The pressure is real
Staff already want to ask plain-English questions of the systems they run, instead of exporting spreadsheets and pivoting by hand.
Soreg is the gate between your regulated records and the AI that helps your staff. Questions go in. Only masked data ever reaches the model, whichever model you choose. Real identities are revealed to the people you authorize, and every step is written to the log your examiner will ask for.
Runs in your environment · your keys · no PII leaves your tenancy
Authorized staff still see the real names, revealed by the gateway after the model answers, only for the roles you permit, always logged.
soreg: the latticed screen that marks the line you may not cross.
Today you're forced to choose between the two. Pasting regulated data into a chatbot is a finding waiting to happen, so the productivity stays on the table.
Staff already want to ask plain-English questions of the systems they run, instead of exporting spreadsheets and pivoting by hand.
A name, an SSN, an account or medical number reaching a third-party model is exactly the kind of nonpublic data your controls exist to protect.
Whatever privacy, security, or financial-services rules you answer to, "we think it's fine" isn't an answer. You need to show what the model saw, and prove no regulated data was in it.
Soreg doesn't trust the AI; it constrains it. The model only ever proposes; the gateway decides what runs and what comes back.
Staff type a question. No SQL, no exports, no copy-paste into someone else's chatbot.
Soreg validates every query before it runs: read-only, masked views only, nothing else executes. A query that reaches for anything it shouldn't is refused, not run.
The model works over hashed keys and masked columns. It never receives a name, an SSN, or an account number, and you can read the exact payload we send it.
The gateway re-identifies results server-side (only for the roles you permit, after the model is done) and writes who asked, what the model saw, and what was revealed to an append-only log.
The gate works field by field. You decide, column by column, what any model is ever allowed to see, so the same control that hides a customer's SSN from the AI also hides your pricing, your margins, and your client list from it.
Compliance is the reason you start.
Confidentiality is the reason you keep it.
Soreg sits between your data and the model, not inside any one vendor. The protection comes from the gate, not the AI, so which model answers the question is never a security decision.
model: your choice (masked-only) system: schema + safe values question: "who's transferring this month?" subject: Sarah Bennett 9deedc48…0501 ssn: 412-55-7705 withheld account: •••• 4021 withheld
Most "AI governance" asks you to trust a promise. Soreg shows you the literal request that left your environment (captured at the wire, key redacted) so anyone can confirm there's no regulated data in it.
Hand it to your examiner. It isn't a claim. It's the receipt.
The gate is the same for everyone. The evidence pack is tailored to your regulator, a configuration, not a rebuild. We compile the mapping; you hand it to your examiner.
Full control-to-requirement mapping for New York's cybersecurity regulation, with the transparency and audit output as the exhibits.
The same gate, tuned for PHI: minimum-necessary access, audit controls, and an evidence pack mapped to the Security Rule.
GLBA, SOC 2, state privacy laws, or a regulator we haven't met yet. Tell us what you answer to and we compile the package.
Every Soreg control ties back to the letter of the regulation. Follow any framework to its governing text.
The point: the framework is a configuration. Whatever your obligations, the protection underneath is identical; only the paperwork changes.
Pick the framework you answer to and we'll send you a sample Soreg evidence pack built for it: the control-to-requirement mapping, the transparency receipt, and the audit log, in the format you'd hand to a regulator.
Tailored to your framework. A sample pack for the exact regulation you select.
The real artifacts. Control mapping, the request receipt, and an append-only audit log.
No obligation. A short walkthrough offer, only if you want one.
Tell us where to send it and which framework applies.
Mortgage servicers, banks, credit unions, fintech, NPI-heavy systems and staff who'd rather ask than build a report. NYDFS §500 ready today.
Providers, payers, and anyone handling protected health information, as the HIPAA package comes online.
Deliver Soreg to the regulated clients you already serve, with the evidence pack as part of the engagement.
If you're weighing AI against your data obligations, we'd like to show you the gate. Tell us a little about your environment and we'll set up a walkthrough.