EN|TR Read the docs
Self-hosted protection layer for AI applications

Protect sensitive data
before AI sees it.

Salus detects sensitive information inside your environment and replaces it with typed, context-consistent tokens. Your application keeps calling its own AI provider; authorized values are restored at the final boundary. The point isn't redaction — it's protection that preserves the relationships the model needs to give useful answers.

Read the documentation

Self-hosted · Provider-independent · Fail-closed · Built to preserve useful context

Collections review
Inside your network — what your team types

Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.

detect · tokenize · vault and keys stay inside
Crosses the boundary — what the provider receives

Assess collection risk for [PERSON_81af3c] ([IBAN_5f7d2e]), 62 days past due on loan [LOAN_9b3ec1], balance €18,400.

answer returns · restored inside
Back to the user — restored

Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.

Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.

The adoption problem

The AI market moves fast.
Your privacy architecture should not have to.

Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.

The tools they already use

No migration, no new app to learn, no rip-and-replace of the AI stack you have.

The next tool, too

Adding a provider is a config change, not another privacy review from scratch.

Agents and applications

The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.

How it works

Detect. Protect. Preserve. Restore.

Five steps — only one leaves your network, and it carries tokens. The model does the work; it just never learns who it was working on.

1

Detect

Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.

2

Protect

Each value becomes a typed token — [PERSON_81af3c], [PHONE_8f3a1d]. The category survives; the identity doesn't leave.

3

Preserve

Identity stays consistent inside a Context — the same person is the same token across a whole job, batch or conversation, so relationships survive.

4

Your AI call

Your application calls its own provider, with its own credentials. The tokenized request is the only thing that crosses the boundary.

5

Restore

Authorized values are restored inside your perimeter, before the answer reaches the person, app or agent that asked.

One product. Two paths.

Choose where Salus sits.
The trust model stays the same.

One product, two ways to deploy: integrate Salus into the applications you build, or deploy it on managed endpoints for the ones you don't control. Same protection model, same Context semantics underneath.

Integrate Salus
Applications you build
Salus deploys inside your environment — integrate via the SDK, a local API, or an adapter for the gateway you already run. Sensitive values leave as tokens; answers are restored inside your perimeter.
  • In-house AI applications and services
  • Plugs into the AI gateway you already run
  • Analytics and batch workloads over customer data
  • Agents and automated pipelines
  • Identity stays consistent across a whole workload
Tokenize before the provider call, restore after — fail-closed by design. Nothing reaches the provider unprotected because a step was skipped.
Salus Desktop on managed endpoints
Applications you don't control
Salus Desktop runs on the employee's device, alongside the tools they already use. Protection is deployed around the AI applications without modifying them.
  • Browser-based AI services
  • Desktop AI applications
  • Specialist and vertical AI products
  • Documents, images and screenshots
  • Human review before anything sends
Same protection model, same Context semantics — deployed at the endpoint instead of inside your code.
Both paths run on one product
Salus
Detection · Protection · Context · Restoration · Dictionary & policy · Evidence & audit

The engine, the restoration state and the restoration path run inside your environment. Salus does not hold your keys.

More than prompts

The sensitive part is rarely the prompt.

It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.

Text Documents PDFs Images Screenshots Faces Signatures Generated files Agent & API payloads

Supported content types and detection classes depend on the selected deployment and policy configuration.

What it detects

Directly identifying values, replaced with typed tokens and restored exactly. Categories are configured per deployment; your own identifiers are part of the dictionary, not an exception to it.

Person names Dates of birth TCKN Tax ID Passport numbers Driving licence numbers SGK numbers IBAN Card numbers Bank account numbers Account and customer numbers Phone numbers and MSISDN IMSI IMEI and IMEISV ICCID E-mail addresses Usernames and identifying URLs IP addresses GPS coordinates Postal addresses Vehicle plates VIN Device serial numbers Organisations Your own identifiers

The telecom identifiers are the fields that appear in CDR, SMS, session and billing records and are treated as traffic data under Turkish telecom rules. Which fields count as personal data follows your own record formats and policy.

Where it shows up

Transcripts, meeting notes and traffic records.

Support and call-centre transcripts

Speaker labels, informal spelling and numbers said out loud. Names, phone numbers and customer references become tokens; the complaint and its resolution stay for the model.

AI Meeting Note Taker and call transcripts

Salus's AI Meeting Note Taker workflow protects the transcript before summarisation or action-item extraction. Names, phones, e-mails and customer references are tokenised; the topics and decisions remain for the summary.

Traffic and billing records

CDR lines, SMS and session logs, itemised bills. MSISDN, IMSI, IMEI and ICCID are tokenised by policy; timestamps and volumes stay usable for analysis.

How results are reported. Every category is counted on your own records as fully masked, partially masked or missed, next to the text the model actually received. The run is repeated after each dictionary or policy change, so the effect of a change is visible.

Human review

And when it matters, a person signs off first.

When a file is about to cross the boundary, the person who knows the document sees exactly what was caught, fixes a wrong detection, flags something missed — and only then continues. In integrated deployments the review step lives in your own application, where regulations want the final human say.

Provider-independent

Change models whenever you want.
The privacy layer does not move.

You keep calling your provider with your own URL, credentials and orchestration — Salus operates before and after that call. Switch model, add a specialist vendor, run both in parallel: the protection layer doesn't move.

OpenAI Claude Gemini Azure Mistral

your provider, your credentials — Salus never sits between you and your model contract

Customer control

The detection model and the restoration path never leave your side.

Self-hosted core

Detection, tokenization, restoration state and the restore path all run inside your environment. There is no Salus-side copy of the mapping.

Human approval

Require a person to approve egress on the workflows where that is worth it — and only those.

Tokenized audit

Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.

On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.

Technical documentation

Security teams ask harder questions.
They are already answered.

Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.

Start with one team.
One workflow. Real data.

A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.

Read the documentation