Read the docs
Self-hosted protection layer for AI applications

Protect sensitive data
before AI sees it.

Salus detects sensitive information inside your environment and replaces it with typed, context-consistent tokens. Your application keeps calling its own AI provider; authorized values are restored at the final boundary. The point isn't redaction — it's protection that preserves the relationships the model needs to give useful answers.

Read the documentation

Self-hosted · Provider-independent · Fail-closed · Built to preserve useful context

Collections review
Inside your network — what your team types

Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.

detect · tokenize · vault and keys stay inside
Crosses the boundary — what the provider receives

Assess collection risk for [PERSON_81af3c] ([IBAN_5f7d2e]), 62 days past due on loan [LOAN_9b3ec1], balance €18,400.

answer returns · restored inside
Back to the user — restored

Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.

Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.

The adoption problem

The AI market moves fast.
Your privacy architecture should not have to.

Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.

The tools they already use

No migration, no new app to learn, no rip-and-replace of the AI stack you have.

The next tool, too

Adding a provider is a config change, not another privacy review from scratch.

Agents and applications

The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.

How it works

Detect. Protect. Preserve. Restore.

Five steps — only one leaves your network, and it carries tokens. The model does the work; it just never learns who it was working on.

1

Detect

Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.

2

Protect

Each value becomes a typed token — [PERSON_81af3c], [PHONE_8f3a1d]. The category survives; the identity doesn't leave.

3

Preserve

Identity stays consistent inside a Context — the same person is the same token across a whole job, batch or conversation, so relationships survive.

4

Your AI call

Your application calls its own provider, with its own credentials. The tokenized request is the only thing that crosses the boundary.

5

Restore

Authorized values are restored inside your perimeter, before the answer reaches the person, app or agent that asked.

One product. Two paths.

Choose where Salus sits.
The trust model stays the same.

One product, two ways to deploy: integrate Salus into the applications you build, or deploy it on managed endpoints for the ones you don't control. Same protection model, same Context semantics underneath.

Integrate Salus
Applications you build
Salus deploys inside your environment — integrate via the SDK, a local API, or an adapter for the gateway you already run. Sensitive values leave as tokens; answers are restored inside your perimeter.
  • In-house AI applications and services
  • Plugs into the AI gateway you already run
  • Analytics and batch workloads over customer data
  • Agents and automated pipelines
  • Identity stays consistent across a whole workload
Tokenize before the provider call, restore after — fail-closed by design. Nothing reaches the provider unprotected because a step was skipped.
Deploy Salus on managed endpoints
Applications you don't control
Protection deployed around the AI tools your teams already use — without modifying the applications.
  • Browser-based AI services
  • Desktop AI applications
  • Specialist and vertical AI products
  • Documents, images and screenshots
  • Human review before anything sends
Same protection model, same Context semantics — deployed at the endpoint instead of inside your code.
Both paths run on one product
Salus
Detection · Protection · Context · Restoration · Dictionary & policy · Evidence & audit

The engine, the restoration state and the restoration path run inside your environment. Salus does not hold your keys.

More than prompts

The sensitive part is rarely the prompt.

It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.

Text Documents PDFs Images Screenshots Faces Signatures Generated files Agent & API payloads

Supported content types and detection classes depend on the selected deployment and policy configuration.

Human review

And when it matters, a person signs off first.

When a file is about to cross the boundary, the person who knows the document sees exactly what was caught, fixes a wrong detection, flags something missed — and only then continues. In integrated deployments the review step lives in your own application, where regulations want the final human say.

Provider-independent

Change models whenever you want.
The privacy layer does not move.

You keep calling your provider with your own URL, credentials and orchestration — Salus operates before and after that call. Switch model, add a specialist vendor, run both in parallel: the protection layer doesn't move.

OpenAI Claude Gemini Azure Mistral

your provider, your credentials — Salus never sits between you and your model contract

Customer control

The detection model and the restoration path never leave your side.

Self-hosted core

Detection, tokenization, restoration state and the restore path all run inside your environment. There is no Salus-side copy of the mapping.

Human approval

Require a person to approve egress on the workflows where that is worth it — and only those.

Tokenized audit

Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.

On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.

Technical documentation

Security teams ask harder questions.
They are already answered.

Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.

Start with one team.
One workflow. Real data.

A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.

Read the documentation