Read the docs
Self-hosted privacy layer for enterprise AI

Use advanced AI.
Keep sensitive data under your control.

Salus swaps names, account numbers and the other data classes you define for reversible tokens before they leave your network — then restores them in the answer. External models only ever see the tokens. The vault and the keys stay with you.

Read the documentation

Runs on your infrastructure. Works with the AI tools your teams already use.

Collections review
Inside your network — what your team types

Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.

detect · tokenize · vault and keys stay inside
Crosses the boundary — what the provider receives

Assess collection risk for PERSON_81af (IBAN_5f7d), 62 days past due on loan LOAN_9b3e, balance €18,400.

answer returns · restored inside
Back to the user — restored

Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.

Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.

The adoption problem

The AI market moves fast.
Your privacy architecture should not have to.

Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.

The tools they already use

No migration, no new app to learn, no rip-and-replace of the AI stack you have.

The next tool, too

Adding a provider is a config change, not another privacy review from scratch.

Agents and applications

The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.

How it works

Detect. Tokenize. Delegate. Restore.

Four steps, all of them inside your network except one. The model does the work; it just never learns who it was working on.

1

Detect

Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.

2

Tokenize

Each one becomes a typed, reversible token — PERSON_81af, PHONE_8f3a, CID_4a2e. Same value, same token, so the model can still reason about it.

3

Delegate

The tokenized request goes to whichever provider you picked for the job. That is the only thing that crosses the boundary.

4

Restore

Tokens in the response are resolved back to real values on your side, before the answer reaches the person, app or agent that asked.

Two products. One engine.

Choose where Salus sits.
The trust model stays the same.

Same detection, same vault, same audit trail underneath. The only question is whether Salus protects the AI you already run, or replaces it with one of ours.

Protect the AI you already use
Salus Gateway
Sits between your organization and the AI tools it already runs. Nothing gets replaced.
  • Browser-based AI services
  • Desktop AI applications
  • Specialist and vertical AI products
  • Internal services and AI agents
  • Any OpenAI-compatible API traffic
Two coverage layers: a server-side gateway for configured applications, internal services and agent traffic, and Salus Desktop for AI traffic on managed devices.
The secure AI application
Salus Workspace
Our own web and desktop AI app — for teams who would rather adopt one safe tool than police ten.
  • Secure chat on web and desktop
  • Documents, images and audio
  • File uploads and generated files
  • Human review before anything sends
  • Routes each task to the right model
The PII intelligence is self-hosted. External models write the answers, working only from tokenized context.
Both products run on the same engine
Salus Engine
Detection · Tokenization · Vault · Restoration · Policy · Audit

The engine, the vault and the restoration path run inside your environment. Salus does not hold your keys.

More than prompts

The sensitive part is rarely the prompt.

It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.

Text Documents PDFs Images Screenshots Faces Signatures Audio Generated files Agent & API payloads

Supported content types and detection classes depend on the selected deployment and policy configuration.

Human review

And when it matters, a person signs off first.

Users can see exactly what was caught, fix a wrong detection, flag something the model missed, and only then continue. Policy decides when that gate applies — a data class, an application, one team — so the rest of the work does not stop for an approval nobody needed.

Provider-independent

Change models whenever you want.
The privacy layer does not move.

The privacy layer belongs to you, not to whichever provider is ahead this quarter. Switch model, add a specialist vendor, run both in parallel — the detection, tokenization, vault, policy and restoration stay exactly where they are.

OpenAI Claude Gemini Azure Mistral

and any OpenAI-compatible provider

Customer control

The detection model and the restoration path never leave your side.

Self-hosted core

Engine, vault, policies and restoration all run inside your environment. There is no Salus-side copy of the mapping.

Human approval

Require a person to approve egress on the workflows where that is worth it — and only those.

Tokenized audit

Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.

On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.

Technical documentation

Security teams ask harder questions.
They are already answered.

Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.

Start with one team.
One workflow. Real data.

A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.

Read the documentation