100% Sensitive Data Discovery. Irreversible Masking. Zero Leaks.

Real-time data privacy control with agentless discovery, clone-only masking runs, and audit-first automation.

01 Connect
02 Discover
03 Mask
04 Run
05 Audit
Wrapar masking engine
Agentless
Discovery
100%
Irreversible
Audit
First
wrapar.ai Mask in place. Audit everywhere.

Compliance-ready masking for every major privacy standard

HIPAAHITECHGDPRUK GDPRDPAPIPEDAPHIPAHIAAPPDPDPABDMABHAEHRPDPAAPPIPIPAPIPLLGPDPOPIAFADPPDPLPrivacy Act 2020 HIPAAHITECHGDPRUK GDPRDPAPIPEDAPHIPAHIAAPPDPDPABDMABHAEHRPDPAAPPIPIPAPIPLLGPDPOPIAFADPPDPLPrivacy Act 2020
0

rows masked in a single run, in under a minute

0

connector types: Postgres, MySQL, CSV, JSON & growing

0

of runs execute against a clone — zero writes to source

0

reversible mappings stored, ever, by design

Watch real values transition into masked ones

The same engine that powers Wrapar — a scan sweeps each row, and every sensitive cell flips from its original value to its irreversible, deterministic replacement.

patients.csv — masking_session_8841
NameEmailSSN
Whitfield, A.Doyle, M. a.whitfield@acmehealth.ioq.larkin@acmehealth.io 021-44-9981884-61-2207
Bryne, K.Solano, R. k.bryne@acmehealth.ior.solano@acmehealth.io 558-12-3047203-95-4418
Odusanya, T.Petrakis, N. t.odusanya@acmehealth.ion.petrakis@acmehealth.io 390-77-6614517-08-3392
Mercer, J.Halvorsen, D. j.mercer@acmehealth.iod.halvorsen@acmehealth.io 104-29-5582729-43-1065
Castellano, R.Ferreira, S. r.castellano@acmehealth.ios.ferreira@acmehealth.io 672-03-8847346-87-2951

Five steps from raw data to a safe, realistic clone

No agents to install. No copies of production sitting around. Every action is one API call away from your CI pipeline. This is the real product below — not a mockup.

1

Register the sources you already have

Point Wrapar at Postgres, MySQL, CSV, or JSON — through an SSH tunnel if your database lives in a private network. Test the connection with one click.

  • Postgres · MySQL · CSV · JSON connectors
  • Credentials encrypted at rest, never echoed back
  • File sources and databases side by side, per project
data.wrapar.ai · connections
Wrapar connections page listing CSV and PostgreSQL sources registered for a project
2

Find every sensitive column automatically

Schema introspection plus pattern sampling classifies each column — names, emails, national IDs — with a confidence level and a suggested masking strategy, ready to review.

  • Classification with high / medium confidence per column
  • Primary and foreign keys detected and respected
  • One click from findings to a generated rule set
data.wrapar.ai · discovery
Wrapar discovery results classifying columns with confidence levels and suggested masking strategies
3

Turn findings into versioned rule sets

Discovery output becomes a YAML rule set you can review, edit, and re-generate. Every revision is kept, so you always know exactly what a run applied.

  • Format-preserving, deterministic, and seed-file strategies
  • Foreign keys stay consistent across tables
  • Revisioned YAML — reviewable in a pull request
data.wrapar.ai · rule sets
Wrapar rule sets page listing versioned YAML rule sets per source connection
4

Every run targets a clone, never the source

A masking session clones the connection's data first; runs only ever touch that clone. Close the tab — durable background workers keep going and email you the result.

  • Clone-only sessions — zero writes to your source
  • Durable background runs that survive redeploys
  • Email notification with a download link on completion
data.wrapar.ai · masking sessions
Wrapar masking sessions page with cloned sessions in Ready state
5

One dashboard, every run accounted for

Runs across every project you can access, logged immutably — who ran what, against which clone, and when. Re-identification is admin-gated and always recorded.

  • Immutable run history across projects
  • Org · department · project RBAC, enforced at the query layer
  • Admin-gated, fully traceable re-identification
data.wrapar.ai · dashboard
Wrapar dashboard summarizing projects, total runs, and recent masking runs

Engineering-grade masking, not a checkbox feature

Plugin masking strategies

Six strategies ship in the box — or plug in your own generator, including local LLM-backed ones. Formats stay valid, relations stay intact.

Session-based cloning

Masking always runs against a clone, never the connection you registered. Your system of record is structurally unreachable from a run.

Durable background runs

Close the tab, redeploy the worker — runs keep going and notify you by email with a download link the moment they finish.

Org · department · project RBAC

Every resource is project-scoped and enforced at the query layer — not just hidden in the UI. Cross-project access returns a clean 404.

Controlled re-identification

A per-project persistent secret lets you recover a specific flagged row from the real source — admin-gated, unconditionally audit-logged.

API-first, always

Every button in the UI is one curl call away. Build masking into CI, not into a click-through ritual.

Built on three non-negotiables

01 · Never touch the source

Masking runs operate exclusively on a cloned session. The original connection has no write path from a run, ever.

02 · Irreversible by default

Standard masking uses an ephemeral, per-run secret that is never persisted in a reconstructable form.

03 · Every action is logged

Runs, audits, and re-identification attempts — including zero-match attempts — are recorded immutably, no exceptions.

Stop shipping real data to staging.

Connect your first database and see a generated rule set in under five minutes.