Your client's security team asks what left the pipeline. Show them.
You build n8n workflows on your client's data, and the bigger contract goes to whoever can prove that data was handled safely. Privent turns that proof into a deliverable: a login-free, attestable evidence report you hand over under your own brand.
The motion, in three steps.
- 01
Scan free, inside your own n8n
The free risk scan runs as a workflow you import and execute yourself. No API key handover, aggregate counts only, results expire in seven days.
- 02
Protect in the workflow
Drop the Privent nodes into the client's workflows. Sensitive values become typed, reversible tokens before any external model sees them, and the workflow never stops.
- 03
Hand over the report, under your brand
Generate the evidence report, sign and lock it, and share one login-free link your client's security team can read. Your logo and name are on it.
The report is the deliverable.
| Ref | Control | Status | Evidence |
|---|---|---|---|
| Art 30 | Records of processing | COVERED | Data processing inventory from observed entity flows |
| Art 32 | Security of processing | COVERED | Tokenization events and egress log for the period |
| Art 15-22 | Data subject rights | OUT OF SCOPE | Remains with the controller; stated, not claimed |
Out of scope is deliberately neutral in this report. It means we do not claim to cover this, and that honesty is exactly what an auditor-facing document needs.
Attestation and sign-off
After certification, the report is locked and the attestation becomes part of the audit trail.
One link, in your client's inbox
- –One login-free link; the token is the access
- –Frozen at attest time; it does not update if the report changes
- –Revocable in one click; signing again mints a new link
- –The link always shows every framework, including out-of-scope rows; your PDF and CSV exports follow your framework selection
Under your brand.
This is white-label done honestly: the shared report page carries your logo and name in place of ours, and the exported auditor PDF carries them too, with a small Powered by Privent line on its cover. Branding applies to new exports and newly shared reports.
What you control: Branding mode (Privent or custom), your logo (PNG, JPG or SVG), brand name, prepared-by line, and an accent colour from eight curated presets or your own hex.
Three export formats travel with it: the auditor PDF, a JSON artifact, and a CSV evidence package (a zip of seven CSVs plus a manifest).
The trust argument is architectural.
Raw prompt and agent payload text is never stored; it is processed in memory only, and detection events keep metadata: risk score, category, decision, timestamp. When the LLM judge learns from a blocked detection, it stores an embedding vector, never the text. Self-hosted deployments that don't configure a vector store persist nothing beyond event metadata.
Every artifact also says plainly what it is: point-in-time operational evidence. It does not constitute an audit opinion or conformity assessment, and independent auditor review is required for formal assertions. Your client's auditors read that line and trust the rest more, not less.
Win the bigger contract.
Start with the free scan on your own n8n, then bring the report to your next client review.
