# Glossary

Canonical: https://careinstitute.ai/glossary/
Published: 2026-09-25
Author: CARE Institute
Code licence: Apache 2.0 (https://github.com/CAREInst)

**Privacy routing.** Privacy routing decides where an AI agent may send each request. It has three steps. Classify each request by how sensitive it is. Route it only to models cleared for that class, on a device or in the cloud. Audit every choice so a reviewer can check it later.

**Classify.** We label each request by how sensitive it is before it moves: health data, personal data, privileged, classified, or general.

**Route.** We send each request only to models cleared for its label, then pick the best one on cost and speed.

**Audit.** We log every choice so a reviewer can check what went where, and why.

**Sensitivity classes.** Health data, personal data, privileged, classified, or general.

**Cleared set.** The models cleared to see a request’s data.

**Held.** A route the router does not use, because that model is not cleared for the request’s class. The audit log records it.

**Re-token threat.** A query that is safe under one model's token scheme can leak data under another's, because the token cuts land in different spots.

**Governance overhead.** How much time governance checks add to each API call.

**Criticality routing.** Sort demand by what’s actually at stake before deciding who gets served, and at what price.
