Glossary

Short, plain-language definitions of the terms used across this site, each linked to where it is explained in full.

PII (Personally Identifiable Information)
Any data that could identify a specific person: names, emails, phone numbers, national ID numbers and similar. This is what the deterministic and semantic tiers are built to find and mask before it reaches a model provider.
ZDR (Zero Data Retention)
The claim that no code path in the gateway writes raw input, masked output or the mapping table to disk, a log or a database. See the Security page for the verified claims and their stated limits.
Deterministic tier
The detection layer that matches identifiers with a fixed, checksummable shape: emails, phone numbers, national IDs, payment cards, IBANs and credentials. It runs first, on every request, in the gateway and in the browser extension.
Semantic tier
The detection layer that finds free-text entities without a fixed shape: people's names, organisations and places. It uses a machine-learning model and is evaluated across six languages.
Surrogate (placeholder tag)
The tag substituted for a detected value before a request leaves the gateway. Tags are derived from a keyed hash scoped to the conversation, so the same value gets the same tag within one conversation without being reversible to the original value.
Reconstitution
Restoring the original values in a model's reply by swapping surrogate tags back for what they replaced, as the response streams back through the gateway.
Mapping table
The in-memory table linking each surrogate tag to the original value for the life of one request. It is deleted from memory when the stream closes.
Attestation
The X-zer0pii-Attestation response header: an Ed25519 signature over the hashes of the raw and masked request. It proves that whoever holds the signing key produced that exact pair of hashes; it does not by itself prove anything was deleted.
Merkle receipt
A proof that one specific attestation sits at one specific position in an append-only log, without needing the whole log to verify it.
Signed tree head
A signature over the (root, size, timestamp) of the Merkle log at a point in time. Checking a receipt against the root and size taken from a signed tree head, rather than supplied separately, closes a size-aliasing gap that a bare inclusion proof has on its own.
BYOK (Bring Your Own Key)
Requests are forwarded to the model provider using the customer's own provider API key, never a shared or pooled key belonging to zer0pii.
Fail-open
When a check cannot complete in time or errors out, the request proceeds anyway rather than being blocked. The semantic tier fails open to the deterministic tier if it exceeds its latency budget.
Fail-closed
The opposite of fail-open: when a check cannot complete, the request is blocked rather than allowed through. Prompt-injection detection can be configured to fail closed (block mode) instead of the default flag mode.
SIEM (Security Information and Event Management)
A customer's own log-aggregation system. zer0pii can forward metadata, such as event IDs, labels and counts, never text, to a customer-configured SIEM webhook or S3 export bucket.
SCIM (System for Cross-domain Identity Management)
A standard protocol for a customer's identity provider to automatically provision and deprovision member accounts in the console.
Prompt injection
An attempt to manipulate a model's behaviour through crafted text in a request. zer0pii checks every request against a corpus of known injection and jailbreak phrases, independently of PII redaction.
Tokenization
The general industry term for replacing a sensitive value with a non-sensitive placeholder. zer0pii's specific mechanism for this is the surrogate tag described above.
Gateway
The service that sits between a customer's tools and the model provider, speaking the OpenAI, Anthropic and Gemini request formats, running detection and masking on every request.
Data plane
The part of the system that handles request and response text: the gateway and the browser extension's on-device detection.
Control plane
The part of the system that manages accounts, keys, policy and configuration: the console and its backing services, separate from the data plane that touches request text.