Untraceable

    The confidential AI workspace for regulated experts and consultants.

    Consultants in HEOR, pharma, regulatory affairs and biostatistics use Untraceable to work with AI on data they're legally forbidden from sharing with it — the model never receives the confidential value at all.

    Patent-pending cloakingZero-trust Azure infrastructureUS · Canada · EU data residencyHIPAA · PIPEDA · GDPR aligned
    Proud to collaborate with Microsoft for Startups

    Built entirely on Microsoft Azure

    100% Microsoft AzureMicrosoft AI Cloud Partner Program member

    Microsoft, Azure, and Microsoft for Startups are trademarks of the Microsoft group of companies.

    00 — What we offer

    You were never allowed to use the good AI. Now you are.

    Untraceable is the AI workspace for consultants and experts in regulated fields — the people working with confidential, NDA-bound, proprietary and health data, who have had to sit out the AI revolution because their data was never theirs to share.

    The problem

    As a consultant or regulated industry researcher and expert, you could draft your report, plan your analysis, and update your deliverables. But you can't paste a client dataset, internal sensitive data, a study protocol, or a patient record into a chatbot — not legally, not ethically, not without risking the relationship your career is built on. So you either use a weaker tool, or you use the right tool quietly and hope no one asks.

    What we invented

    Untraceable removes the confidential content before the AI ever sees it — and replaces it with semantic flags: markers that carry the meaning the AI needs to reason, and nothing that could identify anyone. The model understands your work. It never sees your data.

    Patent-pending. Around 95% (Tremblay & Harricharan, 2026) of the writing and reasoning quality of plain, uncensored text — with zero secrets exposed, zero data traceable, and nothing about you or your client leaving your environment.

    Why that isn't enough — the vision

    Inventing the technology was the first step, not the last. Experts shouldn't have to build their own tools on top of it. So we built the tools: drafting and reporting, statistical analysis planning and execution, automated report generation and updates — the actual work, automated.

    Our vision: that consultants and regulated-industry experts finally get the full power of frontier AI — safely, legally, and without having to become software engineers to get there.

    Same AI everyone else uses. None of the exposure.Here's how it works. ↓
    01 — The Problem

    Regulated experts and Consultants hold five kinds of data. Only one is safe to put in AI.

    For the other four, a single prompt can break a law, leak a secret, or breach an NDA.

    Off-limits

    PII

    Personal identifiable information

    Risks a leakCould break a law
    Off-limits

    PHI

    Protected health information

    Risks a leakCould break a law
    Off-limits

    NDA secrets

    Data sealed under contract

    Risks a leakBreaches an NDA
    Off-limits

    Industrial secrets

    Trade secrets & proprietary IP

    Risks a leak
    AI-safe

    Non-confidential

    Public & unrestricted data

    Free to use with AI
    The bind

    So the real work — the confidential 80% — stays off AI entirely. That's the productivity being left on the table.

    Would you like to know more?

    Your people already use AI. Your secrets already leak.

    It's not a future risk or an edge case. Adoption is near-universal, it's deliberately hidden, and every hidden prompt carries data that can't leave the building. And the breach already has a price tag.

    The adoption01

    Your people already use AI every day — most of it chosen and run by them, not by you.

    78%
    bring their own AI (BYOAI)
    Used daily, not occasionallyFaster than any rollout you've approved
    Microsoft & LinkedIn, 2024 Work Trend Index
    The concealment02

    And they keep it quiet. More than half actively hide their AI use from their employer.

    57%
    conceal it from employers
    “We don't use AI” is a blind spot, not a factYou can't govern what you can't see
    KPMG · University of Melbourne, 2025
    The exposure03

    What goes in is the work itself — client records, financials, NDA-bound material — pasted into public tools on personal devices.

