AI without the exposure

Your team keeps using AI. Personal data stops leaving the building.

A gateway that sits between your people and any language model: it strips names, contacts and identifiers before the request leaves your perimeter and restores them in the answer. Staff work exactly as before; the compliance question has a documented answer.

1 line
to switch a service over
an OpenAI-compatible endpoint — applications need no rewrite
3 layers
of detection
structured identifiers, named entities, and a model-based safety net
0
content stored in the audit log
who and when is recorded; what was written is not
ÆTHER — data gateway · illustrative data
ÆTHERdata gateway · request pathrunning · 184ms01_requestcontract textnames · numbers02_pseudonymise3 detection layerstokens issued03_modelhosted or localno personal data04_responsetokens resolvedreadable answerlog14:02:11service · legal-assistantentities masked: 14ok14:02:11model · eu-hostedpayload: no personal dataok14:02:12response · restoredtokens resolved: 14ok14:03:47service · crm-summaryentities masked: 31okaudit log stores who and when — never the content

Interface generated in code · figures illustrative

WHY IT EXISTS

What it removes

Shadow AI is already here

Contracts, correspondence and CRM exports are pasted into chatbots because it is faster. The company finds out during an audit.

Banning it costs more than it saves

A blanket ban moves the same behaviour onto personal devices, where you have no visibility at all.

Nobody can size the exposure

How many requests leave per day, carrying what, from whom — there is no number to put in front of a board.

Local-only is expensive

A fully self-hosted stack means hardware, staffing and a visible drop in answer quality.

WHAT IT INCLUDES

Inside the engagement

HOW IT RUNS

From access to outcome

01

Map

Where AI is already used and which data reaches the prompt.

02

Deploy

Gateway installed in your perimeter or EU cloud, keys issued per service.

03

Switch

Services repointed to the gateway; categories tuned to your processes.

04

Prove

Processing policy, audit log and evidence pack for the regulator or your client's security team.

ENGAGEMENT

Scope and price

Indicative starting points. The number is fixed after the assessment, and it does not move afterwards.

+ €900 / month
Team
from €9,000

One or two services and up to thirty people. The fastest way to close the common case.

  • gateway in your perimeter
  • standard entity set
  • up to 100,000 requests a month
  • audit log
  • 30 days of tuning included
+ €1,800 / month
Company
from €20,000

Every internal service and workstation, own category rules, security reporting.

  • unlimited connected services
  • categories tuned to processes
  • keys and limits per department
  • reporting for the security team
  • evidence pack for audits
  • priority support
+ from €3,000 / month
Closed loop
from €45,000

No external services at all — models run on your own hardware.

  • local models on your hardware
  • hardware sizing and setup
  • sector-specific requirements
  • internal system integration
  • named engineer
TIMELINE

What happens week by week

Week 0

Assessment

where AI is already used

what data reaches prompts

test on your own documents

go / no-go

Week 1

Install

deployment in the perimeter

access keys

baseline categories

test traffic

Week 2

Switch over

services repointed

category tuning

log and limits

a week under observation

Week 3

Hand-over

policy documents

team training

sign-off

30 days of tuning

QUESTIONS

Asked before
every start

The productivity stays, the exposure goes, and there is a document to hand the auditor.

OpenAI-compatible proxyFormat and checksum detectionMultilingual named-entity recognitionPer-service API keys and rate limitsHosted, EU-resident or local modelsAudit log without payloads
Does this make us GDPR compliant?
It removes the transfer of personal data to third-party models and gives you the processing record, log and policy to show for it. Compliance is broader than one control — but this is the control most companies are missing.
Will answers get worse?
No. The model still receives the full context, minus the identifiers it never needed. In practice quality is unchanged.
What about the EU AI Act?
The gateway is where logging, model selection and human oversight are enforced — the plumbing those obligations require, in one place instead of in every application.
NEXT STEP

Start with the assessment

Free, and yours to keep. We look at your own data or site, show what we found, and only then talk about scope.

Request the assessment