIGNATURE · 09a08673aa6e9ccb · deterministic across environments
Review the full posture with our team.
PDI will walk your security and privacy stakeholders through deployment, data handling, and control mapping against your environment.