Privacy Shield
Playable below - no signup
Install the detector and outbound prompts are inspected on your own hardware before they leave. You decide what happens next: block it, mask it, ask the person, or swap the real values for placeholders and put them back in the answer.
Try it below
The full security modelLive demo
This is the organisation shield as an administrator sets it: what to look for, how strict to be, what happens when something is found, and what may leave for an outside model. Then open "What happened" - a month of a fictional insurance broker's traffic, including the personal data that reached servers outside Europe because EU-only routing was left off.
The screen, the controls and the reports are the product's own. The organisation is invented - Van Dael Assurantien, the same company as the compliance demo - and so are its figures, though they add up. Changes are not saved and the demo has no server behind it.
Open the real thingFour answers to one question
Set it once per organisation. There is no single right answer - a hospital and a marketing agency should not pick the same one.
The message never leaves. The person is asked to rephrase. The strictest option, and the default.
The values are stripped and the request goes on without them. The model gets less context; you get a guarantee.
The person sees what was detected and decides for that message. Useful while a team is still learning what counts as sensitive.
Real values are swapped for placeholders like [email_1] before the request leaves, and swapped back into the answer you read. The model works on the structure of the message without ever receiving the name, the address or the account number - the option that keeps an assistant useful on real work. Enterprise.
How it works
Detection happens in a container you run, on CPU, using an Apache-2.0 licensed model - no third-party detection API sits on the default path. Dutch BSN is validated by its checksum rather than guessed at. Data coming back from a tool is scanned on the same terms as anything you type. And if a message is going to a local model the shield steps aside: nothing is leaving, so there is nothing to inspect.
Failure mode
The request is blocked. That is worth stating plainly, because the alternative - letting messages through unchecked while the guard is unavailable - is how a control like this quietly becomes decorative. Failing closed is occasionally inconvenient and always the right default for something whose entire job is to stop data leaving. Attachments too large to scan in full are reported rather than silently passed.
Read the security modelFAQ
No. It runs in a container on your own hardware, on CPU, using an Apache-2.0 licensed model. An external detector can be configured if you want one, but nothing on the default path leaves your network.
21 categories - names, addresses, dates of birth, phone numbers, email addresses, IBANs and other bank accounts, credit cards, passports, national identification numbers, medical conditions, API keys and more. Dutch BSN is validated by its checksum rather than guessed.
The request is blocked. Failing closed is the only safe default for a control whose whole job is to stop data leaving.
It adds a detection pass before the request goes out. Messages to a local model skip the shield entirely, because nothing is leaving in the first place.
The shield runs on every tier - DLP is not an upsell. The tokenise-and-restore round trip and the web-search guard are Enterprise.
Yes - the "What happened" tab in the demo above is that screen. It reports what was caught, in which kind of conversation, by whom, and which outside services your data reached. Events record the category, the direction and the action taken, but never the matched text: an audit log full of the data you were protecting is a second leak.
The fastest way to check a privacy claim is to host the thing and watch what it sends.
Open the app Talk to us