AMAN: Keeping Personal Data Where It Belongs
AMAN, Mizan's PII redaction feature, removes personal data from prompts before they reach a model. Here's how it works, and how well it performs in English and Arabic.
AI is now part of everyday work, and almost every prompt carries personal data: a customer's name, a phone number, an ID, an address. AMAN, Mizan's PII redaction feature, removes that data before a prompt ever reaches a model.
Why it matters for Saudi businesses
Saudi Arabia's Personal Data Protection Law (PDPL) sets strict rules for handling personal data and restricts transferring it outside the Kingdom. Most leading AI models are hosted abroad, so every unredacted prompt is a possible cross-border transfer, and once it's sent, it can't be recalled.
For healthcare, banking and government teams, that risk alone can stall AI adoption.
How it makes life easier
AMAN is built into the Mizan gateway, so your apps don't need a new SDK or any code changes. Every request is redacted automatically, and your team no longer has to clean prompts by hand or maintain its own detection rules.
How AMAN works
Every request passes through four detectors, and each one catches what the others can't:
- 1Pattern detection finds data with a fixed format: emails, phone numbers, card numbers, IBANs and ID numbers. It runs on your own server in milliseconds.
- 2Secrets detection finds passwords, API keys and access tokens. It also runs locally, so credentials are never sent anywhere to be checked.
- 3Local AI model recognizes names, places and addresses, which have no fixed format. It runs on standard server hardware, not an external service.
- 4AI review (optional) reads the already-redacted prompt and flags anything left behind. That text can still hold identifying details, so the review can use a model hosted inside the Kingdom.
After redaction, an optional risk gate scores each prompt on how likely it is to still contain personal data, so risky prompts can be flagged before they're sent.
How we tested it
- Regression suite — every release must pass our own hand-written test suite.
- English — we tested AMAN on an independent, third-party dataset: tens of thousands of synthetic documents, such as forms, records and letters, dense with personal data. We ran every combination of detectors through the real production pipeline.
- Arabic — we generated 500 synthetic documents with Saudi, Emirati, Egyptian and Jordanian names, addresses, phone numbers and IDs, and ran the same combinations.
- Risk gate — we had it score prompts at every level of redaction, from none up to all four detectors, and checked each score against whether anything had actually leaked.
What we found
At a glance
| Detectors | English redaction | Arabic redaction |
|---|---|---|
| Patterns only | 48% | 39% |
| Patterns + local AI model | 90% | 57% |
| Patterns + AI review (no local model) | — | 94% |
| All four detectors | 97% | 86% |
Note: The English and Arabic results come from different datasets, so compare them by type of data, such as names or addresses, rather than by the overall totals.
English
- Patterns alone aren't enough. They reliably catch emails, phone numbers and IDs, but they can't recognize names, so on their own they redact only 48% of personal data.
- The local AI model contributes the most. It raises redaction to 90%, and no text leaves your server.
- The AI review closes most of the remaining gap. It lifts redaction to 97% without increasing over-redaction.
- The two AI layers work best together. Each finds different things, and the review can't replace the local model.
Arabic
- Patterns catch every email, ID and passport number, but on their own they redact 39% of personal data.
- The local AI model is weaker on Arabic names and only raises redaction to 57%.
- The AI review does most of the work. Running it without the local model gives the best result: 94% redaction with almost no over-redaction. With all four detectors it's 86%, because the local model's partial name matches stop the review from redacting the full name.
- Addresses and names are the hardest to catch. Gulf national IDs, numbers written out as words, and Saudi short addresses aren't covered by patterns yet. These are known gaps with fixes already scoped, and for now the AI review catches most of them.
The risk gate
- It reliably separates prompts that still leak from clean ones. On data it hadn't been tuned on, it caught 90% of leaking English prompts and 98% of leaking Arabic ones, and its flags were right about as often.
- Its score drops as redaction gets stronger, so it follows the real risk.
- Its scores are less reliable as exact probabilities in Arabic, so on Arabic text it should be used to flag prompts, not to block them automatically.
AI routing, built for Saudi Arabia
Start routing your AI before complexity controls you.
Route, track and reduce your AI spend with Mizan.
Related articles
Data Residency and Saudi Arabia's PDPL: What AI Teams Should Understand
A plain-language primer on why Saudi Arabia's Personal Data Protection Law is relevant to AI and LLM workloads — and the most common misconception about what it actually requires.
Where your data goes, and what Mizan keeps: data residency and zero data retention
A request through Mizan passes through two points: Mizan and the model provider. Here is where each one sits, what each one retains, and the settings you control.