Kestryl · Security & Data Residency

Your data stays in your environment. That is the starting point.

Kestryl is designed to run inside your environment. It reads data where it already sits, keeps sensitive content away from external model services, and leaves an auditable record of what it does.

PIISCAN 0.6.0 · EVIDENCE DATED 04 SEP 2026

Posture at a glance

Runs where the data already is.

  • Runs whereInside the customer environment, against data already staged there. Connectivity and deployment-specific validation are confirmed during scoping.
  • Data movementDiscovery, OCR, and the locally deployed NER model operate in the deployment environment. Sensitive content is not sent to a public model endpoint for detection.
  • What changesDiscovery does not alter source data. Approved structured remediation is deliberate, and supported document remediation produces a separate clean copy rather than rewriting the original.
  • Original valuesWhen retained, original values are held in a controlled vault or quarantine under separate access. Retention and restoration limitations remain explicit.
  • Audit trailSearch, find, change, refusal, and restore actions are recorded. A chained log makes later alteration detectable.
  • RepeatabilityThe active rules carry a deterministic fingerprint. A changed rule set cannot be mistaken for the one that ran before it.

Change control

Validate before you rehearse; approve before you change.

The rule set is human-readable and version-controllable. A configuration the engine does not understand does not run: it stops and names the line rather than guessing at intent.

01 · Validate

Confirm rules, formats, scope, and the deployment boundary.

02 · Rehearse

Run discovery and review findings without modifying source data.

03 · Review

Inspect findings, refusals, confidence, and the proposed output.

04 · Approve

Authorize the supported remediation action and runtime instruction.

05 · Restore

Use vault restoration only through the key holder and a recorded step.

Boundary we state plainly

Kestryl supports controls; it is not itself a compliance certification or legal determination. PDI works with your security team to place it within the controls and certifications of the environment you run it in.

Vault and limitations

Reversible when you choose it, never invisible.

In vault mode, a key holder can restore retained original values into a database cell or cleansed document copy through a deliberate, evidenced action. Standard masks are permanent. A database file may retain historical pages until compacted, and findings remain sensitive; Kestryl helps govern them but does not make them disappear.

Optional name detection is a report-only heuristic where supplied, not model-backed deterministic remediation. Audio and video handling is limited to metadata or tags where supported, not spoken-content transcription unless explicitly available.

Release evidence

PDI-reported measurements on synthetic data place the 12M-row scan at 6.06 seconds on the stated reference setup, benchmarked 04 SEP 2026. See the whitepaper for the complete benchmark matrix and qualifiers.

RULESET FINGERPRINT · DETERMINISTIC ACROSS ENVIRONMENTS

Review the full posture with our team.

PDI will walk security and privacy stakeholders through deployment, data handling, control mapping, and the release’s supported-format boundaries.