KINDI · A bureau for handling sensitive language.

In-Kingdom PII masking for frontier LLMsRiyadh · Kingdom of Saudi ArabiaPreview
KINDI.me
17 Aug 2026 · 1448-03-04 HRiyadh · --:-- AST
SUBJECT№ 01

For Saudi organizations routing regulated text through frontier LLMs.

TITLE

KINDI lets Saudi organizations use ChatGPT, Claude, and Gemini without exporting personal data.

SPECIMENLIVE
DEM. 00Demonstration · in progress

Patient Khalid Al-Otaibi, NID 1052338942, admitted 07 Shawwal 1446H, reachable at +966 50 221 8403.

SUMMARY

Sending raw Saudi personal data to ChatGPT, Claude, or Gemini is a regulated cross-border transfer under the PDPL. KINDI substitutes regulated identifiers with deterministic placeholders before the request crosses the border, so the payload is no longer personal data. The sector rules that do mandate in-Kingdom processing, SAMA for banking and the NCA DCC and health-data controls, are met the same way. The mapping is encrypted under your API key and unmasked in your client. The server stores nothing.

Routing · the path of one request
Inside the Kingdom
  1. 01

    Raw text

    your application

    Patient نورة … NID 1052338942 …

  2. 02

    Mask

    kindi.me

    Patient PERSON_NAME_01 … NID NATIONAL_ID_01 …

  3. 04

    Unmask

    your client

    Reply restored locally under your API key.

  1. 03

    Frontier model

    hosted abroad

    Same masked text. No citizen data crosses the border.

    Interoperates with
    • OpenAI
    • Anthropic
    • Google
    • xAI
Outside the Kingdom
  1. 01

    Raw

    your application

    Patient نورة … NID 1052338942 …
  2. 02

    Mask

    kindi.me

    Patient PERSON_NAME_01 … NID NATIONAL_ID_01 …
  3. 03

    Frontier model

    hosted abroad

    Same masked text. No citizen data crosses the border.
    Interoperates with
    • OpenAI
    • Anthropic
    • Google
    • xAI
  4. 04

    Unmask

    your client

    Reply restored locally under your API key.

Only masked text crosses the border. Originals stay on your side in the Kingdom, encrypted under a key derived from your API key. KINDI holds neither the data nor the key.

PDPL Art. 29 · NCA ECC · CCC · DCC. Alignment statement; certification pending.

Optional KINDI can mask, forward the request to the model, and unmask the response in one in-Kingdom proxy call, currently for OpenAI and Anthropic. Only masked text crosses the border; originals stay in the Kingdom. The proxy runs only when you call it.

Worked specimens · ongoing
PL. 01 · № 01
Clinical intake

Patient نورة بنت عبدالله السبيعي, NID 1052338942, admitted 03 Rajab 1447H.

PL. 02 · № 02
Reimbursement memo

Transfer to PERSON_NAME_01, IBAN SA44 2000 0001 2345 6789 1234; confirm to +966 50 221 8403.

PL. 03 · № 03
Court correspondence

Re: claimant PERSON_NAME_01, iqama 2391847569, filed 07 Shawwal 1446H.

§ I.

How it works

KINDI detects PII and replaces each span with a deterministic placeholder before the text reaches a model. Your client restores the originals, or the optional proxy restores them in the Kingdom.

01

Detect

KINDI locates PII spans: Saudi National IDs, iqamas, names in both scripts, IBANs, dates, addresses, and phone numbers. Saudi identifiers are checksum-verified: a value that cannot be a real national ID, iqama, or IBAN is not treated as one. Uploaded files are validated more leniently. A saved or per-request glossary adds your own terms, such as codenames and contract identifiers.

detection
02

Mask

KINDI replaces each span with a stable placeholder. It returns the masked text with a mapping encrypted under a key derived from your API key. The server keeps no copy.

deterministic
03

Unmask

Your client decrypts the mapping with the same API key and substitutes the placeholders in the model’s response. With the optional proxy, KINDI performs this unmask in-Kingdom before returning the response. Either way, the originals never leave the Kingdom.

client-side
§ II.

Demonstration

The sample below marks PII, replaces it with placeholders, and seals the mapping in your browser. It sends no request. Extended entity types are switched on for this panel: medical record numbers are off by default and enabled per account in the dashboard.

Case note · intake
PL. 02 · § 02

Marked in your browser: national ID, iqama, IBAN, +966 phone, dates. Nothing is transmitted. Clear the field to restore the sample.

Submission

Patient أحمد بن سالم القحطاني, NID 1098234568, presented on 14 Ramadan 1446H. MRN KFMC-4429012. Reimbursement to IBAN SA03 8000 0000 6080 1016 7519.

