Salus swaps names, account numbers and the other data classes you define for reversible tokens before they leave your network — then restores them in the answer. External models only ever see the tokens. The vault and the keys stay with you.
Runs on your infrastructure. Works with the AI tools your teams already use.
Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.
Assess collection risk for PERSON_81af (IBAN_5f7d), 62 days past due on loan LOAN_9b3e, balance €18,400.
Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.
Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.
Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.
No migration, no new app to learn, no rip-and-replace of the AI stack you have.
Adding a provider is a config change, not another privacy review from scratch.
The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.
Four steps, all of them inside your network except one. The model does the work; it just never learns who it was working on.
Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.
Each one becomes a typed, reversible token — PERSON_81af, PHONE_8f3a, CID_4a2e. Same value, same token, so the model can still reason about it.
The tokenized request goes to whichever provider you picked for the job. That is the only thing that crosses the boundary.
Tokens in the response are resolved back to real values on your side, before the answer reaches the person, app or agent that asked.
Same detection, same vault, same audit trail underneath. The only question is whether Salus protects the AI you already run, or replaces it with one of ours.
The engine, the vault and the restoration path run inside your environment. Salus does not hold your keys.
It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.
Supported content types and detection classes depend on the selected deployment and policy configuration.
Users can see exactly what was caught, fix a wrong detection, flag something the model missed, and only then continue. Policy decides when that gate applies — a data class, an application, one team — so the rest of the work does not stop for an approval nobody needed.
Subscriber Sarah Chen (+1 415-892-3100) reported a recurring fiber outage affecting account ACCT-88231 at her Bay Area address. She requests a credit for the affected billing period.
The privacy layer belongs to you, not to whichever provider is ahead this quarter. Switch model, add a specialist vendor, run both in parallel — the detection, tokenization, vault, policy and restoration stay exactly where they are.
and any OpenAI-compatible provider
Engine, vault, policies and restoration all run inside your environment. There is no Salus-side copy of the mapping.
Require a person to approve egress on the workflows where that is worth it — and only those.
Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.
On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.
Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.
A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.