Security and privacy

Protect Australian data before it reaches a model

Practical controls for organisations that handle personal, client and regulated information.

Australian identifiers

Detects Medicare numbers, tax file numbers (TFN), ABNs, driver licence numbers and passport numbers, as well as common identifiers like names, emails, phone numbers and addresses.

Four handling modes

Monitor to observe only. Redact to mask. Tokenise to swap in a reversible placeholder restored on the response. Block to stop the request. Set per policy and per entity type.

Response scanning

The same detection runs on model output, so sensitive data in context or tool results is caught on the way back.

Secrets detection

API keys, tokens, passwords and private key blocks are recognised before they leave your network edge for a third party.

Prompt-injection detection

Instruction-override and prompt-extraction attempts are flagged, then blocked when you enforce.

Key isolation

Provider keys are stored only in the gateway. Applications use revocable gateway keys with their own models, budgets and rate limits, so a leaked app key is not a leaked provider account.

Audit logging

Who used which model under which policy, and what the gateway did. Prompt content logging is configurable, so you can keep sensitive text out of logs.

Microsoft Entra SSO

Administrators sign in with Microsoft Entra, inheriting your conditional access and multi-factor policies.

Data residency controls

Restrict which providers and regions each team can use, so traffic for sensitive work goes only to endpoints you approve. Region availability depends on the provider.

Choose how each risk is handled

Monitor, redact, tokenise or block

Begin in monitor mode to learn what your people actually send. Then tighten policy by data type, team or key.

  • Tokenisation keeps answers useful: the model sees a placeholder, you see the real value
  • Redaction suits data that never needs to come back
  • Block suits identifiers that must never leave

Example (illustrative)

PromptDraft a letter for ABN 51 824 753 556 about TFN 123 456 782.
Sent to the modelDraft a letter for ABN <ABN_1> about TFN <TFN_1>.
Returned to your appOriginal values restored in the reply.

What we do and do not claim

LyfeAI Firewall is a control layer. It helps you enforce policy and see what is happening. It does not by itself make an organisation compliant with the Privacy Act 1988, the Australian Privacy Principles or sector rules, and detection is never perfect.

We make no third-party certification claims on this site. For a security questionnaire or architecture discussion, contact us.

Put a firewall between your people and AI

Request access and we will help you set up your first policy, key and budget.