## Built For Strict Privacy Rules
-PasteGuard is not a compliance certification and does not make your system compliant by itself. It is designed for teams that need a local or self-hosted control point before AI providers.
+PasteGuard is a privacy control point before AI providers. It can support regulated workflows, but it does not replace your legal, security, or compliance program.
Use it when your current options are:
Configure local routing for sensitive requests
</Card>
-## What PasteGuard Does Not Claim
+## Compliance Boundary
PasteGuard does not by itself certify compliance with DORA, GDPR, HIPAA, SOC 2, or any other framework.
## Built For Raw Data Limits
-PasteGuard does not certify your organization as compliant. It gives teams a local or self-hosted control point before requests reach AI providers.
+PasteGuard gives teams a local or self-hosted control point before requests reach AI providers.
Use it when the current options are manual redaction, no cloud AI for sensitive work, a weaker local-only model, or custom masking code in every app.
- How masking rules are configured
<Warning>
-PasteGuard is not a compliance certification and does not make an organization compliant by itself. It can help keep sensitive values out of prompts before they reach a provider.
+PasteGuard can help keep sensitive values out of prompts before they reach a provider. Your legal, security, and compliance controls still decide whether a workflow is production-ready.
</Warning>
## What To Validate In A Pilot