The prompt leaves.
Your secrets don't.
OwnKeep lets your team use ChatGPT, Claude and Gemini without sending client data to the cloud. Personal information is detected and masked on your own hardware before a prompt ever leaves the building - then restored in the reply, so the work feels exactly the same.
Built for Australian legal & accounting firms. On-premises, vendor-neutral, fail-closed.
Sources: Microsoft & LinkedIn 2024 Work Trend Index; IBM Cost of a Data Breach.
Your data-loss tools can't see this traffic
When staff paste a client name, a contract clause or an account number into an AI tab, that data goes straight from the browser to a third party. It never touches your email gateway, your endpoint controls or a monitored SaaS API - so the tools you already pay for simply don't see it.
- Banning AI backfires. The work doesn't stop - it moves to personal accounts on personal devices, where nobody is watching.
- Regulators don't distinguish intent. Under GDPR, the Privacy Act and sector rules, an accidental leak carries the same liability as a deliberate one.
- Cloud "redaction" defeats the purpose. Many controls still route your raw prompt through the vendor's cloud to inspect it first.
Five steps, all on your own infrastructure
Your team keeps using the AI tools they already know. OwnKeep sits quietly in front of them and handles the rest on every single request.
1 · Intercept
Every prompt to a known AI service passes through the gateway first.
2 · Detect locally
A model on your own hardware finds the personal data. Nothing is sent away to be scanned.
3 · Mask
Real values become typed placeholders - [PERSON_1], [TFN_1].
4 · Forward
The masked prompt goes to the AI. It answers using the placeholders.
5 · Restore
OwnKeep swaps the real values back in. Your team sees a normal, complete reply.
From your team's point of view, nothing changed. From a compliance point of view, sensitive data never left the building.
Every request, masked and logged in real time
The OwnKeep dashboard shows exactly what your staff typed, exactly what the AI received, and a full record of what was protected - so you can prove it to a regulator or an insurer.
A faithful view of the live OwnKeep control dashboard. Logs record the type and count of items detected - never the raw values.
Three things that make it different
Local-only by design
Masking happens on-premises, before anything leaves your network. Unlike cloud "redaction" services, your raw data is never routed through a third party to be inspected - which is the whole point for data-residency and sovereignty.
Vendor-neutral
OwnKeep isn't tied to one model or platform. It governs traffic to whichever AI services your staff actually use - ChatGPT, Claude, Gemini - and adding a new one is a configuration change, not a re-build.
Transparent & auditable
The detection logic is a single, visible, editable instruction set - not an opaque black box. Every interaction produces an audit record: the evidence trail that regulators and insurers increasingly expect.
A safety layer built for regulated work
Not a checkbox. The controls that matter when your core asset is confidential client data.
Detection stays on your machine
The model that finds personal data runs locally through Ollama. No prompt, and no PII, is sent to a third party to be scanned.
Australian identifiers
Names, emails, phones, addresses - plus TFN, ABN and Medicare numbers, validated with real checksums, not just guessed by pattern.
Fail-closed by default
If the shield can't check a prompt, the prompt is held back rather than sent unprotected. Safety is the default, not the exception.
Compliance-ready audit trail
A record of what was intercepted - the type and count of items - without ever storing the raw values in the log.
Blocks risky file uploads
Attaching a document would bypass text masking, so OwnKeep stops those uploads before a file can reach the AI provider.
Works with the big three
ChatGPT, Claude and Gemini through one gateway. Your team keeps the tools and the workflow they already use.
The sensitive data never leaves your perimeter
Your staff
Type into ChatGPT, Claude, Gemini as usual
OwnKeep gateway
Detects & masks locally on your hardware · keeps the audit trail
Public AI
Only ever receives placeholders
Runs on-premises with Docker or natively - your servers, your hardware. GPU optional; sub-second on a laptop-class machine.
Made for firms whose data must stay confidential
Professional-services firms of roughly 50 to 500 staff, where the core asset is client confidentiality and the partners are personally on the hook for it.
Law firms & in-house counsel
Let lawyers use AI to draft, summarise and research - without client names, matters or file notes ever reaching a third party.
Accounting & advisory practices
Prepare BAS, letters and analysis with AI while TFNs, ABNs and account numbers stay inside the practice.
Advisers & wealth firms
Use AI across statements of advice and client comms while personal and financial identifiers are masked on the way out. (on the roadmap)
Clinics & practice groups
Support administration and correspondence with AI while patient names and Medicare numbers never leave the building. (on the roadmap)
Start with a pilot, scale by seat band
On-premises deployment, delivered directly or through your managed IT partner. Pricing is tailored to your firm - talk to us.
Pilot
- Deploy in your environment
- Live masking against your real prompts
- Measured detection report
- Guided setup & support
Team
- Full gateway & dashboard
- On-prem, channel-delivered
- Audit trail & reporting
- Email support
Firm
- Everything in Team
- On-prem with priority support
- Vertical detection tuning
- Compliance reporting pack
Enterprise
- High availability
- Integration & SSO
- Delivered via MSSP / SI
- Custom reporting & SLAs
Questions we get asked
Does any of our data leave the building? +
No. Detection runs on a model hosted on your own hardware, and masking happens before the prompt leaves your network. The public AI only ever receives placeholders. There is no external call - not even to a detection service.
Which AI tools does it cover? +
ChatGPT, Claude and Gemini today, through a single vendor-neutral gateway. Because it governs traffic by destination, adding another AI service is a configuration change rather than a re-build.
Is this just regex redaction? +
No. A local language model reads the prompt in context, so it catches things a rules-based system misses - like "my client Bob" or an identifier phrased in an unusual way. Deterministic checks (including Australian TFN/ABN/Medicare checksums) run underneath as a safety net.
What happens if the detector fails or is unavailable? +
It fails closed. If a prompt can't be checked, it is blocked rather than forwarded unprotected. Safety is the default behaviour, and it's tested.
Is it a finished, perfect filter? +
No detector is perfect, and we don't claim otherwise. OwnKeep is an early-access product now running pilots with regulated firms. We compete on measured recall, fail-closed safety and a clean audit trail - all checkable - rather than a claim of perfection.
How is it deployed? +
On-premises, via Docker or a native install, on your servers. A GPU helps but isn't required; detection is sub-second on laptop-class hardware. It can be delivered directly or through your existing managed IT/security provider.
See it run on your own data
Book a pilot and watch a real prompt get masked, sent and restored - live, in your environment. No client data leaves the room.
Request a pilot