CAIO Vault Gate
A security ingestion gate that re-scans PII regardless of source declarations, quarantines uncertainty, and never logs sensitive values.
This screen carries client operating data, so the case study shows architecture and representative screens instead of a public link.
Overview
A PII ingestion gate that re-scans material on its own before it enters the knowledge base. It does not take the upstream source's word for it.
Payloads route through contract validation, PII scan, sensitivity tiering, and deduplication. I put unicode, homoglyph, and spread-out evasion payloads into the tests, and pinned the log format so sensitive values never get written.
Only what is clearly safe gets through. Anything uncertain stops there, and an operator opens it and decides.
Core skills
Implementation
- 1Validated ingestion contracts before routing through PII scan, sensitivity tiering, and deduplication.
- 2Used NFKC normalization and Luhn checks to separate email, phone, ID-like, and card-like patterns.
- 3Iterated with red-team payloads while fixing logs to store only type names and counts, never values.
Strengths
- Reduces trust in upstream declarations by independently rescanning every payload.
- Reduces operating incidents by quarantining uncertain data instead of passing it through.
- Tests cover adversarial inputs close to real evasion attempts.
Metrics
Tech stack
Screenshots
