App icon PrivatPrompt Solution 07 · PrivatPrompt

The model sees the task, never the identity

PrivatPrompt is the gateway between your applications and every external language model. Every API call in the organisation has to pass through it: people, companies, addresses, account numbers and identifiers are replaced by placeholders on your infrastructure before the prompt leaves the house. The answer comes back, is translated into the real values and checked for usefulness. The mapping never leaves your network.

The provider keys sit in the gateway alone, and the applications know only the gateway. Sanitisation is therefore not a choice left to the individual, it is a property of your infrastructure: the performance of the best frontier models, without customer data ending up in someone else's data centre.

01 · What the solution delivers

Neutrality of data · as a mechanism, not as a rule

Most policies on AI use rest on trust: staff are asked not to enter customer data, developers are asked to keep it in mind. PrivatPrompt replaces the policy with a construction that takes effect before every call. The technical term for it is prompt sanitisation: a prompt is cleaned up before a model sees it, and the answer becomes usable only once it has been translated back.

Sanitisation on your own infrastructure

People, companies, places, addresses, email, phone, IBAN, AHV number, credit card, access credentials. Swiss formats with their own detectors, identifiers with a checksum. Detection, masking and mapping stay inside your network.

Mandatory, not optional

The gateway speaks the usual interfaces of the providers. Applications, agents and automations point at it instead of at the provider, the access keys sit there alone, the direct route out is blocked. There is no call that bypasses sanitisation.

Choose model and provider freely

Per application: a frontier model through the provider's API, a provider operating in Switzerland, or a model in your own data centre. A switch changes nothing in the applications, only the mapping in the gateway.

Rule set per use case

Customer correspondence, contract review, code, free text: every profile settles how strictly masking applies and what must never go out. The answer translated back is checked for fit, and the rule set learns when an external model is not worth it for a task.

02 · The interface

Three zones: original, levels, answers

At the workplace the app shows what the gateway does: on the left the original prompt with entities marked in colour, in the middle the history of the masking levels, on the right the answers per round. For every API call from an application the same history sits in the job log. Every relaxation is a visible, logged decision.

Figure 1: One job with two rounds, from strict masking to a fitting answer
PrivatPrompt · Job 0412
Backend Frontier model · API Thinking level medium Profile Answer an email · 84 % Sanitiser Passthrough Web
Original promptZone 1
Draft a reply to Martina Keller at Nordwind Solutions AG in Winterthur: we accept the quote. The invoice goes to CH93 0076 2011 6238 5295 7, queries to [email protected]. Sender: Alpsteiner Technik.
Sent as Company A (a customer) · Rule: company → enriched · Origin: round 2 · Level L2
The name stays hidden, the role becomes readable.
Person Company, place Identifier own identity, stays visible
Level historyZone 2
  1. L3 · StrictAll five entities sent as placeholders.
  2. Query from the model«Who is Person 1?» Fit 0.41. Type at fault: company without context.
  3. L2 · Company enriched«Company A (a customer)», person and identifiers stay masked.
  4. Answer fitsFit 0.86, references resolved.
Most that was disclosed: L2. 1 company as a category with a role, 1 place sent. Name, email, IBAN: in no round.
AnswersZone 3
Round 1L3Query about a placeholder
Before I can answer: who is Person 1, and how does Company 1 relate to you?
Round 2L2Fit 0.86 · judge: good
Dear Ms Keller
Thank you for your quote. We are glad to accept it and look forward to working with Nordwind Solutions AG. Please send the invoice to CH93 0076 2011 6238 5295 7, queries reach us at …
ApplyFitsDoes not fitRelax one levelAnswer locallyTo knowledge base
Zone 2 is the bookkeeping of disclosure: whoever wants to know what the external model actually saw reads it there. Highlighted in green in zone 3 are the places where the core put the real values back in. Names, companies and account numbers in the example are fictitious.
03 · The process

Six steps · one of them outside the house, and that one masked

Detection, masking, translating back and checking run inside your network, at the workplace on your own machine, for applications on the server of the gateway. Only the masked version reaches the language model. What it returns is made readable again before it is delivered.

