Controls
AI safety and privacy
Personal information kept out of prompts
In progressCriticalVerified 16 September 2026ST4S AI_G1A, AI_PF8, AI_SF6
What this control means
Kuraplan Shield swaps names, emails, phone numbers, student IDs, dates of birth and addresses for placeholders before any request reaches a model, and puts them back in the reply. Live for accounts that turn it on; default-on rollout to follow.
What we found
Released on 15 September as an opt-in setting. Verified in production logs on a real conversation: the model received placeholders on every step, including the results of its own searches through past chats.
How we verified it
- Local detector (no AI involved) with a 47,000-name list including Māori, Pasifika and modern names, context rules, class-list shapes, and names supplied from structured fields.
- Every model call in the API passes through it, including tool results and retrieved context; replies are restored, including streamed ones.
- 87 automated tests; 100 real-model comparisons on two production models capturing the exact request each provider received: zero personal details reached a provider, answer quality within noise of the unshielded version.
- Report-comment class lists are parsed on our server, never by a model.
Still to do
- Shadow mode for all accounts, then default on.
- Warning and 'names kept private' note under prompt boxes.
- Uploaded documents are read by a vision model at upload time before the shield applies; declared and being addressed.
Evidence (private, draft only): kuraplan-st4s-evidence/07-ai/2026-09-15-pii-shield-evidence.md
Questions about this control: security@kuraplan.com