Protect shopper data and keep AI costs bounded
Online retailers combine some of the most sensitive consumer data with the highest and spikiest AI traffic anywhere. Igris protects payment and personal data at the proxy layer, holds AI cost within its allocation during Black Friday and flash sales regardless of traffic, and generates the PCI DSS, GDPR, CCPA, and DPDP Act evidence every review requires.
AI Product Recommendations
An ecommerce platform that generates personalized product recommendations through LLMs processes customer purchase histories continuously. Every prompt that includes an identifiable customer record and reaches an external LLM provider without redaction is a potential GDPR Article 5 data minimization violation for EU shoppers, a CCPA consumer data exposure for California residents, a DPDP Act 2023 breach for Indian customers, and a PCI DSS adjacency risk when order history contains card-adjacent references. During Black Friday, Cyber Monday, and flash sale events, recommendation call volume can spike by orders of magnitude within minutes. Without rate limiting at the gateway layer, a traffic surge that the product team celebrates becomes a billing event that the engineering team discovers after it is over.
Igris Guard PII redaction policies strip customer identifiers from recommendation prompts before they leave the network — purchase history customer IDs, email addresses, and delivery addresses embedded in order context are redacted automatically, enforcing GDPR Article 5, CCPA, and DPDP Act 2023 obligations at the call level. Rate limiting on the recommendation pipeline's connection absorbs Black Friday traffic surges within the defined allocation, preventing runaway spend regardless of how high demand climbs. Igris Lens tracks cost per recommendation model, giving the product and finance teams the data to evaluate model ROI.
Customer purchase history is protected by a technical enforcement control on every recommendation call. The recommendation pipeline's cost is bounded during peak events regardless of traffic volume. When the post-Black-Friday budget review asks what the AI personalization cost on the busiest day of the year, Lens has the per-model answer ready.
AI Customer Service for Orders
Customers contacting an order support AI share sensitive data naturally: order numbers, shipping addresses, full names, email addresses, and partial payment card details appear in support conversations without prompting. Two distinct risks operate at the same time. The outbound risk: every piece of PII that reaches an external LLM without redaction is a PCI DSS scope event, a GDPR Article 5 violation for EU customers, a CCPA consumer data exposure for California residents, and a DPDP Act 2023 breach for Indian customers. The response risk: a model that incorporates context from one customer's session into another's response is the architectural failure mode of any multi-session support bot without response-level inspection. One customer receiving another's order status or shipping address is a data breach notification event.
Igris Guard content guards redact order numbers, credit card references, and shipping addresses in every inbound customer message before the prompt reaches the LLM. Response inspection applies the same policy to everything the model returns — catching any PII that re-surfaces in a response before it reaches the customer. Igris Lens incident clustering identifies systematic bot behaviour problems as a single actionable incident rather than scattered individual alerts. The full audit trail records every interaction, every redaction event, and every policy enforcement action.
Customer PII is redacted before it reaches the LLM on every support interaction. No customer receives another customer's data in a response. Systematic bot problems surface as clustered incidents before they affect hundreds of conversations. When the PCI QSA asks about AI handling of payment-adjacent data in the customer support channel, the answer is a governance log.
AI-Powered Search and Discovery
Semantic search over a product catalog of millions of items compounds cost fast. The first failure mode: using premium conversational models for routine single-intent queries where an economical embedding model produces functionally identical results at a fraction of the cost. The second failure mode: a search index rebuild process whose loop termination misconfigures silently generates millions of LLM calls against the full catalog before anyone notices. The first signal is not an alert — it is an anomalous provider invoice.
Igris Guard model restriction policies route routine search embedding calls to economical models by configuration, reserving premium conversational models for queries requiring language understanding. Token limits prevent catalog-scale data dumps from being passed as prompt context. Igris Lens anomaly detection fires when call volume breaks the expected baseline — catching a catalog rebuild bug, a pagination loop, or a retry amplification pattern before it generates millions of unintended calls. Per-model cost tracking gives the engineering team the data to verify that model routing is producing the cost outcomes the policy was designed to create.
Routine searches run on economical models because the policy enforces it. A catalog rebuild bug announces itself in a Lens anomaly alert within minutes — not in next month's invoice. The monthly AI spend report shows cost per query type rather than a single opaque line item.
AI Personalized Marketing and Email Campaign Automation
Email marketing that uses LLMs to generate personalized content processes customer profiles that are among the richest PII collections in any ecommerce business. Every customer profile passed to an external LLM without redaction is a GDPR Article 6 lawful basis question, a CCPA consumer rights exposure for California customers, a DPDP Act 2023 consent obligation for Indian customers, and a PCI DSS adjacency risk when order history includes card brand or transaction references. At batch campaign scale — a million customer profiles processed in a single generation job — that is a million individual data handling events, each ungoverned at the prompt layer.
Guard PII redaction applies to every customer profile prompt before it reaches the LLM, stripping direct identifiers while preserving the behavioural signals the model needs to generate relevant personalisation. Rate limiting prevents a batch campaign job from exhausting its provider allocation in a single run. Igris Lens tracks cost per campaign. The audit trail records every customer profile processed, every redaction applied, and every model used — satisfying GDPR Article 30 records of processing activities and CCPA data processing transparency requirements.
Campaign personalisation runs at batch scale with enforced data minimisation on every customer profile. GDPR, CCPA, and DPDP Act obligations are addressed at the prompt layer. The campaign spend report shows what each AI-generated campaign actually cost to produce.
Personalize at scale without the exposure
See how retailers redact shopper data on every call, route queries to the right model by cost, and cap spend through peak events.