Confidencial Pipeline

Inline protection for the workflows already moving your files.

Sensitive files leave your systems every day unprotected. Pipeline sits inline in the workflows already moving them: scan, apply policy, output a protected version before the file arrives.

API-nativeReal-timeEntity-level precision
Pipeline run · exampleProcessing
File intake
API call, folder watch, or app event
Input
Analysis engine
NLP entity detection · PII / PHI / financial
Scanning
Protection applied
Encrypt · redact · tokenize, per policy
Policy
Protected output
Delivered to folder, app, or AI pipeline
Clean
7
Entities protected
<1s
Per document
See it work

What the file looks like before and after

Pipeline protects exactly the entities that need it. The SSN, the patient ID, the account number. Run it and watch the rest of the document stay fully readable.

1Select source
2Scan
3Protect
Sample files
Initializing scan
0Sensitive entities
found
0 entities detected
Choose an action for each data type. All instances of that type receive the same treatment in a single pass.
Policy summary
Options
Protected
The problem with current tools

DLP blocks the send.
It doesn't protect the file.

Files move constantly: to courts, to partners, into AI systems. Most teams answer with DLP, which flags risky transfers but leaves the content untouched, or manual redaction, which is slow and error-prone. Either way, no protection travels with the file. Once it leaves your environment, the sensitive data inside is readable by whoever receives it.

DLP ALONE

What DLP and manual redaction give you

A blocked send, a warning, or a manual redaction job routed to someone with other priorities. The file stays in plaintext, exactly as exposed as the day it was created.

01File created with PII, PHI, or financial data insideExposed
02DLP fires so the send is blocked or flaggedDelayed
03Manual redaction ticket opened, routed to legal ops47 days
04File sent with a redaction overlay, which is removableStill at risk
WITH PIPELINE

Protection at the moment of movement

The file enters Pipeline, is scanned and protected, and is output before it reaches its destination. No ticket. No manual step. No removable overlay.

File enters Pipeline
API call · folder watch · app event
Scan & apply policy per entity
ENCRYPTREDACTTOKENIZE
Protected file delivered
Format preserved · audit log generated
How Pipeline works

From raw file to protected output

Every file follows the same path whether it came from a drag-and-drop, a folder watch, or an application API call.

1

File enters

Via API call, folder watch, or app event; one file, a batch, or a continuous stream. No upstream changes required.

2

Analysis engine scans

NLP-based detection identifies PII, PHI, financial, and custom entities, each returned with a confidence score.

3

Policy applied per entity

Chose whether it's encrypted, redacted, or tokenized. Different data handled differently in a single pass.

4

Protected output

Placed in a folder, a destination app, or the next stage of an AI pipeline. Format preserved, content protected.

A file · on demand
A folder watch
An application API call
Pipeline
Scan · Protect · Output
ENCRYPTREDACTTOKEN
Protected file
Format preserved · usable
Processing log
Every detection, for audit
Real-time
Before delivery, not after
Capabilities

What makes Pipeline different

Protection becomes available at the entity level, not only the file level. Applied the moment a file moves, so the document stays usable and the sensitive content never travels unprotected.

Protection at movement

Not scheduled. Not retroactive.

Most tools work after the fact with overnight scans and bulk jobs. Pipeline fires the instant a file transitions. Created at 3:00 and emailed at 3:01? It's protected before it sends.

Entity-level precision

The scalpel, not the hammer

Full-file encryption makes documents unusable. Pipeline touches only what policy specifies, such as the SSN in field 4, the salary in row 12. The rest stays readable and workflows aren't broken.

API-native

Drops into any file workflow

No rebuilds, no new tools. Anything that can fire an HTTP call can integrate. Deploys in your cloud or on-prem: Docker, Kubernetes, ECS, or EKS.

Three protection modes

Encrypt, redact, or tokenize

Encryption keeps content accessible to authorized users. Redaction removes values permanently, which means they are court-ready. Tokenization swaps entities for length-matched hashes, recoverable for AI pipelines.

Policy hierarchy

Entity to whole-document granularity

Configurable per profile, from surgical entity-level up to full-document protection on any match. Conditional logic on metadata, file type, or existing Microsoft Purview labels.

Horizontally scalable

Workers scale per service

Key server, analysis engine, and AI Guard workers each scale independently. Batch mode runs in parallel; streaming mode processes large files in chunks, so there is no wait for full upload.

