Salus detects sensitive information inside your environment and replaces it with typed, context-consistent tokens. Your application keeps calling its own AI provider; authorized values are restored at the final boundary. The point isn't redaction — it's protection that preserves the relationships the model needs to give useful answers.
Self-hosted · Provider-independent · Fail-closed · Built to preserve useful context
Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.
Assess collection risk for [PERSON_81af3c] ([IBAN_5f7d2e]), 62 days past due on loan [LOAN_9b3ec1], balance €18,400.
Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.
Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.
Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.
No migration, no new app to learn, no rip-and-replace of the AI stack you have.
Adding a provider is a config change, not another privacy review from scratch.
The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.
Five steps — only one leaves your network, and it carries tokens. The model does the work; it just never learns who it was working on.
Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.
Each value becomes a typed token — [PERSON_81af3c], [PHONE_8f3a1d]. The category survives; the identity doesn't leave.
Identity stays consistent inside a Context — the same person is the same token across a whole job, batch or conversation, so relationships survive.
Your application calls its own provider, with its own credentials. The tokenized request is the only thing that crosses the boundary.
Authorized values are restored inside your perimeter, before the answer reaches the person, app or agent that asked.
One product, two ways to deploy: integrate Salus into the applications you build, or deploy it on managed endpoints for the ones you don't control. Same protection model, same Context semantics underneath.
The engine, the restoration state and the restoration path run inside your environment. Salus does not hold your keys.
It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.
Supported content types and detection classes depend on the selected deployment and policy configuration.
Directly identifying values, replaced with typed tokens and restored exactly. Categories are configured per deployment; your own identifiers are part of the dictionary, not an exception to it.
The telecom identifiers are the fields that appear in CDR, SMS, session and billing records and are treated as traffic data under Turkish telecom rules. Which fields count as personal data follows your own record formats and policy.
Speaker labels, informal spelling and numbers said out loud. Names, phone numbers and customer references become tokens; the complaint and its resolution stay for the model.
Salus's AI Meeting Note Taker workflow protects the transcript before summarisation or action-item extraction. Names, phones, e-mails and customer references are tokenised; the topics and decisions remain for the summary.
CDR lines, SMS and session logs, itemised bills. MSISDN, IMSI, IMEI and ICCID are tokenised by policy; timestamps and volumes stay usable for analysis.
How results are reported. Every category is counted on your own records as fully masked, partially masked or missed, next to the text the model actually received. The run is repeated after each dictionary or policy change, so the effect of a change is visible.
When a file is about to cross the boundary, the person who knows the document sees exactly what was caught, fixes a wrong detection, flags something missed — and only then continues. In integrated deployments the review step lives in your own application, where regulations want the final human say.
Subscriber Sarah Chen (+1 415-892-3100) reported a recurring fiber outage affecting account ACCT-88231 at her Bay Area address. She requests a credit for the affected billing period.
You keep calling your provider with your own URL, credentials and orchestration — Salus operates before and after that call. Switch model, add a specialist vendor, run both in parallel: the protection layer doesn't move.
your provider, your credentials — Salus never sits between you and your model contract
Detection, tokenization, restoration state and the restore path all run inside your environment. There is no Salus-side copy of the mapping.
Require a person to approve egress on the workflows where that is worth it — and only those.
Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.
On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.
Every control below is in the current release. Nothing on this list is a roadmap.
If detection, tokenisation or document parsing cannot complete, the request stops. Unreadable files are refused, never passed through.
Validated rules, a Turkish language model and a verifier, on CPU. Same input, same output. No GPU, and no prompt surface inside the security layer.
A second model re-checks every candidate before anything is replaced or released.
Tokens are keyed references, not transformations of the value. Nothing about the original can be derived from a token. Optional format-preserving mode (SC-08).
Values are restored only inside your environment, scoped to the session context that created them.
Nothing calls home. No Salus-side data, keys or telemetry. Runs on an isolated network from a mirrored registry.
Tenant-scoped API keys with per-key scopes, rate limits, and request budgets on the detection path (SC-14).
Structured events with stable codes, delivered to your SIEM. Values are never reprinted in logs or API responses.
PDF, DOCX, XLSX and PPTX are protected inside the file. Scanned or unreadable input is refused, not guessed.
Private OCI Helm chart, six images, OpenShift 4.x, non-root containers, health endpoints.
A signed release manifest and a CycloneDX SBOM for every release.
A console for tenants, API-key lifecycle, detection review and security audit events.
Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.
A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.