GDPR-Compliant AI Usage

Anonymize data before
it crosses borders.

Your employees use AI daily. Salus ensures personal data is automatically stripped before anything reaches US-based AI providers — keeping your organization GDPR-compliant.

Start Free Trial Deployment Options
The Compliance Problem

Every AI prompt is a cross-border data transfer.

When an employee asks ChatGPT to "draft an email to John Smith at john@acme.com about the contract at 123 Main Street" — they just sent personal data to servers in the United States. Under GDPR, that's a cross-border transfer of personal data requiring legal basis, data processing agreements, and transfer impact assessments.

Most organizations either ban AI tools entirely — losing productivity — or ignore the risk and hope for the best.

How It Works

Anonymize. Send. Restore.

Personal data never leaves your infrastructure. Only anonymized text reaches external AI providers.

1

Employee writes naturally

No training needed. Write prompts with real names, addresses, IDs — as normal.

2

PII detected & replaced

Self-hosted AI identifies personal data and substitutes with irreversible placeholders.

3

AI sees only placeholders

Claude, GPT, or Gemini processes anonymized text. No personal data crosses borders.

4

Response restored

Placeholders are mapped back to real values on your infrastructure. User sees the full response.

Salus AI
Employee types:
Summarize the NDA between Acme Corp and Maria Schmidt (ID: DE-9847261). Her email is m.schmidt@acme.de
AI provider receives:
Summarize the NDA between [COMPANY_1] and [PERSON_1] (ID: [ID_1]). Her email is [EMAIL_1]
AI provider cannot identify anyone
Employee sees the full response — restored automatically:
The NDA between Acme Corp and Maria Schmidt (DE-9847261) covers mutual confidentiality obligations for a period of 3 years. Key provisions include non-disclosure of trade secrets, non-solicitation...
Deployment

Your infrastructure, your rules.

Choose the deployment model that fits your compliance requirements. Both options keep the anonymization engine within your legal jurisdiction.

Managed

Hosted by Salus

We deploy and manage the anonymization engine on a dedicated server in your country. You get a private endpoint — nothing shared.

  • Dedicated GPU server in your jurisdiction
  • We handle deployment, updates, and monitoring
  • Custom domain (e.g. ai.yourcompany.com)
  • SSO / SAML integration available
  • SLA with guaranteed uptime
  • Audit logs for compliance reporting
Self-Hosted

On Your Infrastructure

Deploy the full Salus stack on your own servers, VPC, or air-gapped environment. No data ever leaves your network.

  • Docker / Kubernetes deployment
  • Runs on any GPU server (NVIDIA L40S+)
  • Air-gapped deployment supported
  • Full source access for security review
  • Integrate with your existing identity provider
  • Complete data sovereignty
Compliance

Built for regulated industries.

Legal, finance, healthcare, government — any organization handling sensitive personal data.

🛡

GDPR Article 28

Anonymized data may fall outside the scope of data processing agreements entirely, per the SRB ruling. Your DPA obligations are drastically simplified.

🌐

Cross-Border Transfers

Since AI providers cannot re-identify data subjects from placeholders, Schrems II transfer concerns are mitigated at the technical level.

🔒

Self-Hosted PII Engine

The anonymization AI runs entirely on your infrastructure. No personal data is sent to any third party for the purpose of anonymization.

📋

Audit Trail

Every anonymization operation is logged — what was detected, what was replaced, who triggered it. Ready for DPO review and compliance audits.

🔍

Transparent Architecture

Users can see exactly what AI saw (anonymized view) vs. what they see (restored view). Full transparency for both employees and compliance officers.

📄

Document Processing

Upload contracts, invoices, court filings, medical records — PDFs, DOCX, images. All PII is anonymized before any AI model processes the content.

Let your team use AI.
Without the GDPR risk.

Start with the free web app, or talk to us about a dedicated deployment in your jurisdiction.