Proxaradocs
Trust Center/Compliance

Data Protection Impact Assessment

Article 35 risk assessment for the Endpoint Protection device service: processing activities, necessity, proportionality, risk scenarios, and mitigation measures.

Updated July 2026

Data Protection Impact Assessment

Last updated: July 2026

Controller / Processor: Proxara, Inc.

Assessment Date: June 2026

Assessor: Jex Pearce, Founder

Review Cycle: Annual, or upon material change to processing activities

This Data Protection Impact Assessment ("DPIA") is prepared in accordance with Article 35 of the UK GDPR and EU GDPR. It assesses one processing activity: the Endpoint Protection device service (network-layer interception, redaction, and MCP observability on managed devices) as deployed within customer environments, and describes the measures implemented to mitigate its risks. The separate Proxara Connect processing activity (server-side retrieval from Microsoft 365 under delegated permissions) has its own assessment: the Proxara Connect DPIA. Statements in this document about where data is and is not stored describe the device service only.


1. Description of Processing

1.1 What Proxara Does

Endpoint Protection is Proxara's device-level data-protection and observability product. A signed agent, deployed through the firm's MDM, redacts sensitive data from AI requests at the network layer before they leave the firm and records a cryptographically signed audit trail for compliance. (Proxara's hosted connector product, Proxara Connect, is assessed separately in the Proxara Connect DPIA.)

The system operates through two integrated components:

  • Device proxy. A native background service for macOS and Windows that operates as a local TLS-inspecting proxy. It intercepts AI-bound HTTPS traffic at the operating system network layer, covering all applications on the device (browsers, desktop AI apps, coding tools, CLIs, API calls). The proxy trusts a per-tenant root CA, minted server-side at enrollment and delivered over the authenticated enrollment envelope, carrying X.509 Name Constraints (RFC 5280) that exclude sign-in, banking, healthcare, government, and security-tooling domains in the certificate itself. A connection is decrypted only on positive evidence the destination is an AI service; all other traffic is tunnelled through without decryption. On platforms that enforce name constraints, a certificate this CA issues for an excluded domain does not validate, and the exclusions are readable directly from the certificate. Sign-in pages, banking services, healthcare services, and government services are excluded by design and are never intercepted.
  • MCP observability component. Embedded in the agent, this component discovers MCP servers and connectors in use on the device, records signed audit events for tool activity observed via the network proxy, and allows the compliance team to block or quarantine a server through the governance console. MCP clients connect directly to their own servers; this component does not sit in line as a holding broker.

Both components share the same classification API, the same identity vault, and the same cryptographically chained audit log.

The system operates through three primary functions:

Real-time semantic redaction. The service intercepts employee prompts before they reach external AI tools. The classification engine identifies sensitive identifiers (client names, account numbers, Social Security numbers, medical record numbers, and similar data) and replaces them with context-preserving semantic tokens (for example, "[Client_A]", "[Account_Num_1]"). The redacted prompt is forwarded to the external AI. When the AI responds, the service restores the original values from a device-side vault so the employee sees natural text. The external AI provider receives the redacted version in place of the detected sensitive values.

Compliance monitoring. The service captures the interaction (prompt text, AI response, and any uploaded files) and sends it to the classification engine. The classifier analyzes each interaction for compliance risk based on the customer's industry profile and organizational policies. Interactions that may contain sensitive data or regulatory risk are flagged for compliance officer review.

MCP governance. When employees use MCP-capable AI clients, the service observes tool activity, tags each event against the compliance control library, and surfaces governance decisions (block or quarantine per server) to the compliance team. MCP requests the device proxy can inspect are redacted with the same engine as other AI traffic before they reach a downstream server.

1.2 What Is and Is Not Intercepted

Proxara inspects interactions with external AI assistants and AI features, including ChatGPT, Claude, Google Gemini, Perplexity, DeepSeek, Grok, Azure OpenAI, Amazon Bedrock, and Google Vertex AI, along with the AI features in the firm's connected business applications. It also observes Model Context Protocol (MCP) activity from AI clients.

