The Gateway

The Xtainable Gateway

The compliant data layer in front of every EXI.

Sensitive data is salted, hashed, anonymized, and minimized before any model sees it, and every access is logged. Built to pass your security review.

How data flows

Made safe before any EXI sees it.

Raw identifiers never reach the model. The Gateway sits between your systems and your EXIs, and writes every step to an audit trail.

Your systems

  • Raw records
  • PII, PHI, confidential

The Gateway

  • Salt and hash
  • Anonymize
  • Minimize

EXI

  • Works on safe data
  • Never the raw values

Audit trail: every access logged, timestamped, and exportable.

How it works

Four controls, working together.

Salted hashing

Identifiers are salted and hashed before they leave your perimeter. Your EXIs match on hashes, never on the raw values.

Anonymization

PII and PHI are stripped or tokenized, so records are processed without the identities attached.

Data minimization

Each EXI receives only the fields it needs for the task in front of it, and nothing else.

Audit trail

Every access is logged and timestamped, and the full trail exports for review at any time.

Built for your concerns

Designed to support the rules you answer to.

PII

Personal identifiers are hashed and tokenized at the edge, so they are never exposed to the model or stored in the clear.

PHI

Health information is de-identified before processing, designed to support HIPAA-aligned handling on the business side of care.

GDPR

Data minimization, purpose limitation, and an exportable audit trail are designed to support obligations like subject access and erasure.

Company confidential

Confidential inputs stay scoped to your instance. They never train a shared model and never leave your control.

The Gateway is built to support these requirements and to be verified by your team. It supports your compliance review. It does not replace it.

For your security team

Built to be reviewed.

Bring your security and privacy reviewers. Everything the Gateway does is inspectable, from the first hash to the last line of the audit trail.

Request a security review →

What your team can verify

  • The data flow, end to end
  • The salting and hashing scheme
  • De-identification of PII and PHI
  • Field-level minimization, per EXI
  • The complete, exportable audit trail
  • Instance scoping and isolation

Put it in front of your security team.

We will walk them through the Gateway, the data flow, and the audit trail, and answer to your standards.