It sees every tool call from inside the engine, scores it in context, and swaps sensitive values for reversible tokens before anything leaves your network. The flow never stops.
Nothing else was ever visible from out here.
Your gateway sees one outbound request. It never sees the twelve that built it.
Steps chain with no human in the loop and native LLM nodes bypass proxies entirely.
A file is one attachment to your DLP and a thousand sensitive fields to your model.
Privent runs inside the execution engine, so the same layer that sees the call is the one that transforms it and the one that signs the evidence.
Privent sits in the workflow's own run, not in a proxy outside it. It works on the session state inside the workflow, data that never crosses an HTTP proxy.
Risk is scored against the live session, then the sensitive values are transformed in place and put back only where you allow it. The workflow is never blocked.
Every run leaves evidence you can hand to an auditor, or to your client.



Privent runs where the agent runs. It reads the full session state, not the final string, and transforms risky values before any call leaves.
Contracts, spreadsheets, scans. Sensitive fields are tokenized in place. The file stays usable, reversible, and audit-ready.
One npm package hands Claude, Cursor, or any MCP client the same tokenize, risk, and audit tools, with the same evidence.
Same engine. Same policy. Same audit trail.
One package hands Claude, Cursor, or any MCP client the Privent tools: tokenize, detokenize, risk scoring, and audit, backed by your organization. Every tool use leaves an audit event, and nothing is blocked. MCP tool-call interception ships as @priventai/mcp-gateway, run with npx in front of your own servers.
Three industries, one layer. The answer is the same every time.
Watch the full run on an n8n flowEvery scan and every run produces a report you can share as one link. Whoever opens it needs no account, the report carries no raw payloads, and you can revoke it the moment it has done its job.

The n8n node ships as a public npm package you can read, sign-check, and install before you ever talk to us.
Privent secures every point where your data meets AI inside your n8n workflows.
Autonomous pipelines have no eyes. Privent does.
n8n flows for intake, triage, and scheduling pull patient records and compose prompts with no human in the loop. Privent masks PHI before it reaches any external model, keeping your workflows inside the HIPAA boundary.
Something not covered? Reach out directly. We respond within one business day.
7 questions,
answered directly.
These are the real questions we get from security leads, engineering managers, and compliance officers evaluating Privent.