AI data security
Give agents the work.Not the secrets.
When an agent transcript leaks, your customer data doesn't.
Custodian lets AI work with sensitive customer records without seeing the real values. Agents use tokens instead; real data is substituted only at the final step, on a machine you control.
Decide what stays private
Choose the fields agents should never see.
Give only the access needed
Control access field by field, for each agent.
Reveal values only when needed
Real data is restored only at the final step, on a machine you control.
See every access
Know who accessed what, when, and under which permission.
Agents don't need every secret to do the job
Filling forms, drafting letters, reconciling accounts — the agent needs the record, not the sensitive values inside it.
- 01
Store customer records safely
Custodian stores structured customer data. Sensitive fields are encrypted before they leave your machine.
- 02
Agents work with stand-ins
Agents see tokens instead of sensitive values, and use them throughout the workflow.
- 03
Real values appear only at the end
On a machine you control and away from LLMs, tokens are resolved to real values only when the final action needs them.
Built for agents that run unattended
No one needs to sit there approving every step. You set the rules once; Custodian enforces them and records every access.
Access only what's needed
Give each agent access to specific fields — and nothing more.
Rules prompts can't override
Access is enforced by Custodian, not by instructions inside the AI conversation.
Find records without exposing values
Look up exact matches without the server holding the original sensitive value.
Keys stay with you
The ability to unlock protected data stays on machines you control.
Every access is recorded
See who accessed which record and field, when, and under which permission.
Check your vault at a glance
See key status, devices, permissions and warnings in one health check.
“Even if someone walked off with our whole database, they would have nothing they could read without one of our own devices.”
Who uses what
Two ways in. One set of rules.
For data owners
Use the command line to set up the vault, define sensitive fields, manage access, review activity and restore values when needed.
For AI agents
Agents connect through Custodian's MCP interface and receive only the access you have explicitly allowed.
What Custodian isn't
Custodian deliberately balances strong data protection with practical, usable workflows.
- No web interface. Custodian is a command-line tool and an MCP server.
- Agents access data via MCP, and there is no server-side decryption. That is the design, not a limitation to work around.
- No automatic detection of sensitive data. You declare what is sensitive during the schema design phase.
- No redaction of secrets inside prose. Custodian works with structured fields, and finding an identity number inside a paragraph is a different problem.
Let AI do the work. Keep the secrets out — together.
See how Custodian can let agents work with customer data without giving them the sensitive values behind it.