Data Masking
Agentless discovery finds every sensitive column, then irreversible masking runs against a clone — never your system of record. Audit-first, API-first, a safe realistic copy in minutes.
Real-time data privacy control with agentless discovery, clone-only masking runs, and audit-first automation.
Mask the sensitive data you already have — or generate realistic data you don't. The same audit-first, background-durable engineering runs under both.
Agentless discovery finds every sensitive column, then irreversible masking runs against a clone — never your system of record. Audit-first, API-first, a safe realistic copy in minutes.
Describe a schema in plain language. An autonomous AI agent asks clarifying questions, plans, and generates relationally-consistent data — then iterates in conversation, exports to any format, and writes matching documents.
Compliance-ready masking for every major privacy standard
rows masked in a single run, in under a minute
connector types: Postgres, MySQL, CSV, JSON & growing
of runs execute against a clone — zero writes to source
reversible mappings stored, ever, by design
The same engine that powers Wrapar — a scan sweeps each row, and every sensitive cell flips from its original value to its irreversible, deterministic replacement.
No agents to install. No copies of production sitting around. Every action is one API call away from your CI pipeline. This is the real product below — not a mockup.
Point Wrapar at Postgres, MySQL, CSV, or JSON — through an SSH tunnel if your database lives in a private network. Test the connection with one click.
Schema introspection plus pattern sampling classifies each column — names, emails, national IDs — with a confidence level and a suggested masking strategy, ready to review.
Discovery output becomes a YAML rule set you can review, edit, and re-generate. Every revision is kept, so you always know exactly what a run applied.
A masking session clones the connection's data first; runs only ever touch that clone. Close the tab — durable background workers keep going and email you the result.
Runs across every project you can access, logged immutably — who ran what, against which clone, and when. Re-identification is admin-gated and always recorded.
Six strategies ship in the box — or plug in your own generator, including local LLM-backed ones. Formats stay valid, relations stay intact.
Masking always runs against a clone, never the connection you registered. Your system of record is structurally unreachable from a run.
Close the tab, redeploy the worker — runs keep going and notify you by email with a download link the moment they finish.
Every resource is project-scoped and enforced at the query layer — not just hidden in the UI. Cross-project access returns a clean 404.
A per-project persistent secret lets you recover a specific flagged row from the real source — admin-gated, unconditionally audit-logged.
Every button in the UI is one curl call away. Build masking into CI, not into a click-through ritual.
Masking runs operate exclusively on a cloned session. The original connection has no write path from a run, ever.
Standard masking uses an ephemeral, per-run secret that is never persisted in a reconstructable form.
Runs, audits, and re-identification attempts — including zero-match attempts — are recorded immutably, no exceptions.
Connect your first database and see a generated rule set in under five minutes.