    48%
    uploaded company information into public tools
    19.2%
    of ALL employees pasted PII / PCI
    Confidential data, public model
    KPMG · Univ. of Melbourne 2025 · 19.2% derived from LayerX 2025
    The stakes

    When that data surfaces, it isn't theoretical. Breaches involving shadow AI cost about $670K more than the average incident, and in regulated sectors the bill runs into the millions. The leak is already happening; only the invoice is delayed.

    +$670K
    extra cost when a breach involves shadow AI ($4.63M vs $3.96M)
    1 in 5
    breaches now involves shadow AI
    97%
    of breached orgs lacked AI access controls
    $7.42M · $5.56M
    avg. breach cost, regulated sectors — healthcare · financial services

    Source: IBM Cost of a Data Breach 2025, Ponemon Institute (n = 604). Healthcare / financial figures are all-breach averages for those sectors, not shadow-AI-specific.

    The core problem

    The Ostrich Syndrome

    Employees in regulated industries need AI to work faster. Employers either ban it outright or hand over limited tools that don't satisfy them — so people bring their own, or paste sensitive data into free public AI on their personal devices.

    An ostrich buries its head in the sand beside a masked figure quietly emptying an office desk drawer of documents
    Adoption trend

    Professional-services AI adoption & unauthorized use, 2024–2025.

    02550751002024202535%estimated50%48%72%
    AI adoption (measured)Unauthorized use — 2025 measured, earlier modeled

    Intapp 2025 Technology Perceptions Survey, Rockbridge Research, n = 820 fee earners (US & UK; accounting, consulting, capital markets, legal). 72% use AI at work (up from 48% in 2024); 50% used unauthorized AI tools for work. Pre-2025 shadow values are modeled estimates.

    See all data + sources
    • Microsoft & LinkedIn, 2024 Work Trend Index — 78% of AI users bring their own AI to work (BYOAI).
    • KPMG & University of Melbourne, “Trust, Attitudes and Use of AI: A Global Study 2025” (n ≈ 48,000 across 47 countries) — 66% use AI regularly, 58% intentionally use it for work, 57% hide their AI use, 48% uploaded company information into public tools. kpmg.com/xx/en/our-insights/ai-and-technology/trust-attitudes-and-use-of-ai.html
    • LayerX, “Enterprise AI and SaaS Data Security Report 2025” (Oct 2025) — 19.2% of all employees pasted PII/PCI into public tools (derived: ~48% use GenAI × ~40% of file uploads include PII/PCI); ~77% of GenAI users paste data into prompts, 82% from unmanaged accounts. go.layerxsecurity.com/the-layerx-enterprise-ai-saas-data-security-report-2025
    • Intapp 2025 Technology Perceptions Survey (Rockbridge Research, n = 820 fee earners; US & UK — accounting, consulting, capital markets, legal) — 72% use AI at work, up from 48% in 2024; 50% used unauthorized AI tools for work. Pre-2025 shadow values are modeled estimates.
    • Anagram, July 2025 (n = 500) — 45% used banned AI tools, 40% would knowingly violate policy, 58% posted sensitive data (client records, financial data, internal documents). anagramsecurity.com/blog/2025-ai-in-the-workplace-survey
    • HR Dive / ClickOnDetroit — 48% uploaded sensitive company or customer info into AI chats.
    • IBM Cost of a Data Breach Report 2025, Ponemon Institute (n = 604 organizations) — shadow AI a factor in 1 in 5 breaches, +$670K per incident; 97% of breached orgs lacked AI access controls, 63% had no AI governance policy. ibm.com/reports/data-breach
    02 — Why this can't be fixed today

    Protect the data, or get usable AI. Until now you couldn't do both.

    Block public AI

    People use it anyway on their phones. Shadow AI, zero visibility.

    Dead end

    Send the real data

    An NDA breach, regulatory exposure, potentially breaking the law — and plainly unethical with health data. No amount of AI power is worth that many compromises and risks.

    Dead end

    Strip the data out

    Redaction / opaque tokenization: the AI is now reading [REDACTED] and x7Qk. It can't reason about what it can't see — it stalls or hallucinates, and output quality drops by half or more.

