A mandatory boundary before inference
Varexis is designed to sit on the mandatory path between the application and any external AI provider. If an alternate route can send information without passing through protection policy, the boundary is no longer verifiable.
Detection, transformation and residual scanning
The operation does not stop after identifying a sensitive entity. Varexis applies type- and jurisdiction-aware rules, transforms the content and scans the resulting payload again for residual exposure before allowing it to leave.
Opaque identity without losing relationships
When analysis must recognize that the same person or entity appears repeatedly, stable tokens can preserve that relationship without revealing the original value to the model. Real identity remains separated from inference and rehydration can be governed by distinct permissions.
Fail-closed security behavior
If a required detector, policy or critical dependency cannot execute, the payload is blocked. Protection does not silently degrade to preserve availability at the expense of confidentiality.
Separate permissions for protection and rehydration
Sending protected content and recovering the original value are different capabilities. An architecture can allow a service to use tokenized text without granting authority to recover identities.
Evidence for every operation
Protection decisions can record the applied policy, detectors used, residual-scan result, hashes and non-sensitive metadata. The goal is to demonstrate which control executed for a specific operation.
Technical support for compliance, not certification
GDPR, UK GDPR, HIPAA, Law 25.326 and LGPD depend on role, purpose, legal basis, contracts, retention and human processes. Varexis provides auditable technical controls; it does not replace legal analysis or make an organization “compliant” by itself.