Ledger
  • PERSON00
  • NATIONAL_ID00
  • DATE_TIME00
  • MRN00
  • IBAN00
  • Total spans00
Envelope · sealed
cipheraes-256-gcm
nonce96-bit, per-request
keyHKDF(api_key) · derived client-side
payload9f2c4a:b81e07:c4d3aa:1e9f02:7b3c81:a04e91:62d8f3
the desk · awaiting submission00:00.00
§ III.

Coverage

Ten entity types are on by default. Thirteen more are available and one toggle away. Entity toggles are set per account in the dashboard and apply to every request the account makes. A saved or per-request glossary adds your own terms.

On by default · 10 types
EntityExamplesPlaceholder form
PERSONPersonal names in Latin or Arabic script, including patronymics.PERSON_NAME_01
NATIONAL_IDSaudi National ID. Ten digits, leading 1, checksum-verified.NATIONAL_ID_01
RESIDENCE_PERMITIqama. Ten digits, leading 2, checksum-verified.RESIDENCE_PERMIT_01
PHONE_NUMBERSaudi and international numbers, in E.164 or local form.PHONE_01
EMAIL_ADDRESSEmail addresses.EMAIL_01
DATE_TIMEHijri and Gregorian dates, times, and ages.DATE_01
IBANSaudi IBAN. SA prefix, 24 characters, checksum-verified.IBAN_01
CREDIT_CARDPayment card numbers.CARD_01
PASSPORTSaudi and foreign passport numbers.PASSPORT_01
ADDRESSAddresses on the Saudi national addressing system: building, street, district, postal code.ADDRESS_01
Available, one toggle away · 13 types
EntityExamplesPlaceholder form
ORGANIZATIONNamed bodies in both scripts: hospitals, ministries, شركة and مؤسسة parties.ORG_01
LOCATIONCities, districts, and other named places.LOCATION_01
MRNMedical record numbers, including facility-prefixed forms.MRN_01
BUSINESS_IDCommercial registration (CR) numbers.BUSINESS_ID_01
TAX_IDVAT and Zakat registration numbers.TAX_ID_01
VEHICLE_PLATESaudi vehicle plates, Latin and Arabic letter sets.VEHICLE_PLATE_01
STUDENT_IDStudent and university enrolment numbers.STUDENT_ID_01
INSURANCE_POLICYInsurance policy and membership numbers.INSURANCE_POLICY_01
MEDICAL_LICENSEPractitioner licence numbers.MEDICAL_LICENSE_01
API_KEYCredentials and bearer tokens pasted into a note.API_KEY_01
MONETARY_AMOUNTSums in SAR and other currencies.AMOUNT_01
SSNForeign national insurance and social security numbers.SSN_01
IP_ADDRESSIPv4 and IPv6 addresses.IP_01

The entity name is the span type /mask returns. The placeholder form is what /redact writes in place of the first occurrence of that type; further occurrences enumerate upward.

§ IV.

The API

Two HTTPS endpoints carry the core: /mask, which returns masked text plus an encrypted mapping, and /redact, which returns enumerated placeholders. File redaction and the optional LLM proxy build on the same detection. Unmasking runs client-side; there is no /unmask endpoint by design.

A. Request
PL. 13 · § 01
>curl -X POST https://api.kindi.me/api/v1/mask -H "Authorization: Bearer mk_live_..." -H "Content-Type: application/json" -d '{"text": "Patient Khalid Al-Otaibi, NID 1052338942."}'
200 masked_text · spans · encrypted envelope
B. Response
200 OKapplication/json
1
{
2
"masked_text": "Patient <MASKED_PERSON_a1b2c3d4>, NID <MASKED_NATIONAL_ID_9e7f21b0>.",
3
"spans": [
4
{ "start": 8, "end": 24, "type": "PERSON" },
5
{ "start": 30, "end": 40, "type": "NATIONAL_ID" }
6
],
7
"pii_count": 2,
8
"ciphertext": "…base64…",
9
"nonce_payload": "…base64…",
10
"wrapped_dek": "…base64…",
11
"nonce_dek": "…base64…",
12
"processing_time_ms": 41,
13
"judge_used": false
14
}

Official TypeScript and Python SDKs are packaged with the private beta; the API is plain HTTPS.

C. HTTP
POSTapi.kindi.me/api/v1/mask200 masked
POSTapi.kindi.me/api/v1/redact200 redacted
1
/mask returns the masked text plus an encrypted envelope containing the original mapping. The key wrapping the envelope is derived from your API key client-side.
2
/redact returns enumerated placeholders without an envelope for cases where the original is not needed back.
3
Revoking the API key makes any outstanding envelopes undecryptable. This is by design.
§ V.

Contact

Get in touch.

Correspondence
Through the form. KINDI publishes no email addresses; notes are routed by topic to the right desk. Legal, data-protection, and security correspondence has its own topics at kindi.me/contact.

Location
Riyadh, Kingdom of Saudi Arabia

Hours
Replies within one business day, Sunday through Thursday.

Send a note

Delivered to the KINDI desk. Not published; used only to reply.