Privacy-first AI infrastructure.

← Use cases

Use AI on case files. Keep the file privileged.

Draft, summarise and compare on the real file, with the client, the counterparty and the matter masked before anything leaves your machine.

What you have

Instruct counsel for Marina Folch Moros, NIF 48023306L, in matter M-204817. Balance of EUR 200,000 payable to ES91 2100 0418 4502 0005 1332.

What the assistant receives

Instruct counsel for PERSON_1, NIF DNI_NIF_1, in matter INTERNAL_ID_1. Balance of EUR 200,000 payable to IBAN_1.

Synthetic. The reply comes back with the tokens in it and the real values are restored on your machine.

What gets masked
Client and counterparty names, national identifiers, matter and case references, addresses, contact details and bank details. Amounts stay, because the amount is usually the question.
The privilege question
A cloud redaction service has to receive the raw file first, which puts one more third party in the chain. With on-device masking the identifying details never reach anyone, so your confidentiality analysis starts from what was actually disclosed.
Consistent parties
Each person keeps the same stand-in through the document, so the assistant can tell the parties apart and the restored draft puts every name back where it belongs.

A modern practice has every reason to use AI and one good reason not to: the text of the work is the confidential part. Banning the tools moves the work to personal phones; allowing them accepts the exposure.

Masking is the fourth option. The assistant reasons about the structure of the matter without seeing whose matter it is.

What detection catches, and what still slips through, is measured and published on the benchmarks page.

What people ask first

Does using AI on masked text waive privilege or confidentiality?

That is a legal judgment for your jurisdiction, but the factual position changes: with on-device masking, the identifying details never reach the AI provider or anyone else. What leaves the machine is text about masked stand-ins. Your confidentiality analysis starts from what was actually disclosed, and with masking, the client identifiers were not.

What happens to the mapping between real names and masked tokens?

It stays on your machine with the rest of the data. Nothing derived from the document, including the mapping, is sent anywhere. Unmasking is never gated by licensing either, so text you masked remains recoverable by you even if you stop using the product.

Can opposing names and client names get mixed up in the reply?

Each distinct person or entity gets its own consistent stand-in, so the model can keep parties apart while working. On restore, each stand-in maps back to exactly one original. The tokenized mode makes this visible: you can read the masked text and check who is who before sending.
Request a demo

See it work on your own data.

Tell us what you work with and we will walk you through it on a call, on your own files. Nothing leaves your machine while we do.

Your details mask themselves as you go. That is Velum, running in this page. Press the eye to unmask. We still receive them in full.

Your address is used to reply to you, and for nothing else.