Figure 2: From the prompt to the checked answer, with processing locations
Six-stage process: detect, mask, ask, translate back, check, relax or hand over; only the third step leaves the house, and it does so masked 010203 040506 Detect Mask Ask Translate back Check Relax / hand over People, companies andidentifiers in theprompt, Swiss detectors Placeholder per entity,mapping table storedlocally only The chosen modelreceives only themasked version Placeholders in theanswer become realvalues again Guard rails and localjudge: does the answerfit the task? One level lessmasking, or applythe answer Runs on your infrastructure Only step outside the house — the masked version Loop if the fit is missing, at most three times The mapping between placeholder and original value never leaves your network — no provider learns who your customers are.
If step 5 comes out negative, the loop runs again with one level less masking, at most three times. The lowest level always keeps account numbers, identifiers and access credentials masked. The route entirely without masking is never the result of the automatic process, but an explicit decision, preceded by a report of what would be disclosed.
04 · The masking ladder

As much masking as needed, as little as possible

Too much masking takes the context away from the model, too little gives data away. The ladder settles this in levels: it starts strict and relaxes only the type the answer fails on. For applications the rule set fixes the level per use case; at the workplace the person writing the prompt decides, within the same limits.

L3Start

Strict: everything as a placeholder

People, companies, places, addresses, email, phone, account numbers, AHV numbers, credit cards, access credentials. The model sees a category and a number, nothing else. For many tasks that is enough already.

L2Relaxed

People and identifiers stay masked, companies gain context

Companies and places become a category with a letter: «Company A», «Place B». On request enriched with the role from your knowledge base: «Company A (a customer)», «Person A (head of purchasing at Company A)». The name stays hidden, the task becomes solvable for the model.

L1Floor

Identifiers only

Email, phone, IBAN, AHV number, credit card and access credentials stay masked, everything else goes out in plain text. The automatic process never goes below this level. If it reaches no fitting answer, the rule set reports the limit and names the ways out: answer locally, rephrase the prompt, or deliberately without masking.

L0Deliberate

Passthrough: without masking, after a report

The prompt goes out unchanged. For applications only where the rule set expressly allows it for that use case, never at the request of the caller; at the workplace only after the gateway has shown what it detected in the prompt. Intended for tasks with no personal data: public texts, general questions, research with web access. Web access is permitted here only, because a search query would otherwise give away the masked details.

Version of the same valueWhat the model seesWhat is disclosed
Placeholder‹ORGANIZATION 1›Nothing
Category«Company A»Category and distinguishability
Category with role«Company A (a customer, mechanical engineering)»Role and business relationship, never the name
Plain text«Nordwind Solutions AG»The value itself, only if the rule set allows it for this type
05 · Why this makes the difference

Neutrality of data: a precondition, not an extra

The strongest models run in data centres that belong to someone else. Whoever used them has paid with customer data so far. Masking separates performance from identity, and for most of a company's data that is no option but the condition.

Frontier models without data leavingThe performance of the best models for contract questions, customer correspondence and analyses, without names and identifiers leaving the house.
The policy becomes a mechanism«Do not enter customer data» is a guideline. An application that can reach the provider only through the gateway is a construction. It holds on a Friday evening too, and in every script someone wrote two years ago.
Provable what was disclosedEvery job logs the lowest level that was sent and the types that were relaxed. Never the values themselves.
One key, one placeThe provider keys sit in the gateway alone. No key in applications, in scripts or with staff, no shadow access that nobody knows about any more. Changing provider is an entry in the gateway, not a change to the application.
Fit instead of flying blindA masked answer is only useful if it fits the task. The local check says when that is not the case, and when an external model is not worth it for a task at all.
Honest limitsMasking is pseudonymisation, not anonymisation. Industry, place and size together can make a company recognisable. The detection rate is measured, not promised; account numbers and identifiers are verified by checksum.

