Skip to content
Governance

Central policies for every AI workspace

FastPII gives security teams one Policy Engine to decide what should happen when the platform detects sensitive data, with workspace-level isolation and scope-based API key control built in.

Policy-first control plane

Match policies against entity type, country, provider, model, workspace, confidence, and sensitivity, then enforce the right action across live traffic.

Seven actions

Choose the exact response every time

The Policy Engine can pass traffic through, transform it, stop it, or route it for review depending on what the request contains.

ALLOW

WARN

MASK

BLOCK

ESCALATE

LOG

QUARANTINE

Policy flow

How governance decisions move through the platform

Every request passes through detection, policy matching, action enforcement, and audit logging in a consistent sequence.

Step 1

Detect

Sensitive data is identified in the request content.

Step 2

Match conditions

Policy conditions are evaluated against entity type, country, provider, and more.

Step 3

Enforce action

The chosen action is applied: allow, warn, mask, block, escalate, log, or quarantine.

Step 4

Audit

The full decision trail is recorded for review and export.

Conditions and controls

Governance that maps to real operating boundaries

FastPII policies can track who is sending traffic, where it is going, and what level of transformation or logging should happen next.

Policy conditions

entity_type · country · provider · model · workspace · confidence · sensitivity

Workspace isolation

Separate workspaces can keep policies, provider routing, audit streams, and review ownership isolated from one another.

API key scoping

Scope-based API keys let teams limit what a key can do without requiring broad access to every workspace or provider path.

Data retention

Set retention rules around audit events and workspace data so the governance layer matches your organisation’s review horizon and operational needs.

Consistent enforcement

The same governance model can drive SDK calls, REST API requests, secure chat sessions, and gateway-routed model traffic.

Roll out governance

Move policy decisions out of application code

Central policy management lets security teams change the decision layer once and apply it everywhere FastPII protects AI traffic.