Documentation

Use AI without exposing your data.

ChatSecret is a privacy airlock placed between you and the leading AI models. This documentation explains, without jargon, what it does, what it protects and how it is deployed at your premises.

VAULT (stable, local) Real value → Marc Rossier Randomisation before each send SEND #1 — 09:14 "…letter for Luc Favre…" coherent everywhere WITHIN this call SEND #2 — 09:15 "…letter for Jean Dupont…" same person, different substitute
The same real value gets a different substitute on every send: two exchanges can never be cross-matched.

What is ChatSecret?

The leading AI models are powerful, but entrusting them with confidential files raises a problem: your data leaves your perimeter. ChatSecret resolves this dilemma — you keep the power of AI without handing it your real data.

The power of AI

You keep using the best models on the market to draft, analyse and summarise your professional documents.

Without exposure

Names, addresses, identifiers and personal data are masked before anything is sent. The external model never sees your real values.

At your premises

The mapping between masked data and real data stays on your device, under your control.

How your data is protected

ChatSecret steps in at every exchange, in four stages. The operator stays in control from start to finish.

1

Detection

ChatSecret spots the sensitive data in your request: names, roles, addresses, identifiers, amounts, personal data — across the four national languages and English.

2

Masking

Each sensitive value is replaced before sending. The text passed to the external model stays coherent and workable, but contains no real data.

3

Review

Before anything leaves for the outside, you can check and correct what will be sent. Nothing leaves your perimeter without your approval.

4

Restoration

On receipt, the real values are reinjected locally. You get a complete, readable answer, as if the AI had known everything all along.

You real data ChatSecret masks on the way out · restores on the way back vault · never leaves External AI sees the masked text border real masked masked response restored
At a glance: your real data is masked before the border, then restored on the way back.

What the external model sees — and does not see

The external model works on text that is useful but anonymised. It reasons normally, without ever knowing your real data.

What it receives

  • Coherent, workable text
  • The structure and meaning of your request
  • Plausible substitute values

What it never receives

  • The real names, addresses and identifiers
  • The mapping that would allow them to be recovered
  • The most sensitive categories, never transmitted
ON YOUR DEVICE — SOVEREIGN · Message in the clear · Mapping vault · Local model, on the device · Restoration of the real values Marc Rossier · 756.9217.0652.93 never transmitted in the clear Anti-leak + hard block EXTERNAL — OFF THE DEVICE · Large model (Claude / ChatGPT) · Sees only the masked text · No real identity · Masked response in return masked text, no identity or realistic substitutes masked → ← restored
On your device, everything stays real and sovereign. To the outside, only the masked text travels.

Where ChatSecret is installed

Two modes depending on your level of requirement, without your data ever leaving Switzerland.

On your servers (on-premise)

Installed on your own infrastructure, with no internet connection required. For the most sensitive environments, everything can be processed on the device, with no outbound traffic at all.

Swiss sovereign cloud

Hosted with a Swiss provider, data stored in Switzerland. The convenience of a managed service, with data sovereignty.

Who it is for

ChatSecret is aimed at professions where confidentiality is not negotiable.

  • Lawyers, notaries and fiduciaries — contracts, deeds, accounting records
  • Doctors and healthcare professionals — reports, letters, summaries
  • Banking and finance — compliance, KYC, regulatory reporting
  • Architects and public administrations — case files, correspondence, decisions
  • SMEs and large companies — internal AI use on confidential data

Compliance & sovereignty

ChatSecret is designed for compliance: personal data is not transmitted in the clear, the most sensitive categories are blocked as a matter of principle, and every exchange with the outside is logged. You keep control and traceability, within the framework of the nLPD (revised Swiss Data Protection Act) and the GDPR.

Worth knowing

ChatSecret sharply reduces the exposure of your data, but it does not turn a confidential document into a public one: the content remains sensitive even once the names are masked. That is why review by an operator remains recommended before anything is sent, and why we speak of pseudonymisation — not absolute anonymisation.

Want to see ChatSecret on your own files?

Book a personalised demonstration. On your own cases, we show you how ChatSecret masks, delegates and restores.

Request a demo