NeuBird Features · Proxy
PII redacted before it leaves your network.
The NeuBird Proxy is a component you deploy inside your own network. It redacts personally identifiable information from logs, metrics, traces and alerts before anything is sent to NeuBird or to a model, replacing each value with an HMAC token. Personal data never leaves your environment, and investigations can still follow the same person or address across every source.
user=alee@example.comusr_3f9a1c07 ip=10.24.8.17ip_b81e44d2 card=4111 1111 1111 1111card_09c7aa13 msg="checkout failed"HMAC tokens: the same value always gets the same token, and no token can be reversed.For illustration only. The product interface may differ.
How Proxy works
What does the NeuBird Proxy redact?
The Proxy removes PII from every kind of data NeuBird reads: logs, metrics, traces and alerts. Values such as email addresses, IP addresses and card numbers are replaced with tokens before the data leaves your network.
How can redacted data still be investigated?
The Proxy redacts with HMAC, a keyed hash. The same value always produces the same token, so an email address that appears in a log line, a trace and an alert becomes the same token in all three, and NeuBird can correlate them into one investigation. Different values produce different tokens.
A token cannot be reversed to recover the original value. NeuBird and the model can tell that two events involve the same user or the same IP address, but never who or which one.
Can I choose what the Proxy redacts?
Yes. The redaction policy is set per kind of PII, so you decide what is replaced and what stays as written. You can keep names intact, for example, while email addresses and phone numbers are still replaced with tokens. Tune the policy to what your investigations need and what your data rules allow.
How is it deployed?
The Proxy is a fully self-contained, independent deployment that you run and control. Deploy it as a container on Kubernetes or as a standalone service on a VM, inside the network where your data lives.
Where does it sit in the data path?
Your sources send data through the Proxy first. The Proxy redacts it inside your network, and only the redacted data continues to NeuBird and on to the model. Neither ever receives the original values.
How does it fit NeuBird security?
The Proxy adds to controls NeuBird already has. NeuBird keeps zero telemetry storage, runs in your cloud, VPC, on-premises or air-gapped environments, and is SOC 2 Type II certified. Read more on the security page.
FAQ
Common questions
What is the NeuBird Proxy?
The NeuBird Proxy is a self-contained component you deploy in your own network. It replaces PII in logs, metrics, traces and alerts with HMAC tokens before any of that data is sent to NeuBird or to an LLM.
How do I deploy the NeuBird Proxy?
Deploy the NeuBird Proxy as a container on Kubernetes or as a standalone service on a VM, inside your own environment. It is an independent deployment that you run and control.
Can I choose which PII the NeuBird Proxy redacts?
Yes. The NeuBird Proxy redaction policy is configurable per kind of PII. For example, you can keep names intact while redacting contact information such as email addresses and phone numbers.
Can NeuBird still correlate events after redaction?
Yes. The NeuBird Proxy redacts with HMAC, so the same value always becomes the same token. An email address or IP address that appears in several logs, traces and alerts maps to one token everywhere, which lets investigations correlate events without the original value, and a token cannot be reversed.
Does NeuBird or the LLM ever see the original data?
No. With the NeuBird Proxy in place, PII is redacted inside your network, and only redacted data is sent to NeuBird and the model. NeuBird also keeps zero telemetry storage.
NeuBird Proxy
See it on your own stack.
Book a demo and watch NeuBird work across your environment, with every action approved by your team.
