Product · Compared to the alternatives

How the ways of sanitising a bundle compare

A diagnostic bundle that has to reach a vendor is dealt with one of four ways today: someone scrubs it by hand, an archive scrubber replaces its text, a data-loss-prevention gateway stops it at the perimeter, or an option of the OEM's own collection command is relied on. Each is the right answer for some cases. This page says what each does and where it stops — by category, never by name — and then says, as mechanism, what LogVeil is being built to add.

By category

Four ways it is done today

Each category is described by what it does and by where its work ends. None is a product name, and none is ranked against another.

Hand-scrubbing

What it does

Needs no tool: an engineer, time, and knowledge of the network — which addresses matter, which hostnames encode a site, which secrets must not travel.

Where it stops

Slow, incomplete and unverifiable, and useless on binaries. A multi-gigabyte archive that nests eleven levels deep, with members nobody can open, is beyond search-and-replace — and there is no way to know what was missed.

Archive scrubbers

What it does

Replace text values consistently across an archive — the same original to the same substitute in every member — which is real work, done consistently.

Where it stops

Built for text: a binary member is outside its scope. Its work ends at the replacement — whether the output was checked, and who may read the map from original to substitute, are questions outside what it is for. And where the substitute is an arbitrary token, the subnet structure the vendor's engineer needs to reason about the case is lost.

Data-loss-prevention gateways and cloud data-protection services

What it does

Detect sensitive content in what leaves the perimeter and stop it. Common in perimeters already, well understood, and the right control for a channel that should stay closed.

Where it stops

They detect and block rather than make safe, so the case still does not move: the bundle does not go, or goes raw. A cloud-hosted service is outside the air gap by construction, and a gateway that blocks does not produce a bundle that can be sent.

OEM-native options

What it does

An OEM's collection command may offer options of its own; what they mask is the OEM's documentation to state, and LogVeil is designed to run on what comes out.

Where it stops

Whatever such an option masks, the bundle still has to be judged as a whole before it leaves, and that judgement — what may go out, under whose rules, with what record — is the sender's own.

The mechanism

The mechanism LogVeil is being built to bring

What LogVeil is designed to do, each part badged with its status and linked to its page.

Structure-aware, whole-bundle

in development

LogVeil understands the anatomy of the bundle — every member, every nested archive, every filename and header — and has no file-size ceiling.

Ingest, in depth →

Your policy, your dictionary, your key

in development

The customer writes the rules and holds the key; Zindagi never sees either.

The policy and the key →

Verified — and honest about what isn’t

in development

A separate verification stage re-scans the output with independent scanners, fails closed, and signs an attestation that also says what is not claimed.

The attestation, field by field →

Reversible under control

in development

When the TAC replies about a masked address, your engineer can translate it back — and nobody else can.

Reversal, in depth →

Built for the air gap

in development

An offline kit for your own VMs; nothing phones home; AI is optional, off by default, and never touches the result.

The offline kit →

The limits

Where LogVeil stops

These are commitments, not omissions. LogVeil is not a data-loss-prevention gateway, a SIEM, a log pipeline or a ticketing system. It is not a general document-redaction service; document formats are handled only insofar as they appear inside OEM bundles. It is not a cloud service — a hosted instance is a demonstrator on synthetic data only. It makes no claim of certainty that nothing sensitive remains; the attestation is the product’s honesty mechanism. And there is no automated upload to OEM support portals in the first release.

It is also not finished — the scope note above says what the engine does today. It does not replace a gateway: a data-loss-prevention control that watches every channel stays in place, and LogVeil is designed to sit behind it on the one channel that has to stay open. It does not decide for you: the release decision — what may go out, under whose rules, with what record — stays with you, and the engineer still decides what is sent. And it is not a substitute for an OEM option where one exists; the two are used together.

Status, and the next step

LogVeil is in development. An early-access programme opens after our first field trial.

Request early access