Use cases

Point it at anything that moves files

Four workflows where sensitive data leaves a system without protection applied, and where Pipeline closes the gap inline.

Legal · eDiscovery

Pre-production redaction for eDiscovery. One missed field compromises the case.

Case files must reach court, opposing counsel, or regulators with PII stripped. Paralegals spend days on manual redaction, and overlays can be stripped back off.

With Pipeline

Documents route through the pipeline before production. Every file is scanned, all PII redacted, and a submission-ready set delivered with a full processing log. No manual review, no overlay risk.

AI · data engineering

AI pipeline pre-processing. Governance won't approve raw PII entering the LLM.

Documents with PII or PHI are queued for chunking, embedding, and ingestion into a vector DB or RAG pipeline. The raw data has sensitive content that would enter the model.

With Pipeline

Pipeline sits inline between source and embedding service. Files are tokenized before ingestion, so raw PII is never embedded or retrievable. Workflows get approved; analytical value is preserved.

IT · integration

Application-to-application transfer. Every hop moves data with no inline protection.

Files generated in one internal system must reach a partner portal, a regulator, or a downstream app. Each transfer ships sensitive data with nothing applied at the moment it moves.

With Pipeline

The application triggers Pipeline before a file reaches its endpoint — invisible to the user. The file that arrives has already had its sensitive content encrypted or tokenized. The workflow doesn't change.

Healthcare · claims

Automated claims export to payers. PHI leaves the EHR in nightly batch files.

Scheduled jobs push thousands of claims documents to payers and clearinghouses. Each batch carries PHI in plaintext, and the export job has no protection step built in.

With Pipeline

A folder watch sits on the export staging directory. Every batch file is scanned and protected before it ships — PHI tokenized for the payer's systems, format preserved so downstream processing still runs.

Why teams trust Confidencial

Built for the environments that matter

40+

File types supported, original format preserved

3

Protection modes include encrypt, redact, and tokenize

2026

Data Solution of the Year for Legal, Data Breakthrough Awards

HIPAA Compliant
PCI DSS Compliant
AFWERX STTR Phase II
Customer-controlled keys
Deploys into the stack you already run
REST APIDockerKubernetesAWS ECSAWS EKSS3 / Azure BlobMicrosoft Purview
Questions about Pipeline

What security teams ask us first

We already have DLP. Why do we need Pipeline?

DLP tells you when something moved that shouldn't have. Pipeline protects the file before it moves — so even if it reaches the wrong destination, the sensitive content is inaccessible. DLP is detection; Pipeline is protection. DLP is actually a good reason to add Pipeline: you've already decided this data matters enough to monitor. Now protect it so monitoring isn't the last line of defense.

How is this different from encrypting the whole file?

Full-file encryption makes the document unusable until decryption — anyone with the key sees everything. Pipeline applies selective encryption at the entity level. Only the SSN is protected; the rest of the document stays readable. Authorized users access what they're allowed to see, and AI systems can process the non-sensitive context. That's the difference between a hammer and a scalpel.

What happens with a false positive?

The analysis engine returns a confidence score with every detection. Policies can act only above a confidence threshold, so a low-confidence match doesn't trigger protection automatically. Entity definitions are fully customizable — if a default pattern is too aggressive for your content, it's tunable, and every detection decision is visible in the monitoring view.

How long does integration take?

Pipeline exposes a standard REST API — if your application can make an HTTP call, it can trigger Pipeline. Deployment is Docker or Kubernetes, with configuration files, Helm charts, and Docker Compose files provided. For the simplest use case — a folder watch with drag-and-drop — it's usable the same day.

If we already use Shield, do we need Pipeline too?

Different jobs. Shield scans your data estate on a scheduled or continuous basis, handling what already exists at scale and keeping it encrypted and protected in place. Pipeline handles files at the exact moment they move. A common pairing: Shield holds the authoritative protected version of a document; Pipeline creates a clean copy for external distribution, redacting the sensitive fields so the file can go to a court, a regulator, or a partner while the original stays intact and access-controlled under Shield. Files created between scan runs, documents flowing through an application pipeline, or anything that needs protection at the instant of transfer are Pipeline territory. They cover different moments in the data lifecycle, not the same one.

Get started

Stop sending files before they're protected

Pipeline deploys in your environment in hours, with keys you control. No agents. No re-architecture. Protection at the moment of movement, before any file arrives.

One platform, no gaps with Discover, Shield, Pipeline, Exchange, AI Guard.