The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic; it passes through unmodified. (Proxara Connect's server-side retrieval of Microsoft 365 content is a separate processing activity, assessed in its own DPIA.) Sign-in pages and traffic to banking, healthcare, and government services are never intercepted.

1.3 Deployment Model

Proxara provisions and manages a dedicated, isolated cloud environment on behalf of each customer (Amazon Web Services). There is no shared multi-tenant environment. Each customer deployment is a single-tenant instance running in a dedicated AWS account.

Proxara-Managed (default). Proxara provisions, deploys, and operates the customer's dedicated AWS environment. The customer receives read-only access to the environment and retains full ownership of all data. On termination, the customer may take ownership of the dedicated AWS account or Proxara will delete all data and certify destruction.

Customer-Managed (alternative). Proxara provides deployment templates and software. The customer deploys and operates the service in their own AWS account. Proxara does not access customer data.

The agent reaches employee laptops through the firm's MDM (Jamf, Intune, Kandji, and compatible platforms); employees install nothing themselves.

This DPIA addresses the Proxara-Managed deployment model, where Proxara acts as a data processor.

1.4 Data Subjects

  • Employees and contractors of the customer organization who are authorized to use external AI tools. These individuals' interactions with AI tools are monitored and, where applicable, subject to automated redaction.
  • Third parties whose personal data may be present in employee prompts or uploaded files (for example, client names, account numbers, or contact details referenced in the course of work).

1.5 Categories of Personal Data Processed

Data CategorySourceRetention
Employee identifiers (name, employee ID, device ID)Customer-provided during deploymentDuration of service
Prompt text submitted to external AI toolsCaptured by the serviceAll intercepted interactions are stored briefly. Default retention is 7 days (configurable; 0 = retain until manually purged). Purged automatically at the end of the retention window.
AI response textCaptured by the serviceSame as prompt text
Uploaded file content (spreadsheets, PDFs, CSVs, documents)Captured by the device proxy when an employee uploads files to AI toolsRetained during the same window as the associated interaction. Original file bytes are never stored; only redacted text and a hash of the redacted bytes.
Identity vault tokens (original value to semantic token mapping)Generated on-device by the classification engineHeld in an on-device encrypted vault; the device service does not store these mappings in the customer's cloud environment. Retiring a token destroys the AES-256-GCM key, making the original unrecoverable.
Device enrollment data (device ID, platform, hostname, agent version)Collected during device service registrationDuration of service
Classification results (severity, risk category, data types)Generated by classification engineRetained as part of the interaction record and supervision audit log
Supervision audit log (reviewer actions, status changes, notes)Generated by compliance workflowRetained as the permanent supervision record. Contains metadata only; no original prompt or response content. Never purged.
Session metadata (provider name, page URL, timestamp)Captured by the serviceRetained with audit records
MCP tool-call records (tool name, server identifier, hashed arguments, classification, resolved egress mode)Observed by the MCP componentRaw payloads are never stored; only hashes and signatures. Retained per customer-configured retention window. Cryptographically signed and hash-chained per tenant.
Per-server governance records (egress mode, taxonomy, compliance officer identity, optional DPA reference)Set by the customer's compliance officerRetained with version history; never physically deleted.

1.6 Special Category Data

Proxara does not intentionally process special category data (Article 9). However, depending on the customer's industry, employee prompts may contain:

  • Health data (healthcare firms handling patient information)
  • Financial data subject to professional secrecy
  • Data revealing racial or ethnic origin, political opinions, or trade union membership (if present in uploaded documents)

The purpose of Proxara's processing is to prevent this data from reaching external AI tools. The redaction engine intercepts and replaces such data before it leaves the firm's environment.

