Salus detects sensitive information inside your environment and replaces it with typed, context-consistent tokens. Your application keeps calling its own AI provider; authorized values are restored at the final boundary. The point isn't redaction — it's protection that preserves the relationships the model needs to give useful answers.
Self-hosted · Provider-independent · Fail-closed · Built to preserve useful context
Assess collection risk for Maria Sandoval (DE12 3456 7890 1234 5678 90), 62 days past due on loan LN-4471822, balance €18,400.
Assess collection risk for [PERSON_81af3c] ([IBAN_5f7d2e]), 62 days past due on loan [LOAN_9b3ec1], balance €18,400.
Maria Sandoval qualifies for a 6-month hardship plan — proposed instalment €310 on loan LN-4471822.
Illustrative exchanges. Only the middle panel leaves your network — the figures the model needs to reason with survive, the identities do not.
Your teams are already pasting customer records into ChatGPT, Claude and a dozen specialist tools nobody approved. Blocking them stalls the work. Manual redaction strips out the context that made the answer worth asking for. And every new provider restarts the same review.
No migration, no new app to learn, no rip-and-replace of the AI stack you have.
Adding a provider is a config change, not another privacy review from scratch.
The same tokenization, policy, vault and audit apply to machine traffic, not just people typing.
Five steps — only one leaves your network, and it carries tokens. The model does the work; it just never learns who it was working on.
Salus finds the sensitive values in the prompt, the attached document, the screenshot — in the data classes you configure.
Each value becomes a typed token — [PERSON_81af3c], [PHONE_8f3a1d]. The category survives; the identity doesn't leave.
Identity stays consistent inside a Context — the same person is the same token across a whole job, batch or conversation, so relationships survive.
Your application calls its own provider, with its own credentials. The tokenized request is the only thing that crosses the boundary.
Authorized values are restored inside your perimeter, before the answer reaches the person, app or agent that asked.
One product, two ways to deploy: integrate Salus into the applications you build, or deploy it on managed endpoints for the ones you don't control. Same protection model, same Context semantics underneath.
The engine, the restoration state and the restoration path run inside your environment. Salus does not hold your keys.
It is the contract someone attached, the screenshot of a customer record, the spreadsheet an agent picked up on its own. Salus reads the text and the pixels — names, account numbers, contact details, document regions, faces and signatures, in the classes you configure.
Supported content types and detection classes depend on the selected deployment and policy configuration.
When a file is about to cross the boundary, the person who knows the document sees exactly what was caught, fixes a wrong detection, flags something missed — and only then continues. In integrated deployments the review step lives in your own application, where regulations want the final human say.
Subscriber Sarah Chen (+1 415-892-3100) reported a recurring fiber outage affecting account ACCT-88231 at her Bay Area address. She requests a credit for the affected billing period.
You keep calling your provider with your own URL, credentials and orchestration — Salus operates before and after that call. Switch model, add a specialist vendor, run both in parallel: the protection layer doesn't move.
your provider, your credentials — Salus never sits between you and your model contract
Detection, tokenization, restoration state and the restore path all run inside your environment. There is no Salus-side copy of the mapping.
Require a person to approve egress on the workflows where that is worth it — and only those.
Feed governed activity into your existing SIEM. The logs record what happened without reprinting the values you were protecting.
On-premises, private cloud, or isolated environments — depending on the architecture you choose and what your external models require.
Architecture, tokenization design, vault and key handling, human review, visual detection, deployment models — written for the people who will actually review this.
A focused pilot is the fastest way to see what Salus catches in your own traffic — and what it hands to the model instead. Tell us the workflow and we will set it up.