    Dead end

    Every road is a dead end. That's the problem no one else has solved.

    Why protection breaks AIWant to know more

    As AI adoption accelerates, we need to provide better sanctioned tools so employees aren't driven to shadow AI.

    Original— Sharp, specific, usable.
    AI receives

    Acme Corp is acquiring Beta Inc. for $400M, closing Q3. Draft a client advisory.

    AI returns

    Acme Corp's $400M acquisition of Beta Inc. is expected to close in Q3. Key risks and timelines below…

    🔓But the secret just left the building — this violates NDAs, confidentiality law and trade-secret protection. It can never be shared with a public model.

    ⚠️Redacted— Stalls / generic filler.
    AI receives

    [REDACTED] is acquiring [REDACTED] for [REDACTED], closing [REDACTED].

    AI returns

    I need the company names, deal value, and timeline before I can draft a meaningful advisory.

    Opaque tokens— Treats tokens as real, invents nonsense.
    AI receives

    x7Qk is acquiring 9zRm for §TKN_4, closing §TKN_9.

    AI returns

    x7Qk's acquisition of 9zRm positions it ahead of §TKN_9 competitors in the §TKN_4 sector…

    🔓Restored on your screen, the reply reads: “Acme Corp's acquisition of Beta Inc. positions it ahead of Q3 competitors in the $400M sector…” — the model treated the opaque tokens as real words, so even the restored text is nonsense.

    Hide the data and the AI can't reason about it. Both common fixes break the output.

    03 — The Solution

    Stop hiding it.
    Cloak it.

    Untraceable catches every confidential name and value, then cloaks each one with patent-pending Sequential and Semantic Cloaking before a single token reaches the AI. You clear what's safe and assign meaning-preserving cloaks to the rest — so the model writes fluently and accurately, while your secrets stay invisible.

    The AI sees the cloak. Only you see the truth.

    A masked thief opens the vault and finds it empty

    Crack the vault all you want. There's nothing inside but cloaks.

    Your real values never leave your environment. The model — and anyone who ever intercepts it — only ever reasons over informative stand-ins. Break in, and the box is empty.

    Your document — what you see

    The study evaluated Pembrolizumab in patients with non-small cell lung cancer at Memorial Sloan Kettering. The primary endpoint showed a hazard ratio of 0.68 (95% CI: 0.51–0.89).

    What the AI sees — cloaked

    The study evaluated NSSA_Drug_1 in patients with NSSA_Indication_1 at NSSA_InstitutionalInvestigator. The primary endpoint showed a hazard ratio of SSA_OSHR_POB_SMCID_KVM_CLIN_054 (95% CI: SLC_004431_012SLC_004532_054).

    Patent Pending
    04 — Why it holds and how it works

    Protection that doesn't lobotomize your AI.

    How much of the model's natural writing quality survives under each protection method. Patent-pending cloaking keeps nearly all of it.

    <20%
    Generic substitution
    32%
    Crypto-tokens
    37%
    Censoring
    91–93%
    SLC
    94–98%
    SSA

    Internal benchmark · composite writing-quality index · 30 tests per technique · patent-pending

    Read the preprint — Tremblay & Harricharan (2026)

    Would you like to learn how we do this? Click here

    From sensitive document to AI output — all on your computer, nothing exposed.

    01

    Open your document

    Word, Excel, PowerPoint and PDFs open right on your computer — they're never uploaded. Your Project Vault keeps everything encrypted and local to you.

    You

    You see everything

    As the human operator you always see the real values. Confidential data never leaves your computer.

    02

    Auto-detect & flag

    Untraceable scans the document on your computer and flags every potential confidential value — names, figures, identifiers. Confirm each in one click.

    Us

    We never see your data

    The cloaking runs entirely on your computer. Nothing reaches our servers — not your files, not your values, only the cloaks.

    03

    AI works for you

    VaultScribe, VaultChat and Blueprint send only cloaked data to the AI models. Your real values never leave your computer.