1.7 Recipients of Personal Data

RecipientData ReceivedLegal Basis
AWS (Amazon Web Services)All data processed within the customer's dedicated, isolated AWS environment. Amazon Bedrock processes prompt text for classification (Claude Haiku 4.5); Bedrock does not store model inputs or outputs. Amazon Textract processes file bytes for text extraction.Sub-processor agreement (AWS Customer Agreement)
Google LLC (Google Workspace)Outbound transactional and notification email: recipient addresses and email content.Sub-processor agreement
Customer's compliance archive provider (e.g., Smarsh, Global Relay)Where the firm enables the integration, interaction records the firm chooses to forward for regulatory archivalCustomer's agreement with archive provider
Customer's communication platforms (Slack, Teams, email)Notification summaries (severity, employee name, provider, brief excerpt) routed to customer-configured channels. Off by default; customer-controlled.Customer-controlled; Proxara does not select or operate these platforms
ExaUsed only when Proxara researches an unrecognized MCP server's capabilities. Receives server or software metadata and a generated query; never employee content or personal data.Sub-processor agreement
Sigstore Rekor (public transparency log, on by default)Audit anchoring transmits only 32-byte Merkle batch root hashes. No personal data is sent.Public service operated under the Linux Foundation. Anchoring runs by default and continues locally if the log is unreachable.

Proxara does not sell, share, or disclose personal data to any other third party.


2. Necessity and Proportionality

2.1 Lawful Basis

The customer (data controller) determines the lawful basis for monitoring employee AI interactions. Typical bases include:

  • Legitimate interest (Article 6(1)(f)): the firm's interest in regulatory compliance, supervision of communications, and prevention of inadvertent data disclosure. Regulated firms in financial services, healthcare, and legal sectors have statutory obligations to supervise employee communications (for example, FINRA Rule 3110, SEC Regulation S-P, HIPAA, ABA Model Rules).
  • Legal obligation (Article 6(1)(c)): where applicable regulations require supervision of employee use of external communication tools.

Proxara processes personal data solely on the customer's documented instructions and for the purpose of providing the service as described in the Data Processing Addendum.

2.2 Why This Processing Is Necessary

Employees at regulated firms are using external AI tools regardless of whether their firm has a formal AI policy. Industry surveys indicate over 70% of employees at advisory firms use AI tools, and the majority use personal devices or accounts outside employer visibility.

Without a technical supervision layer, firms face a binary choice: ban AI (unenforceable and commercially disadvantageous) or permit AI with no compliance oversight (regulatory risk).

Proxara resolves this by enabling supervised AI use: employees can use AI tools productively while the firm maintains the compliance oversight its regulators require.

2.3 Why This Processing Is Proportionate

Data minimization is core to the architecture:

  • Identity vault tokens (the link between a semantic tag and its original value) are held in an on-device encrypted vault and are not stored in the customer's cloud environment. Each token's original value is sealed under its own AES-256-GCM key derived via HKDF. Retiring a token destroys the key; the original becomes unrecoverable.
  • All intercepted interactions are stored for a short, configurable window (default 7 days) and then purged automatically. The supervision audit log retains metadata only (no content) and is the permanent record of compliance activity.
  • File originals are never stored. Only redacted text and a cryptographic hash of the redacted bytes are retained.
  • MCP tool-call raw payloads are never stored. Only hashes and signatures are retained.
  • AWS Bedrock (used for AI classification) does not store model inputs or outputs.

The processing scope is narrowly targeted:

  • The device proxy's TLS interception is restricted to AI provider domains by X.509 Name Constraints embedded in the root CA certificate; non-AI traffic is never intercepted or decrypted.
  • Only user-submitted text (prompts) and uploaded files are analyzed. The service does not capture browsing history, keystrokes, screenshots, or other ambient data.
  • The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic.

Less intrusive alternatives were considered:

AlternativeWhy Insufficient
Policy-only approach (no technical controls)Unenforceable; does not provide regulators with evidence of active supervision
Post-hoc log review (no real-time interception)Does not prevent sensitive data from reaching external AI tools; by the time a log is reviewed, the data has already been disclosed
Full network monitoring (DLP at network layer)Disproportionate; captures all web traffic, not just AI interactions; higher privacy impact
Blanket AI banCommercially disadvantageous; studies show employees circumvent bans using personal devices

Proxara is the least intrusive approach that satisfies the regulatory requirement for active supervision while preventing data leakage.


