How we compare
A regulated consultant doesn't need another AI pipe to wire up, or another seat whose contract still sends the client's data to the model. You need one place to do confidential work end to end — drafting and updating reports, publications, statistics, full reporting and quality control — where the model never sees the secret. Here's how the options actually compare.
Most ways to use AI on confidential and secret data give you a fragment: a redaction API you still have to build a workflow around, an enterprise seat whose contract doesn't satisfy your client's NDA, or a Copilot that governs access but still shows the model your raw data. Untraceable is the only turnkey, vertical workspace where the model never receives the confidential value at all.
Each row is a category of approach a regulated consultant could take today — a de-identification API, an enterprise AI seat, Microsoft Copilot, or building your own — scored across the six things that decide whether it actually works for confidential deliverables: whether the real value reaches the model, whether it's turnkey or you have to build it, whether it's deep in your field, whether it carries the whole workflow, and whether it's auditable. The last row is Untraceable.
| Approach | Confidential value reaches the model? | Turnkey, or you build it? | Vertical depth in your field? | Full deliverable workflow? | Auditable & certifiable? |
|---|---|---|---|---|---|
| De-identification / redaction APIs (HIPAA scrubbing, crypto-tokens) | No — but redaction strips context, so quality craters (~32–37%) | You build the whole workflow and integrate the API | No — generic, not field-aware | No — it's a pipe, not tools | Partial |
| Enterprise AI seat (ChatGPT Enterprise, private LLM) | Yes — in full | Ready to use | No | No | Limited (vendor logs) |
| Microsoft Copilot | Yes — in full (governance controls access, not model exposure) | Ready, but needs the full E5 + Purview stack to be safe | No — generic assistant | Partial — generic office work | Limited |
| On-prem / build-your-own model | Exposed internally | Heaviest — you build and maintain everything | Only if you build it | Only if you build it | Build it yourself |
| Untraceable | Never — the model receives only cloaks (architectural, not contractual) | Turnkey — cloaking + eight tools, no infrastructure to build | Yes — Blueprint templates, Grounding Codex + region-aware Hybrid RAG | Yes — draft and update reports, generate statistics, full reporting and audit in one place | Yes — Sentinel breach test, certificate and full audit trail |
These are pipes, not workspaces. They scrub or tokenize a value and hand it back — you still have to build the drafting, statistics, reporting and audit around them, integrate the API, and maintain it. That is a months-long, six- or seven-figure engineering project before a single deliverable ships. And redaction alone strips the context the model reasons from, so quality drops to roughly a third of baseline. These aren't really our competitors — they're a component you'd otherwise have to buy and build a whole workflow around.
A vendor's no-training promise protects your firm's relationship with the vendor. It does not grant your client's consent to send their confidential data to that vendor — and the model still receives every value in full. The protection is a promise about what happens after the data arrives, not a guarantee that it never does.
The strongest mainstream posture — tenant isolation, Purview governance, a no-training contract — and the best generic assistant a consultant can buy. But governance controls who can access data; it doesn't stop the model from receiving your raw data. Under a client NDA the exposure remains, and reaching that posture takes the full E5 + Purview stack. Untraceable is complementary: it cloaks the confidential values before the text ever reaches Copilot, so you keep Copilot and lose the exposure.
You can host a model and own the whole stack — but you're building and maintaining it, on weaker models than the frontier, and the data is still exposed inside your own walls. It's the heaviest path to the weakest AI.
Generic tools give you a blank box. Untraceable goes deep in one regulated field at a time — so the AI already knows the rules of your work before you type a word.
Need a Canadian budget-impact analysis? Blueprint hands you the template, already anchored to the guideline rules and pre-loaded with AI instructions for each section. Feed it your primer and it produces the BIA skeleton — roughly half the work that used to take an analyst weeks. As the AI fills it in, the Grounding Codex feeds it the field's authoritative rules and definitions, so what comes back is aligned to the guidelines, not improvised.
A field-specific Hybrid RAG bundles the relevant guidelines, agency recommendations, presentation standards and laws for your regulated field and region — Health Canada and CDA-AMC/INESSS, FDA and ICER, EMA and NICE. The Grounding Codex — an expert-approved field encyclopedia — gives the model cross-references, authoritative sources and precise definitions as it writes. Together they make the AI fluent in your field, not just your language.
The reason nobody de-identifies before prompting is that it usually guts the output. Meaning-preserving cloaking doesn't: it protects the value while keeping almost all of the AI's writing quality.
| Method | AI writing quality retained | Why |
|---|---|---|
| Censoring / redaction | ~37% | Strips the context the model reasons from |
| Substitution / crypto-tokens | ~32% | Opaque tokens the model can't reason about |
| Rapid Cloaking | 91–93% | Position-aware stand-ins the model can reference |
| Advanced Cloaking | 94–98% | Stand-ins that encode each value's meaning + position |
Source: Tremblay & Harricharan (2026), Zenodo, doi:10.5281/zenodo.21343321. Composite writing-quality index, 30 tests per technique.
It solves one step, not the job. A de-identification or crypto-token API scrubs a value and hands it back — you still have to build the drafting, statistics, reporting and audit workflow around it, integrate the API, and maintain it. That's a months-long engineering project before a single deliverable ships. And redaction alone strips the context the model reasons from, so output quality drops to roughly a third of baseline. Untraceable is the workspace, not the pipe: cloaking plus the tools, turnkey.
Copilot is the strongest mainstream posture — tenant isolation, Purview governance, a no-training contract — and the best generic assistant a consultant can buy. But governance controls who can access data; it does not stop the model from receiving your raw data. Under a client NDA, the exposure remains, and reaching that posture takes the full E5 + Purview stack. Untraceable is complementary: it cloaks the confidential values before the text ever reaches Copilot or any model, so the model never sees the secret.
No. An enterprise agreement is between your firm and the AI vendor. Your NDA is between your firm and your client. A vendor's promise not to train on your data does not grant your client's consent to send their confidential data to that vendor — and the model still receives every value in full. Architecture, not a contract, is what removes the disclosure.
It goes deep in one regulated field at a time. Blueprint provides guideline-anchored report templates — ask for a Canadian budget-impact analysis and you get the template pre-loaded with AI instructions; feed it your primer and it produces the BIA skeleton, roughly half of work that used to take an analyst weeks. A field-specific Hybrid RAG bundles the relevant guidelines, agency recommendations and laws, and the Grounding Codex — an expert-approved field encyclopedia — feeds the AI authoritative definitions and sources as it writes. Generic tools do none of this.
No. The infrastructure players ship an API you have to wrap in your own AI workflow — an expensive, months-long build. Untraceable is turnkey: cloaking plus eight tools (drafting, chat, multi-model consensus, templates, reporting, statistics, and audit) work out of the box inside your Microsoft 365 environment, with nothing to build or maintain.
On the cloaking names. Rapid Cloaking and Advanced Cloaking are the commercial names for the two patent-pending methods — sequential cloaking (SLC) and semantic cloaking (SSA) respectively in the patent and research wording.
On the quality figures. Scores are a composite writing-quality index rebalanced out of a 97% baseline (uncensored text is not itself scored as perfect). The underlying ISPOR submission and pitch materials report the raw values; the rebalanced figures shown here express each method as a share of that baseline for comparison.
Cloaking plus eight tools — Blueprint, VaultChat and VaultDelphi, VaultStat, VaultCanvas, VaultScribe, VaultPublish, and VaultAudit / the Untraceable Protocol — inside your Microsoft 365 environment, where the model never receives the confidential value at all.