Work with the latest models.
Without exposing
your sensitive data.

ChatSecret is a privacy airlock that sits between you and the large AI models. It automatically spots sensitive data — names, addresses, identifiers, personal data — masks it before sending, then restores the real values in the reply.

You harness the full power of Claude or ChatGPT on confidential files, without a single real value ever leaving your perimeter. nLPD-compliant, Swiss or fully local hosting.

ChatSecret

Professions where confidentiality
is non-negotiable.

ChatSecret is built for professionals who want the power of the large AI models without ever compromising the secrecy of their files.

Architects

Specifications, correspondence, client files — have AI draft and analyse without disclosing names or addresses.

Lawyers & Notaries

Contracts, deeds, court documents — AI works on the content, the identity of the parties stays with you.

Trust companies

Balance sheets, returns, accounting records — delegate the analysis without exposing your clients' figures or names.

Physicians

Reports, letters, summaries — AI assists you, your patients' health data never leaves in the clear.

Banks

Compliance, KYC, regulatory reports — leverage the large models while keeping your data sovereign and masked.

Public authorities

Minutes, letters, decisions — draft and summarise with AI without transmitting citizens' data.

An airlock that protects
every piece of data.

Automatic detection

What is sensitive is spotted

ChatSecret automatically spots names, roles, addresses, identifiers, amounts and sensitive data under the nLPD — before anything is sent.

nLPDMulti-categoryMultilingual

Reversible masking

Nothing real leaves

Each sensitive value is replaced before sending. The external model only ever sees anonymised, coherent, usable text.

ReversibleCoherent

Faithful restoration

The real values come back

On return, ChatSecret reinjects the original values locally. You get a complete, readable reply — as if the AI had known everything.

AutomaticTransparent

Hard block

Some data never leaves

The most sensitive categories — identifiers, coordinates, classifications, health data — are blocked: they never cross the border, whatever the setting.

nLPDSovereign

The vault stays with you

The mapping never leaves

The table linking each token to its real value — the vault — never leaves your workstation. Without it, the masked text is useless to a third party.

LocalSovereign

Local or external

You choose at every exchange

Handle everything on the workstation with a local model, or delegate to a large external model. Switching is explicit, and local mode never contacts the outside.

ControlTraceable
On the workstation

Local model

A model installed on your workstation handles the request end to end. No external connection, no data leaving — the strictest guarantee.

  • Nothing leaves the workstation
  • Works offline
  • Full infrastructure control
External relay

Large model, masked

For demanding tasks, ChatSecret relays to Claude or ChatGPT — but only the masked version. The real values stay with you and are restored on return.

  • Only masked text is sent
  • Review and check before sending
  • Automatic restoration on return

Open.
Transparent.
Auditable.

Built on open, auditable technologies: you stay in control of what goes onto the network. No black box.

01

Detection in context

ChatSecret understands context and catches what simple rules miss — a lone surname, a lone first name. The multiple forms of a single referent — a person, but also a unit or an acronym — are grouped together, across the four national languages and English.

02

Local vault

The token ↔ value mapping stays in session, on the workstation. It is never transmitted and can be corrected by hand.

03

Leak check

Before every send, a check verifies that no sensitive value remains in the clear. Blocked categories never leave.

04

Traceable end to end

Every exchange with the outside is checked and logged. You know exactly what leaves your perimeter — no black box.

0

real data transmitted to the external AI

100%

of sends pass through the leak check

nLPD

sensitive categories blocked by default

2

modes: on the workstation, or masked external relay

Discover

See ChatSecret
in action

Schedule a personalised demonstration. We'll show you how ChatSecret masks, delegates and restores — without ever exposing your data.

Request a demo

Everything you need
to know.

No. Sensitive values are masked before anything is sent, and the vault linking each token to its real value never leaves your workstation. In local mode, no data leaves at all. In external mode, only the masked text is transmitted.

The leading models on the market — Claude (Anthropic) and ChatGPT (OpenAI) — via their APIs. ChatSecret sits between you and the model: you keep the power, without handing it your real data.

Coherent text where each sensitive value is replaced by a plausible substitute value. It reasons normally, but knows no real identity, address or identifier.

ChatSecret is built for compliance: personal data is not transmitted in the clear, the most sensitive categories (health, identifiers, coordinates) are blocked on principle, and every exchange is logged. You keep control and traceability.

Yes. A local model installed on the workstation can handle requests end to end, with no external connection. You only switch to a large external model when you explicitly decide to.

The operator stays in control: the vault is editable. You can correct a substitute value, remove a misclassified item or adjust a value before sending. Nothing leaves without your validation.

Yes. Before anything is sent to an external model, you can review and correct the masked text: adjust a substitute value, remove a misclassified item, confirm. Nothing leaves your perimeter without your validation.

Let's talk about your project

Schedule a demonstration or ask us your questions. We'll get back to you within 24 hours.