3. Risk Assessment

3.1 Risks to Data Subjects

RiskLikelihoodImpactOverall RiskMitigation Reference
R1: Unauthorized access to audit records. An attacker or unauthorized person gains access to stored prompts, responses, or file content containing personal data.LowHighMediumM1, M2, M3, M4
R2: Breach of identity vault. Token-to-original mappings stored on-device are exposed, enabling re-identification.Very LowHighLowM5
R3: Redaction failure. The classification engine fails to detect sensitive data in a prompt or file, allowing it to reach an external AI tool.MediumMediumMediumM6, M7
R4: Excessive monitoring. Employees are subjected to disproportionate surveillance beyond what is necessary for compliance.LowMediumLowM8, M9
R5: Data retained beyond necessary period. Audit records or file content retained longer than required.LowMediumLowM10
R6: Sub-processor breach. AWS infrastructure or Bedrock service is compromised.Very LowHighLowM11, M12
R7: Employee awareness gap. Employees are not informed that their AI interactions are monitored.MediumMediumMediumM13
R8: Inference from classification metadata. Even after purge of full text, retained metadata (severity, data types, risk category) could reveal information about the nature of an employee's work.Very LowLowVery LowM14
R9: Device service root CA compromise. The per-tenant root CA private key is extracted from a device, enabling impersonation of AI provider domains for the firm's devices.Very LowHighLowM15
R10: Local vault data exposure. Identity vault data stored on the employee's device is accessed by an unauthorized party.Very LowMediumVery LowM16
R11: Sensitive data reaches a downstream MCP server. MCP requests the device proxy can inspect are redacted before they reach a downstream server, but a server reached over a path the proxy cannot inspect could receive sensitive data.LowMediumLowM17
R12: Tampering with the audit chain. A bad actor with local access attempts to alter, reorder, or delete events from the audit log to conceal an action.Very LowHighLowM18
R13: Tool-call supply-chain compromise. A poisoned or rug-pulled MCP server attempts to exfiltrate data via a malicious tool description, hidden instruction in a tool result, or a multi-step "leak then send" pattern.MediumHighMediumM19

3.2 Risk Ratings

  • Very Low: Risk is negligible; no further action required beyond existing controls
  • Low: Risk is adequately controlled; monitor and review annually
  • Medium: Risk requires active mitigation; controls must be verified and maintained
  • High: Risk is unacceptable; additional controls must be implemented before processing

4. Mitigation Measures

M1: Infrastructure Isolation

Each customer deployment runs within a dedicated, isolated AWS account and VPC provisioned and managed by Proxara on the customer's behalf. There is no shared multi-tenant infrastructure. Customer data does not commingle with other customers' data. Network security groups restrict inbound and outbound traffic to required ports and services. The classification API and database run in private subnets with no direct inbound internet access. The customer receives read-only access to the environment and retains full ownership of all data.

M2: Encryption

  • In transit: All communications between the service (device proxy and MCP component) and the classification API use TLS 1.2 or higher, with TLS 1.3 supported. AWS Bedrock API calls use TLS, and inference runs within the customer's own AWS account.
  • At rest: PostgreSQL databases (RDS) are encrypted with AES-256 via AWS KMS using customer-managed keys. Amazon S3 audit archives are encrypted with AES-256 via KMS with COMPLIANCE Object Lock (WORM), 7-year retention, immutable. EBS volumes are encrypted with AES-256 via KMS.

The customer owns the KMS keys. Proxara holds use-only rights and the customer can revoke access at any time.

M3: Access Controls

  • The governance console implements role-based access control (RBAC). Compliance reviewers can view flagged events, add notes, and change status. Administrators can manage users, configure policies, and adjust settings.
  • API authentication uses API keys (for the device service and MCP component) and JWT tokens with configurable expiry (for the console).
  • All actions in the console are logged with the reviewer's identity and timestamp in an immutable, append-only audit log.
  • For Proxara-Managed deployments, operational access uses IAM roles with least-privilege policies and is logged in AWS CloudTrail.

