The prompt leaves.
Your secrets don't.
OwnKeep lets your team use ChatGPT, Claude and Gemini without sending client data to the cloud. Personal information is detected and masked on your own hardware before a prompt ever leaves the building - then restored in the reply, so the work feels exactly the same.
Built for Australian legal & accounting firms. On-premises, vendor-neutral, fail-closed.
Sources: Microsoft & LinkedIn 2024 Work Trend Index; IBM Cost of a Data Breach.
Your data-loss tools can't see this traffic
When staff paste a client name, a contract clause or an account number into an AI tab, that data goes straight from the browser to a third party. It never touches your email gateway, your endpoint controls or a monitored SaaS API - so the tools you already pay for simply don't see it.
- Banning AI backfires. The work doesn't stop - it moves to personal accounts on personal devices, where nobody is watching.
- Regulators don't distinguish intent. Under GDPR, the Privacy Act and sector rules, an accidental leak carries the same liability as a deliberate one.
- Cloud "redaction" defeats the purpose. Many controls still route your raw prompt through the vendor's cloud to inspect it first.
Five steps, all on your own infrastructure
Your team keeps using the AI tools they already know. OwnKeep sits quietly in front of them and handles the rest on every single request.
1 · Intercept
Every prompt to a known AI service passes through the gateway first.
2 · Detect locally
A model on your own hardware finds the personal data. Nothing is sent away to be scanned.
3 · Mask
Real values become typed placeholders - [PERSON_1], [TFN_1].
4 · Forward
The masked prompt goes to the AI. It answers using the placeholders.
5 · Restore
OwnKeep swaps the real values back in. Your team sees a normal, complete reply.
From your team's point of view, nothing changed. From a compliance point of view, sensitive data never left the building.
Every request, masked and logged in real time
The OwnKeep dashboard shows exactly what your staff typed, exactly what the AI received, and a full record of what was protected - so you can prove it to a regulator or an insurer.
A faithful view of the live OwnKeep control dashboard. Logs record the type and count of items detected - never the raw values.
Type a prompt and watch it get masked
Put in a sentence with a name, an email, a phone number or an Australian TFN, ABN or Medicare number, and see what the AI would actually receive. Everything here runs in your browser - nothing is sent anywhere.
This in-browser demo uses simple pattern rules so it can run without a server - it is a simplified illustration. The real OwnKeep gateway uses a language model on your own hardware to read each prompt in context, so it catches cases plain patterns miss (like a first name on its own), backed by the same deterministic Australian checksums you see here.
Three things that make it different
Local-only by design
Masking happens on-premises, before anything leaves your network. Unlike cloud "redaction" services, your raw data is never routed through a third party to be inspected - which is the whole point for data-residency and sovereignty.
Vendor-neutral
OwnKeep isn't tied to one model or platform. It governs traffic to whichever AI services your staff actually use - ChatGPT, Claude, Gemini - and adding a new one is a configuration change, not a re-build.
Transparent & auditable
The detection logic is a single, visible, editable instruction set - not an opaque black box. Every interaction produces an audit record: the evidence trail that regulators and insurers increasingly expect.
A safety layer built for regulated work
Not a checkbox. The controls that matter when your core asset is confidential client data.
Detection stays on your machine
The model that finds personal data runs locally through Ollama. No prompt, and no PII, is sent to a third party to be scanned.
Australian identifiers
Names, emails, phones, addresses - plus TFN, ABN and Medicare numbers, validated with real checksums, not just guessed by pattern.
Fail-closed by default
If the shield can't check a prompt, the prompt is held back rather than sent unprotected. Safety is the default, not the exception.
Compliance-ready audit trail
A record of what was intercepted - the type and count of items - without ever storing the raw values in the log.
Blocks risky file uploads
Attaching a document would bypass text masking, so OwnKeep stops those uploads before a file can reach the AI provider.
Works with the big three
ChatGPT, Claude and Gemini through one gateway. Your team keeps the tools and the workflow they already use.
The alternatives, side by side
Most firms are choosing between four options right now. Here is how they compare on the things that actually carry the risk.
| Ban AI | Do nothing | Cloud redaction tool | OwnKeep | |
|---|---|---|---|---|
| Sensitive data stays on your hardware | Yes | No | No - raw prompt is sent to the vendor to inspect | Yes - detection runs locally |
| Staff keep using ChatGPT, Claude, Gemini | No | Yes | Sometimes - often one tool only | Yes - vendor-neutral |
| Shadow AI use is reduced, not pushed underground | No - work moves to personal devices | No | Partly | Yes - the sanctioned path is the easy path |
| Audit trail for regulators and insurers | No | No | Held by the vendor | Yes - kept on-premises, counts not raw values |
| Fails safe if the check cannot run | n/a | No | Varies | Yes - fail-closed by default |
| Blocks risky file uploads that bypass masking | n/a | No | Rarely | Yes |
"Cloud redaction tool" refers to services that detect or redact PII by first sending the prompt to the provider's own cloud. Capabilities across such tools vary - the point of difference with OwnKeep is that the raw data never leaves your perimeter to be inspected in the first place.
