Data governance middleware

Filter what matters.
Discern what's real.
Deliver what's approved.

Filcerne sits between your source systems and everything downstream. Fields an administrator hasn't approved don't move forward — they're held back, logged, and never reach the other side.

Built for banking · retail · healthcare · insurance

How it works

Five stages between your data and everyone else's.

Every record takes the same path, whatever format it arrived in and wherever it's headed.

Receive

Records arrive from any of 17 sources — a Kafka topic, an S3 drop, a database query, a REST call.

Reconcile

When one entity ID arrives under two near-matching spellings of a name, both records still move. The discrepancy goes to a report you can act on.

Validate

Your business rules run. Missing a required field, or resubmitting an unchanged profile, produces a coded rejection.

Filter

Every field is checked against the allowlist. Approved fields pass, PII and PCI columns encrypt, everything else is held.

Deliver

Cleared fields go downstream in whatever format that system needs — CSV, Excel, XML, Parquet, JSON.

Where it sits

Access governance decides who can query a column. Filcerne decides what leaves the building.

Both matter. They are not the same control, and they do not sit in the same place.

The usual approach

Access governance platforms

  • Enforces at query time — an analyst asks for a column and is allowed or refused
  • Lives against cloud data platforms: Snowflake, Databricks, BigQuery, Redshift
  • Assumes the data has already landed somewhere it governs
Filcerne

Governs data in transit

  • Enforces as the record moves — between a source system and whatever consumes it
  • Lives in the integration layer: Kafka, Lambda, SFTP drops, REST calls, LDAP, database extracts
  • Acts before the data reaches the other side, so an unapproved field is never transmitted at all

If your exposure is an analyst over-reaching in a warehouse, buy an access governance platform. If it is a nightly feed quietly carrying nine fields a downstream partner was never approved to receive, that feed never touches a query engine — and that is the gap Filcerne is built for.

Sources and destinations

Arrives as JSON. Leaves as Excel. Or the reverse.

Input format and output format are set separately, so neither side has to change to work with the other.

Reads from

JSONJSONLXMLCSVTSVYAMLExcelParquetAvroFixed-widthSQLMongoDBLDAPS3KafkaKinesisREST / GraphQL

Writes to

JSONJSONLCSVTSVXMLYAMLExcelParquet

Runs as

AWS LambdaHTTP servicePython libraryCLI / batch job

What it does

Control at the field, not the file.

Most tools decide whether a whole record moves. Filcerne decides column by column.

Approved fields only

An administrator lists what may leave. Anything not on that list is held back by default — including fields nobody knew were in the feed.

PII and PCI stay encrypted

Flag a column and it travels as ciphertext. If the key is ever missing, the field is held rather than sent in the clear.

Discrepancies surfaced, not guessed

Near-matching names under one ID are flagged for reconciliation. Filcerne never picks a winner or rewrites a value — the source systems stay the record of truth.

Rejections you can answer for

Every blocked record gets a code and a plain-English reason, searchable by entity, name, or date for 30 days.

Built for regulated data

Designed so the safe path is the default one.

Every choice assumes the data is sensitive and the configuration might be wrong.

Deny by default

Fields are held unless explicitly approved, so a new column upstream can't quietly start flowing downstream.

Fails closed, not open

A field marked for encryption with no key available is withheld — a misconfiguration can't turn into a leak.

Logs hold no secrets

The audit trail records field names and salted hashes, never the values, so the log itself isn't a second copy of your PII.

Encrypted in transit

Plain-HTTP destinations are refused outright. Downstream endpoints have to be TLS.

Separated access

Reading data is one permission. Reading logs, exporting reports, and decrypting values are another.

Where we are today

Filcerne is early. We are pre-SOC 2 and run pilots on masked or synthetic data while certification and independent penetration testing complete. We would rather tell you that now than have your security review find it.

Evidence on demand

Export what was delivered, rejected, held, or flagged for reconciliation as CSV or Excel — for an auditor, a regulator, or a Monday morning question.

See it run against your own data.

About 30 minutes. Send us your field names — no data — and we’ll show you exactly what would and wouldn’t reach your downstream systems.