M4: Immutable Audit Log

All compliance reviewer actions (status changes, notes, feedback, escalations) are recorded in a dedicated append-only audit log. Entries are never updated or deleted. Each entry contains the event identifier, the action taken, the actor's identity, a UTC timestamp, and action-specific details. This provides the tamper-evident evidence trail required by regulators and ensures accountability for all access to personal data within the system.

M5: On-Device Identity Vault

Identity vault tokens (the association between a semantic tag and an original value) are held in an on-device encrypted vault. Each original value is sealed under its own AES-256-GCM key derived via HKDF. The device service's mappings are not transmitted to or stored within the customer's cloud environment (the separately assessed Proxara Connect service maintains its own server-side vault there). Retiring a token destroys its key irreversibly; the original becomes unrecoverable even if a backup of the vault is later obtained. On uninstall, the entire vault is deleted.

M6: AI-Powered Classification

Proxara uses Claude Haiku 4.5 (via AWS Bedrock) for semantic classification. Semantic analysis understands context, distinguishing, for example, between a client's Social Security number and an employee's own personal information in a resume. The classification engine applies industry-specific rules (financial services, healthcare, legal, accounting) calibrated to the customer's regulatory environment.

M7: Multi-Pass Review for File Content

When employees upload files to external AI tools, the system applies a multi-pass classification:

  1. First pass: File content is extracted (supporting XLSX, CSV, PDF, DOCX, and text formats) and analyzed alongside the prompt text for PII and compliance risk.
  2. Second pass (confirmation): A secondary AI review evaluates whether the flagged content genuinely warrants compliance attention. Personal files, generic templates, and data unrelated to the firm's clients are filtered out, eliminating false positives before notifying the compliance officer.
  3. Three-tier routing: Events are classified as "critical" (push notification to compliance officer), "activity" (logged in console, no push notification), or "dismissed" (no action). Only genuinely critical events generate real-time alerts.

M8: Narrow Monitoring Scope

The device proxy's TLS interception is restricted to AI provider domains by X.509 Name Constraints in the root CA certificate and by domain matching in the proxy. The service does not access or monitor other websites, browsing history, keystrokes, or ambient data. The device agent does not intercept Microsoft 365, Microsoft Copilot, Teams, or Outlook network traffic. Non-AI traffic passes through the device's network stack untouched and is never decrypted or inspected.

M9: Employee Controls and Transparency

  • When the system identifies sensitive data in a prompt, employees are shown a confirmation overlay with individual toggles for each detected entity. Employees can accept, modify, or reject suggested redactions.
  • Employees can override redaction for specific items when they determine a detection is a false positive.
  • The sensitivity threshold is configurable, allowing the customer to balance between automated correction and employee review.
  • Customers control which AI providers are monitored and can enable or disable screening per employee.

M10: Automated Data Retention and Purge

All intercepted interactions are stored for a short, configurable retention window (default 7 days). At the end of this window, interaction records, prompt and response text, and file content are purged automatically. After purge, the supervision audit log retains metadata only (no content). The audit log is the permanent record of compliance activity. Cryptographic audit proofs are archived to S3 COMPLIANCE Object Lock for 7 years (meeting SEC Rule 17a-4(f), FINRA 4511, and NYDFS 500.6 minimums).

Where the firm has enabled an archive integration, interaction records can be forwarded to the firm's designated archive provider (Smarsh, Global Relay, or equivalent) for long-term regulatory retention before the purge window expires. That archive, not Proxara, is the firm's system of record.