The sensitive data never leaves your perimeter
Your staff
Type into ChatGPT, Claude, Gemini as usual
OwnKeep gateway
Detects & masks locally on your hardware · keeps the audit trail
Public AI
Only ever receives placeholders
Runs on-premises with Docker or natively - your servers, your hardware. GPU optional; sub-second on a laptop-class machine.
Built to help you meet your obligations
OwnKeep is designed around the principle regulators keep returning to: keep personal data under your control. Here is where it fits, stated plainly.
Australian Privacy Act & APPs
Supports your handling of personal information under the Privacy Act 1988 and the Australian Privacy Principles by keeping identifiers inside your perimeter.
- Data minimisation at the point of use
- No disclosure of raw PII to overseas AI providers
- Evidence trail of what was protected
GDPR & data residency
For firms with EU or cross-border exposure, detection and masking happen locally, so personal data is not transferred to a third party to be processed.
- Processing stays in your chosen jurisdiction
- Reduces cross-border transfer risk
- You remain the data controller
Security posture
We are honest about our stage. OwnKeep is early-access, running pilots - these are the controls in place today and what is next.
- Encrypted audit store, no raw PII in logs In place
- Fail-closed, token-gated services In place
- SOC 2 / ISO 27001 alignment On the roadmap
OwnKeep is a technical control that supports your compliance programme; it is not legal advice and does not by itself make a firm compliant. We are happy to work through your specific obligations during a pilot.
Made for firms whose data must stay confidential
Professional-services firms of roughly 50 to 500 staff, where the core asset is client confidentiality and the partners are personally on the hook for it.
Law firms & in-house counsel
Let lawyers use AI to draft, summarise and research - without client names, matters or file notes ever reaching a third party.
Accounting & advisory practices
Prepare BAS, letters and analysis with AI while TFNs, ABNs and account numbers stay inside the practice.
Advisers & wealth firms
Use AI across statements of advice and client comms while personal and financial identifiers are masked on the way out. (on the roadmap)
Clinics & practice groups
Support administration and correspondence with AI while patient names and Medicare numbers never leave the building. (on the roadmap)
Start with a pilot, scale by seat band
On-premises deployment, delivered directly or through your managed IT partner. Pricing is tailored to your firm - talk to us.
Pilot
- Deploy in your environment
- Live masking against your real prompts
- Measured detection report
- Guided setup & support
Team
- Full gateway & dashboard
- On-prem, channel-delivered
- Audit trail & reporting
- Email support
Firm
- Everything in Team
- On-prem with priority support
- Vertical detection tuning
- Compliance reporting pack
Enterprise
- High availability
- Integration & SSO
- Delivered via MSSP / SI
- Custom reporting & SLAs
Questions we get asked
Does any of our data leave the building? +
No. Detection runs on a model hosted on your own hardware, and masking happens before the prompt leaves your network. The public AI only ever receives placeholders. There is no external call - not even to a detection service.
Which AI tools does it cover? +
ChatGPT, Claude and Gemini today, through a single vendor-neutral gateway. Because it governs traffic by destination, adding another AI service is a configuration change rather than a re-build.
Is this just regex redaction? +
No. A local language model reads the prompt in context, so it catches things a rules-based system misses - like "my client Bob" or an identifier phrased in an unusual way. Deterministic checks (including Australian TFN/ABN/Medicare checksums) run underneath as a safety net.
What happens if the detector fails or is unavailable? +
It fails closed. If a prompt can't be checked, it is blocked rather than forwarded unprotected. Safety is the default behaviour, and it's tested.
Is it a finished, perfect filter? +
No detector is perfect, and we don't claim otherwise. OwnKeep is an early-access product now running pilots with regulated firms. We compete on measured recall, fail-closed safety and a clean audit trail - all checkable - rather than a claim of perfection.
How is it deployed? +
On-premises, via Docker or a native install, on your servers. A GPU helps but isn't required; detection is sub-second on laptop-class hardware. It can be delivered directly or through your existing managed IT/security provider.
Who is behind OwnKeep
Dr Asim Baig
OwnKeep is founder-led by Dr Asim Baig, who holds a PhD and has spent more than two decades building data, machine-learning and privacy-focused systems. OwnKeep grew out of a simple observation: regulated firms want to use AI, but cannot afford to send client data to the cloud to do it. The product is built in Australia, for the firms that carry that risk personally. If you are evaluating OwnKeep, you will be talking to the person who built it.
See it run on your own data
Book a pilot and watch a real prompt get masked, sent and restored - live, in your environment. No client data leaves the room.