Data handling

Detection
On your infrastructure, with no connection to the outside
Mapping table
Inside your network, encrypted, with an expiry date; never leaves it
Provider keys
In the gateway only, never in applications or with staff
Jobs and answers
A log of the disclosure per call; contents deleted automatically after a set period
Fit check
A model inside your network, or masked through the provider; never with plain text
Language model
Selectable per application: a frontier model through the provider's API, a provider operating in Switzerland, your own data centre

No additional cloud service in between, no copy of your prompts at an intermediary. The contract with the provider stays your contract.

The question is no longer whether your staff use frontier models. They do. The question is what leaves the house, and whether anyone can say what it was.
06 · Access

Three ways in, one core

The core runs as a service on your infrastructure. For applications it is the gateway that no route gets past. For assistants it is a tool, for the workplace an app.

Figure 3: The gateway on the company network, no call bypasses the sanitiser
Applications, agents, automation platforms and workplaces call the gateway only; the gateway holds the provider keys and calls a frontier model, a provider operating in Switzerland or your own data centre; the direct route from the applications to the provider is blocked YOUR NETWORK OUTSIDE THE HOUSE Applications, scripts Agents, workflows AI assistants (MCP) Workplace app GATEWAY · PRIVATPROMPT Sanitise, rule set per application Provider keys, here only Translate back, check the fit Log of the disclosure per call Speaks the provider interfaces unchanged masked only Frontier model, provider's API Provider operating in Switzerland Model in your own data centre with a data processing agreement data stays in the country never leaves the house at all direct route blocked
Enforcement is a question of the network and the keys, not a question of trust: the applications receive only the address of the gateway and an access credential for it. The provider keys are known to the gateway alone, and the direct route to the provider addresses is blocked in the network. A call that sets out to bypass sanitisation does not arrive.
Access A

As a gateway on the company network

Applications, agents, automation platforms and chat tools call the gateway the way they would call the provider itself, through the same interface. The gateway sanitises, calls the provider with its own key and delivers the answer translated back.

  • Switching an application: address and key, nothing else
  • Direct connections to the provider blocked
  • Rule set and log per application
Access B

In AI assistants

As a tool in assistants that speak the open tool protocol MCP. The assistant calls «ask an external model in masked form», everything else runs in the core.

  • The same tools for every client
  • Checking, masking and translating back also usable on their own
  • Its own access key per client, separate views
Access C

At the workplace

Select text in any application, hand it to PrivatPrompt through a service, apply the answer. The app shows masking, levels and answers and needs no system permissions.

  • Its own app on the machine, also through existing subscriptions
  • No window monitoring, no reading along in the clipboard
  • Hand over as text, as a file or into the knowledge base
07 · Implementation

As a project in three steps

Clarify use cases and data classes

Which applications and tasks go to external models, which data may go out at which level, and which never? Along with the contractual basis at the provider, because the gateway adds to the data processing agreement, it does not replace it. Result: the rule set per use case.

Put the gateway into operation

Provider keys into the gateway, applications switched over to the gateway, direct routes blocked. Tune detection to your data: companies from your customer base, Swiss identifiers, your own terms that must never go out. Tested on real texts with a measured hit rate instead of an assumption.

Pilot and roll-out

Start with one application or one team. Feedback sharpens the starting level and the limits per profile. Only when the fit check agrees with your own judgements may it release answers on its own. Then the remaining applications follow.

How it fits

The gateway in front of every external model

Wherever an application, an assistant or an agent calls a language model, PrivatPrompt sits in front of it: for reply drafts in the Activity Cockpit, for minutes from PrivatTranscript, for the route to the frontier model in the target picture of the knowledge layer. The model stays exchangeable, the neutrality of the data remains.

Target picture of all solutions
Document

The summary as a PDF

The gateway for every API call, the masking ladder, the six-stage process with processing locations, the three ways in and the data handling, compact for the decision paper.

PDF · 3 pages

PrivatPrompt

The model sees the task, never the identity: gateway, ladder, process, ways in and data handling on three pages.

Which prompts containing company data leave your house today?

In a first conversation we count the applications that call a provider directly today, and clarify which data may go out at which level. No obligation, at eye level.

Get in touch All solutions