M11: Sub-Processors

Proxara's primary sub-processor is Amazon Web Services, which hosts the customer's dedicated environment and provides AI classification (Amazon Bedrock, running Claude Haiku 4.5) and document text extraction (Amazon Textract). Outbound notification email is sent through Google Workspace (smtp.gmail.com). Audit anchoring uses Sigstore Rekor by default (cryptographic hashes only; no personal data). Exa is used solely for researching unrecognized MCP server capabilities (server metadata only; no employee content). Customer-connected integrations (Slack, Microsoft Teams for notifications, Google Calendar for context) are off by default and controlled by the customer. The full sub-processor list is published separately and updated with 30 days' notice.

AWS maintains SOC 1/2/3, ISO 27001, PCI DSS, FedRAMP, and HIPAA certifications. AWS Bedrock does not store model inputs or outputs; data is processed in real time and discarded.

M12: International Transfer Safeguards

Customer data is processed within the customer's selected AWS region (default: US regions). Where data is transferred from the UK or EEA to a country without an adequacy decision, the Data Processing Addendum incorporates Standard Contractual Clauses (Module Two: Controller to Processor) and, for UK transfers, the UK International Data Transfer Addendum.

M13: Employee Monitoring Disclosure

Proxara provides a customizable Employee Monitoring Disclosure Template that customers deploy to inform employees about monitoring. The device proxy surfaces a built-in notice on first use of any AI tool, which customers can customize with their firm name and compliance contact information. The notice explains what is monitored, why, what data is collected, and how employees can raise concerns.

M14: Metadata Minimization After Purge

After full text and file content are purged, the retained metadata consists of classification results (severity, risk category, data types detected) and audit trail entries. This metadata is designed to answer "was supervision active?" without retaining enough detail to reconstruct the original interaction. Risk category labels are generic ("data_sensitivity", "advice_risk") rather than content-specific. The underlying numeric risk scores are stripped server-side and never sent to the console.

M15: Root CA Security (Device Service)

The device service's root CA is per tenant: minted server-side at enrollment and delivered to each device over the authenticated enrollment envelope, so extraction of the key on one device is extraction of the firm's CA, and the risk is assessed on that honest basis. Two bounds apply. The CA certificate carries X.509 Name Constraints excluding sign-in, banking, healthcare, government, and security-tooling domains; verifiers that enforce constraints (Firefox and other NSS-based software) reject violations cryptographically, while macOS does not reliably enforce them on user-added roots, so the operating control there is the agent's runtime gate, which refuses the excluded categories before any connection is opened. The CA private key is stored in a system-protected directory readable only by the system account (file mode 0600, re-asserted on load). On uninstall, the CA is removed from the OS trust stores and all key material is deleted. The device service also verifies code signatures on update packages (macOS: Developer ID; Windows: Authenticode) to prevent supply-chain compromise.

If the agent's CA is not OS-trusted, the agent passes traffic straight through to the real origin and alerts the firm. Sites keep working; no Proxara certificate is ever presented without trust.

M16: Local Vault Data Protection

The identity vault is stored in a system-protected directory on the employee's device. Hourly cleanup removes expired tokens. On uninstall, the entire data directory is deleted. The device vault's data does not leave the employee's device and is not transmitted to the customer's cloud environment or to Proxara.

M17: MCP Observability and Governance

Proxara observes MCP activity from AI clients and redacts inspectable MCP requests with the same engine as other AI traffic before they reach a downstream server. Each observed tool call produces a signed audit event; raw payloads are never stored, only hashes and signatures. The compliance officer can classify each MCP server and can block or quarantine one through the governance console; block and quarantine decisions propagate to enrolled devices. Original values never enter the audit log, so a regulator can confirm whether a person's data was involved without the personal data being retained.

M18: Cryptographic Audit Chain

Every event is encoded in canonical form (RFC 8785 JCS for JSON records), signed with Ed25519, and linked into a per-tenant hash chain (each event references the SHA-256 of the previous event). Five-minute batches are Merkle-rooted, the root is signed, and each batch root is anchored by default to Sigstore Rekor, a public transparency log (hashes only; local recording continues if the log is unreachable). The offline proxara-audit-verify CLI confirms signatures, chain continuity, Merkle inclusion proofs, and the public-log timestamp, independently of any Proxara service. Tampering at any link breaks the chain and is detected by verification.