    AI

    AI sees only cloaks

    The patent-pending cloaking engine swaps sensitive values for informative, untraceable cloaks before anything is sent — preserving ~95% of AI writing quality.

    04

    Review & uncloak

    Cloaked results come back and are restored on your computer. You decide what to uncloak — keeping full control over what stays protected.

    Log

    Full audit trail

    Every AI submission is traceable. Protocol Certification and Sentinel auto-detection ensure nothing slips through.

    05 — The Suite

    Expert tools, all built on the cloak.

    Purpose-built for regulated industries — every tool runs on patent-pending cloaking technology.

    Cloaking

    Patent-pending Semantic and Sequential Cloaking. Every sensitive value is replaced with an informative cloak before any AI sees it — meaning preserved, exposure eliminated.

    VaultScribe

    A field-expert AI writer built on Hybrid RAG and a Grounding Codex — a field-specialized, human-anchored knowledge base. Drafts, rewrites and reviews on cloaked data — fluent in HEOR, regulatory and biostatistics.

    VaultChat

    A conversational assistant for quick questions and drafting on your documents. Every value is cloaked before it's sent, so you get fast answers from frontier AI without exposing a thing.

    VaultDelphi

    Multi-model consensus for high-stakes questions. Up to four AI models answer independently, then converge using the Delphi method — all on cloaked data — for a more robust, defensible answer.

    Blueprint

    Field-specific generators for report templates and AI instructions. Beat the blank page with compliance-aware structure.

    VaultCanvas

    Automated DOCX and XLS reporting from a single Excel source of truth — including secure, customer-facing report UIs.

    VaultStat

    Generate pseudo-IPD on cloaked data and auto-produce statistical code. Test and validate analyses under our quasi-encryption method.

    VaultAudit and Untraceable Protocol

    Certification, breach testing and oversight. On every account: an audit trail of every value, every cloak and every AI submission — with a breach test that certifies the cloak — retained in your own SharePoint. For Enterprise, VaultAudit adds organization-wide oversight: a live dashboard across every project and team member with cloak-coverage metrics, operator accountability, and permanent reports you can share with clients or your compliance officer. Cloaks only, never raw values.

    06 — Who it's for

    Built where confidentiality is non-negotiable.

    Available now

    Health Economics and Outcomes Research (HEOR), Payers & Real-World Evidence (RWE)

    Health economics, outcomes research, payer submissions and real-world evidence — protecting patient data, endpoints and proprietary results while AI accelerates evidence generation.

    Learn more →
    Available now

    Pharma, Biostatistics and Regulatory Affairs

    Regulatory submissions, safety reports and clinical study reports — product names, trial data and strategy stay confidential through AI-assisted drafting.

    Learn more →
    Coming soon

    ESG & Sustainability

    ESG reporting with confidential corporate metrics and audit data.

    Coming soon

    Management Consulting

    Strategy decks, client deliverables and financial models — client confidentiality preserved while AI does the heavy lifting.

    We're actively expanding into new fields. If your work demands advanced AI on confidential data — in any industry — we want to collaborate. Tell us what you're protecting and we'll build the cloaking keys and workflows around it.

    Start a conversation →
    Want to know more about what we are?

    Built for regulated work and consulting

    Tools adapted for consultants and regulated-industry experts to expand AI use legally and safely.

    Model agnostic

    Premium and standard AI models with in-country residency, used through residency-proof APIs.

    An AI compliance enabler

    Use AI while respecting your NDAs, confidentiality laws, and industrial secrets. Audit any project, train your teams, and track compliance on a live dashboard.

    Certified and auditable

    We certify your cloaked AI use — the AI never sees confidential data — backed by deep project audits and permanent reports you can send to clients or hand to your compliance officer.

    What we're not — and how we bridge it

    Not a consulting firm

    We're a compliance enabler — we never see your data in any form — so we don't deliver consulting ourselves.

