Privacy Guard

Sensitive data,
caught and masked in stream.

Realm Clarity AI finds PII, PHI, and PCI in your logs and redacts it before it reaches your SIEM or a third party. No regex to maintain.

custom_crm.contact · object 44182 Inspecting in stream
object_type contact.custom
source salesforce
card_on_file 4929 4412 2331 3456 •••• •••• •••• 3456 PCI
patient_mrn MRN-88213-4471 •••••••••• PHI
email j.rivera@acme.com ••••••@acme.com PII
sync_status synced
3 sensitive fields masked before this record left the pipeline.
The exposure you can't see

Regulated data hides in logs no one wrote a rule for.

PHI, PII, and PCI slip into security telemetry, then fan out to your SIEM, your data lake, and the MDR or MSSP you pay to watch it. By the time anyone notices, it has already left your control.

Without redaction in stream
Your sources firewall, endpoint, apps
SIEM PHI PII PCI
MDR / MSSP PHI PCI
Data lake PII

Every destination, including vendors you don't control, receives regulated data unmasked.

What Privacy Guard does

Detect it, redact it, and prove it, before it lands

Find sensitive data by what it is

Realm profiles every source at the field level and classifies PII, PHI, and PCI with Realm Clarity AI, catching what a regex was never told to look for.

  • Field-level classification across structured and free text
  • Your full exposure mapped within 48 hours
  • Continuous as new sources and formats appear
Source: custom_crm.contact 5 fields scanned
member_ssn PII
diagnosis_code PHI
card_on_file PCI
session_id Clean
geo_region Clean

Mask it in stream, per destination

Before data reaches a destination, Realm masks the sensitive fields and keeps the rest. The same source is masked for your MSSP and can stay intact for a destination you control. Nothing changes until you approve the rule.

  • Per-destination masking rules
  • Detection value maintained, sensitive values removed
  • Rules stage in pending before they go active
Field: card_pan PCI
4929 4412 2331 3456
masked in stream
•••• •••• •••• 3456
SIEM masked
MDR / MSSP masked
Your lake kept, your call

Show it held, mapped to the rules you answer to

Realm records where sensitive data came from, what was masked, and where it went, then maps it to the frameworks your auditors care about. Audit-ready by default, not a spreadsheet you rebuild each quarter.

  • Every masked field logged and reported
  • Sources of exposure ranked by volume and type
  • Shareable with audit, leadership, or an examiner
Coverage Audit-ready
HIPAA PHI kept out of the SIEM
PCI DSS Cardholder data masked
GDPR Personal data controlled
CCPA Consumer data protected
How it works

Redaction happens in stream

Discover

Realm profiles each source and flags PII, PHI, and PCI at the field level, including data no rule was written for.

Redact

You approve the rules. Realm masks each sensitive field in stream, shaped per destination, before data lands anywhere.

Prove

A report shows what was found, what was masked, and where it went, mapped to HIPAA, PCI, GDPR, and CCPA.

Clarity AI does the sensitive data detection. Your team makes the call.

Realm shows why it flagged each field and masks nothing until you approve the rule.

Learn more about Realm Clarity AI

Any pipeline can move your data.
Only Realm proves the regulated data never left your control.

On your own data, in a report you can share. Others claim they catch sensitive data. Realm shows exactly what was masked, on which source, before it reached your SIEM or your vendors.

Proof, in production

Main Line Health , a multi-hospital health system that has to keep Protected Health Information out of its SIEM and away from its service providers.

48 hrs
to a clear picture of sensitive-data exposure
Zero
regulated fields reaching vendors unmasked
4
frameworks mapped: HIPAA, PCI, GDPR, CCPA

Realm gives us a comprehensive view of what data we're piping where. We have zero confusion about how our data is being leveraged. Aaron Weismann, CISO, Main Line Health

Straight answers

The questions a CISO actually asks

How do you find PII, PHI, and PCI in logs without writing regex?

Realm Privacy Guard uses Realm Clarity AI to identify sensitive data by what it is, not by a pattern you defined in advance, so it catches PHI, PII, and PCI in fields and free text no regex was written for.

Regex only catches the formats you anticipated, and every new field or format is a manual edit. Running on the Realm platform, Privacy Guard classifies each source at the field level automatically.

Does redacting sensitive data break SIEM detections?

No. Realm Privacy Guard masks the sensitive values while preserving the fields your detections rely on, so detection value is maintained.

Rules stage in a pending state so you confirm the impact before anything goes active. Sensitive data leaves, detection value stays.

Where should sensitive data be redacted in a security data pipeline?

Redact it in stream, before data lands. Realm Privacy Guard runs on the Realm platform, upstream of your SIEM, data lake, and any third party, so sensitive data is removed before it reaches any of them.

That is prevention rather than cleanup after ingest, so regulated data never reaches a destination it shouldn't.

Can you mask sensitive data differently for a SIEM versus an MSSP?

Yes. With Realm Privacy Guard , the same source can be masked for your MSSP or MDR and kept intact for a destination you control.

Because the Realm platform sits between your sources and destinations, masking rules are set per destination, so your vendors stop receiving data they should never have.

How do you prove sensitive data was redacted for a HIPAA or PCI audit?

Realm Privacy Guard generates a report showing the sources of sensitive data, what was masked, what was shared, and coverage mapped to HIPAA, PCI, GDPR, and CCPA.

It is produced continuously on your own data across the Realm platform, so it is audit-ready by default.

Pick one source.
We'll prove it on your data in days.

The 7-Day Data Assessment. You pick a source, usually firewall logs. We do everything else, and deliver your reduction, detection integrity, and ROI on your own data in a week.

Start a 7-Day Data Assessment