Announcements

AMAN: Keeping Personal Data Where It Belongs

AMAN, Mizan's PII redaction feature, removes personal data from prompts before they reach a model. Here's how it works, and how well it performs in English and Arabic.

October 1, 20265 min read

AI is now part of everyday work, and almost every prompt carries personal data: a customer's name, a phone number, an ID, an address. AMAN, Mizan's PII redaction feature, removes that data before a prompt ever reaches a model.

Why it matters for Saudi businesses

Saudi Arabia's Personal Data Protection Law (PDPL) sets strict rules for handling personal data and restricts transferring it outside the Kingdom. Most leading AI models are hosted abroad, so every unredacted prompt is a possible cross-border transfer, and once it's sent, it can't be recalled.

For healthcare, banking and government teams, that risk alone can stall AI adoption.

How it makes life easier

AMAN is built into the Mizan gateway, so your apps don't need a new SDK or any code changes. Every request is redacted automatically, and your team no longer has to clean prompts by hand or maintain its own detection rules.

How AMAN works

Every request passes through four detectors, and each one catches what the others can't:

  1. 1Pattern detection finds data with a fixed format: emails, phone numbers, card numbers, IBANs and ID numbers. It runs on your own server in milliseconds.
  2. 2Secrets detection finds passwords, API keys and access tokens. It also runs locally, so credentials are never sent anywhere to be checked.
  3. 3Local AI model recognizes names, places and addresses, which have no fixed format. It runs on standard server hardware, not an external service.
  4. 4AI review (optional) reads the already-redacted prompt and flags anything left behind. That text can still hold identifying details, so the review can use a model hosted inside the Kingdom.

After redaction, an optional risk gate scores each prompt on how likely it is to still contain personal data, so risky prompts can be flagged before they're sent.

How we tested it

  • Regression suite — every release must pass our own hand-written test suite.
  • English — we tested AMAN on an independent, third-party dataset: tens of thousands of synthetic documents, such as forms, records and letters, dense with personal data. We ran every combination of detectors through the real production pipeline.
  • Arabic — we generated 500 synthetic documents with Saudi, Emirati, Egyptian and Jordanian names, addresses, phone numbers and IDs, and ran the same combinations.
  • Risk gate — we had it score prompts at every level of redaction, from none up to all four detectors, and checked each score against whether anything had actually leaked.

What we found

At a glance

DetectorsEnglish redactionArabic redaction
Patterns only48%39%
Patterns + local AI model90%57%
Patterns + AI review (no local model)—94%
All four detectors97%86%

Note: The English and Arabic results come from different datasets, so compare them by type of data, such as names or addresses, rather than by the overall totals.

English

  • Patterns alone aren't enough. They reliably catch emails, phone numbers and IDs, but they can't recognize names, so on their own they redact only 48% of personal data.
  • The local AI model contributes the most. It raises redaction to 90%, and no text leaves your server.
  • The AI review closes most of the remaining gap. It lifts redaction to 97% without increasing over-redaction.
  • The two AI layers work best together. Each finds different things, and the review can't replace the local model.

Arabic

  • Patterns catch every email, ID and passport number, but on their own they redact 39% of personal data.
  • The local AI model is weaker on Arabic names and only raises redaction to 57%.
  • The AI review does most of the work. Running it without the local model gives the best result: 94% redaction with almost no over-redaction. With all four detectors it's 86%, because the local model's partial name matches stop the review from redacting the full name.
  • Addresses and names are the hardest to catch. Gulf national IDs, numbers written out as words, and Saudi short addresses aren't covered by patterns yet. These are known gaps with fixes already scoped, and for now the AI review catches most of them.

The risk gate

  • It reliably separates prompts that still leak from clean ones. On data it hadn't been tuned on, it caught 90% of leaking English prompts and 98% of leaking Arabic ones, and its flags were right about as often.
  • Its score drops as redaction gets stronger, so it follows the real risk.
  • Its scores are less reliable as exact probabilities in Arabic, so on Arabic text it should be used to flag prompts, not to block them automatically.

AI routing, built for Saudi Arabia

Start routing your AI before complexity controls you.

Route, track and reduce your AI spend with Mizan.