M19: MCP Supply-Chain Defenses

Three layers prevent a compromised downstream server from exfiltrating data: (a) tool descriptions, results, resource bodies, prompt messages, and task payloads pass through a semantic prompt-injection scanner with severity-graded actions (allow, annotate, sanitize, block); (b) a tool-call graph analysis catches multi-step patterns including read-then-exfil, enumerate-then-escalate, and leak-then-send, and surfaces them as policy signals; (c) tool descriptions are hashed on first sight and rechecked on every call so a mid-session mutation triggers a block. The component's STDIO subprocess pool validates arguments on registration to refuse any program string with shell metacharacters, user input interpolation, or unresolved variable expansion.


5. Consultation

5.1 Customer (Controller) Consultation

Customers configure the scope of monitoring (which AI providers, which employees, sensitivity thresholds) and are responsible for determining the lawful basis for processing, providing employee notice, and obtaining any required consent. Proxara provides documentation, disclosure templates, and technical controls to support customers' compliance decisions.

5.2 Employee (Data Subject) Consultation

Employees are informed of monitoring through the Employee Monitoring Disclosure and the in-product notice the device proxy surfaces on first use of any AI tool. Employees exercise agency through the confirmation overlay, where they can review, accept, modify, or reject suggested redactions for each interaction. Employees may also raise data protection concerns through their employer's designated channels.

5.3 DPO Consultation

Customers with a designated Data Protection Officer are encouraged to review this DPIA and the Data Processing Addendum as part of their vendor assessment process.


6. Compliance and Certifications

FrameworkStatus
HIPAABusiness Associate Agreement available for healthcare deployments
GDPR / UK GDPRData Processing Addendum with Standard Contractual Clauses available
CCPA/CPRAService Provider obligations documented in DPA
AWS ComplianceAWS Bedrock is SOC 2 compliant, HIPAA eligible, and GDPR-compliant. AWS maintains ISO 27001, SOC 1/2/3, PCI DSS, and FedRAMP certifications.

Proxara's security program includes internal adversarial security reviews, least-privilege IAM, private-subnet data stores, KMS-encrypted storage, MFA-gated administration, and nightly automated audit-chain verification. Independent third-party penetration testing is planned.


7. Conclusion and Residual Risk

This assessment identifies thirteen risks to data subjects arising from Proxara's processing activities. All identified risks are mitigated to Low or Very Low through the measures described in Section 4, with the exception of R3 (redaction accuracy) and R13 (MCP supply-chain), which carry residual Medium risk explained below.

Residual risks:

  • Redaction accuracy (R3) remains the primary residual risk. Semantic AI classification significantly outperforms pattern-based approaches but cannot guarantee complete detection. The multi-pass review system, employee confirmation overlay, and compliance officer review provide layered defenses. Proxara does not warrant that the service will detect all sensitive data (this is disclosed in the Master Subscription Agreement, Section 8.3).
  • Sub-processor risk (R6) is inherent in any cloud-deployed system. This risk is mitigated by AWS's compliance certifications and Proxara's single-tenant deployment model, which ensures each customer's data is isolated within a dedicated AWS account.
  • MCP supply-chain risk (R13) is the inherent risk of an autonomous agent acting through a downstream tool that may itself be malicious or poisoned. Proxara's three-layer defense (M19) reduces exposure, but the threat surface evolves with the MCP ecosystem. Customers should treat MCP server selection with the same care as any third-party dependency and review their server configuration as part of vendor onboarding.

Overall assessment: The processing described in this DPIA is necessary and proportionate to the legitimate interests pursued. The residual risks are acceptable given the mitigation measures in place and the regulatory obligations that the processing is designed to satisfy. Processing may proceed.

Next review date: June 2027, or upon material change to processing activities.


8. Contact

For questions about this DPIA:

Proxara, Inc.

28 Geary St. Suite 650 PMB 5328, San Francisco, CA 94108

Email: support@proxara.ai

Security inquiries: security@proxara.ai