Your team keeps using AI. Personal data stops leaving the building.
A gateway that sits between your people and any language model: it strips names, contacts and identifiers before the request leaves your perimeter and restores them in the answer. Staff work exactly as before; the compliance question has a documented answer.
Interface generated in code · figures illustrative
What it removes
Shadow AI is already here
Contracts, correspondence and CRM exports are pasted into chatbots because it is faster. The company finds out during an audit.
Banning it costs more than it saves
A blanket ban moves the same behaviour onto personal devices, where you have no visibility at all.
Nobody can size the exposure
How many requests leave per day, carrying what, from whom — there is no number to put in front of a board.
Local-only is expensive
A fully self-hosted stack means hardware, staffing and a visible drop in answer quality.
Inside the engagement
Drop-in endpoint
An OpenAI-compatible address inside your network; applications change one configuration line and keep working.
Pseudonymisation on the way out
Names, contacts, addresses, tax and document numbers replaced by tokens before the request leaves.
Restoration on the way back
Tokens are resolved in the response, so the person reading it sees a normal document.
Structured identifier layer
Account, card, VAT and document numbers detected by format and checksum, independent of language.
Model choice
One entry point for hosted, EU-resident and fully local models — switched by configuration, not by rewriting code.
Audit and limits
Per-service keys, rate limits and a log of who called what and when, with no message content retained.
From access to outcome
Map
Where AI is already used and which data reaches the prompt.
Deploy
Gateway installed in your perimeter or EU cloud, keys issued per service.
Switch
Services repointed to the gateway; categories tuned to your processes.
Prove
Processing policy, audit log and evidence pack for the regulator or your client's security team.
Scope and price
Indicative starting points. The number is fixed after the assessment, and it does not move afterwards.
One or two services and up to thirty people. The fastest way to close the common case.
- gateway in your perimeter
- standard entity set
- up to 100,000 requests a month
- audit log
- 30 days of tuning included
Every internal service and workstation, own category rules, security reporting.
- unlimited connected services
- categories tuned to processes
- keys and limits per department
- reporting for the security team
- evidence pack for audits
- priority support
No external services at all — models run on your own hardware.
- local models on your hardware
- hardware sizing and setup
- sector-specific requirements
- internal system integration
- named engineer
What happens week by week
Assessment
where AI is already used
what data reaches prompts
test on your own documents
go / no-go
Install
deployment in the perimeter
access keys
baseline categories
test traffic
Switch over
services repointed
category tuning
log and limits
a week under observation
Hand-over
policy documents
team training
sign-off
30 days of tuning
Asked before
every start
The productivity stays, the exposure goes, and there is a document to hand the auditor.
Does this make us GDPR compliant?
Will answers get worse?
What about the EU AI Act?
Start with the assessment
Free, and yours to keep. We look at your own data or site, show what we found, and only then talk about scope.