Raw text arrives with names, IDs, phone numbers, or account references still intact.
"Draft apology for order delay. Customer: Khalid Al-Rashid, Phone: +966501234567"
"Summarize patient discharge. Patient: Noura Al-Qahtani, ID: 1087654321"
"Flag suspicious transfer. Account holder: Majid Al-Dossari, IBAN: SA9810000041234567890123"
"Translate performance review. Employee: Sara Al-Amri, Badge: EMP-04419"
"Optimize delivery route. Driver: Nawaf Al-Harbi, Phone: +966542113344"
Personal data is identified, moved into the vault, and replaced with typed placeholders the model can safely process.
"Draft apology for order delay. Customer: [[PERSON:01]], Phone: [[PHONE:01]]""Summarize patient discharge. Patient: [[PERSON:01]], ID: [[NATIONAL_ID:01]]""Flag suspicious transfer. Account holder: [[PERSON:01]], IBAN: [[IBAN:01]]""Translate performance review. Employee: [[PERSON:01]], Badge: [[EMPLOYEE_ID:01]]""Optimize delivery route. Driver: [[PERSON:01]], Phone: [[PHONE:01]]"Only the prepared payload reaches the selected model. Provider and residency choices stay bound to route policy.
Tokens are rehydrated from the vault and the user sees a natural response with the original context restored.
"Dear Khalid Al-Rashid, we sincerely apologize for the delay in your order...""Patient Noura Al-Qahtani is cleared for discharge with follow-up in 14 days...""Transaction by Majid Al-Dossari flagged for analyst review...""Sara Al-Amri exceeded Q3 targets by 18%. Recommend promotion review...""Route optimized for Nawaf Al-Harbi. Three stops consolidated, ETA reduced."| Provider / Network | Available Lanes | Flagship Selection |
|---|---|---|
| OpenAI |
Green Lane (Global)
|
Latest GPT family Reasoning Multimodal + live catalog |
| Anthropic |
Green Lane (Global)
|
Claude family Long-context Writing + live catalog |
|
Green Lane (Global)
|
Gemini family Multimodal Fast + live catalog | |
| STC SambaNova Configured in-Kingdom path |
Amber Lane (Pseudonymous)
Red Lane (Raw Data)
|
Amber Red Configured in-Kingdom path + integrated path |
| Groq Configured in-Kingdom path |
Amber Lane (Pseudonymous)
Red Lane (Raw Data)
|
Amber Red Low-latency + live catalog |
Amber/red provider residency depends on operator-configured provider endpoints. DataSitr does not independently verify provider data residency.
5736 tests in the current verified snapshot · Saudi-hosted privacy routing
Live posture, dated proof limits, and benchmark snapshots are published on the trust, status, and benchmark pages.
Anonymized. Sent to global AI.
PII replaced with typed placeholders before external processing.
Pseudonymized. Routed to operator-configured in-Kingdom AI paths.
Linkable tokens stay on Saudi-hosted infrastructure.
Raw. Routed only to configured in-Kingdom paths or blocked.
Sensitive data is kept on Saudi-hosted infrastructure when the configured provider path is in-Kingdom.