    Instead we partner with approved consulting firms in your field, ready to support your Untraceable journey when you'd rather not run it yourself.

    Not a one-size SaaS giant

    We don't ship a custom build for every client off the shelf.

    For enterprise clients, we're glad to scope a pilot that brings new tools to your specific industry and needs.

    07 — Field-specific AI

    VaultScribe knows your field — not just your language.

    Hybrid Retrieval Augmented Generation (RAG) and a Grounding Codex — a field-specialized, human-anchored knowledge base — trained as expert writers in your regulatory and scientific landscape.

    Canada

    Canadian HEOR, Market Access, Regulatory & Biostatistics

    Hybrid RAG + Grounding Codex aligned with Health Canada requirements, Canadian HTA submission processes (CDA-AMC/INESSS), provincial payer submissions, and Canadian biostatistical standards.

    United States

    US HEOR, Market Access, Regulatory & Biostatistics

    Hybrid RAG + Grounding Codex aligned with FDA regulatory requirements, ICER value assessments, IRA and MFN pricing frameworks, AMCP dossier standards, and US biostatistical methodologies.

    Europe

    European HEOR, Market Access, Regulatory & Biostatistics

    Hybrid RAG + Grounding Codex aligned with EMA regulatory pathways, European HTA submission requirements (NICE, G-BA, HAS, AIFA, ZIN), EU joint clinical assessments, and EUnetHTA methodological guidelines.

    This is the starting line, not the finish. We're building new field-specific models continuously — and Enterprise subscribers can commission a custom Hybrid RAG + Grounding Codex purpose-built for their exact domain.

    FAQ

    The questions regulated teams ask first.

    Is this the same as encryption?

    No. Encryption scrambles data into ciphertext the AI cannot reason about. Untraceable replaces each confidential value with an informative, meaning-preserving cloak — so the model still writes fluently and accurately, while your real values never leave your environment.

    Does the AI ever see my real data?

    Never. The AI model only ever receives cloaked data — never your files, never your raw values. The truth is re-inserted only on your screen, after the AI responds. We never see it either.

    How is this different from redaction or anonymization?

    It's worth separating three things. Redaction removes the context the model needs. Opaque tokens (x7Qk, §TKN_4) leave it there but meaningless — the model treats them as real words and invents nonsense around them. Generic substitution swaps in fake values that break type and consistency, so the reasoning quietly goes wrong. Sequential and Semantic Cloaking preserves the meaning of each value — what kind of thing it is, how it relates to everything else in the document — so the model reasons correctly while your real values never leave your environment.

    Isn't this just a de-identification API?

    The idea of replacing confidential values with meaning-preserving stand-ins is not ours alone — there are APIs that do a version of it, and a research literature converging on it. But an API is a component, not a tool. To use one, a consultancy has to build the document handling, the review step, the drafting, the analysis, the restore, the audit trail — and hire the engineers to maintain it. We didn't ship the primitive. We shipped the work: VaultScribe, VaultStat, VaultDelphi and VaultAudit, built on the cloak, in the fields you actually work in.

    What happens if a cloaked document is intercepted?

    There is nothing to steal. Crack the vault all you want — anyone who intercepts the data only ever sees informative stand-ins, never your real names, figures or identifiers. The box is empty.

    Which industries is Untraceable built for?

    Regulated work where confidentiality is non-negotiable: HEOR, payers and biostatistics, plus pharma and regulatory affairs — with management consulting and ESG on the way. If your work demands advanced AI on confidential data, we want to collaborate.

    Where is my data stored?

    We don't store it — and we never see it. Your documents and real values stay in your own Microsoft 365 environment; cloaking and compute happen in your browser or your M365 account, so your data never leaves where it already lives. The only thing we keep is an audit trail of the cloaks, which never contains a single real value. We only ever see the cloak.

    Untraceable

    Ready to cloak your data?

    Join regulated teams already using Untraceable to harness AI without compromising confidentiality.