FAQ
How cloaking differs from encryption and redaction, whether the AI ever sees your real values, where your data lives, and how each tool works — answered in one place. Every answer links to the full page when you want to go deeper.
No. Encryption scrambles data into ciphertext the AI cannot reason about. Untraceable replaces each confidential value with an informative, meaning-preserving cloak — so the model still writes fluently and accurately, while your real values never leave your environment.
Read more: Semantic Cloaking, explained →Never. The AI model only ever receives cloaked data — never your files, never your raw values. The truth is re-inserted only on your screen, after the AI responds. We never see it either.
Read more: Security architecture →It's worth separating three things. Redaction removes the context the model needs. Opaque tokens (x7Qk, §TKN_4) leave it there but meaningless — the model treats them as real words and invents nonsense around them. Generic substitution swaps in fake values that break type and consistency, so the reasoning quietly goes wrong. Rapid and Advanced Cloaking preserve the meaning of each value — what kind of thing it is, how it relates to everything else in the document — so the model reasons correctly while your real values never leave your environment.
Read more: What redaction costs you →The idea of replacing confidential values with meaning-preserving stand-ins is not ours alone — there are APIs that do a version of it, and a research literature converging on it. But an API is a component, not a tool. To use one, a consultancy has to build the document handling, the review step, the drafting, the analysis, the restore, the audit trail — and hire the engineers to maintain it. We didn't ship the primitive. We shipped the work: VaultScribe, VaultStat, VaultDelphi and VaultAudit, built on the cloak, in the fields you actually work in.
Read more: How Untraceable compares →There is nothing to steal. Crack the vault all you want — anyone who intercepts the data only ever sees informative stand-ins, never your real names, figures or identifiers. The box is empty.
Read more: Security architecture →Regulated work where confidentiality is non-negotiable: HEOR, payers and biostatistics, plus pharma and regulatory affairs — with management consulting and ESG on the way. If your work demands advanced AI on confidential data, we want to collaborate.
Read more: Industries →We don't store it — and we never see it. Your documents and real values stay in your own Microsoft 365 environment; cloaking and compute happen in your browser or your M365 account, so your data never leaves where it already lives. What we keep is cloak-level — the cloak audit trail and, for conversational tools, the cloaked prompts and responses — none of which contains a single real value. We only ever see the cloak.
Read more: Security architecture →Cloaking is Untraceable's patent-pending method for replacing each confidential value — a name, a price, an NDA-bound term — with an informative, meaning-preserving cloak before any AI model sees the text. Two tiers: Rapid (sequential) Cloaking retains 91–93% of the model's natural writing quality, and Advanced (semantic) Cloaking retains 94–98% (Tremblay & Harricharan, 2026, doi:10.5281/zenodo.21343321). Unlike redaction, the model keeps the context it needs to write well; unlike encryption, the cloak is something the model can reason over.
Read more: Cloaking + VaultScribe →VaultScribe is a field-expert AI writer built on top of Cloaking. It drafts, rewrites and reviews regulated documents — HEOR dossiers, regulatory submissions, biostatistics narratives — using Hybrid RAG and a human-anchored Grounding Codex for domain accuracy. Because it runs on cloaked data, you get frontier-model writing quality without ever sending the confidential value to the model.
Read more: Cloaking + VaultScribe →Never. Cloaking runs client-side, in your browser, before anything is transmitted. The AI receives only cloaks; your files and real values stay in your own environment. VaultScribe re-inserts the truth on your screen after the model responds — we never see it either.
Read more: Cloaking + VaultScribe →De-identification strips context, which guts writing quality and invites hallucination, and it protects persons — not the information an NDA covers. VaultScribe's cloaks preserve meaning, so writing quality stays near-frontier, and it is purpose-built for the document types regulated experts actually produce, with an audit trail of every cloak and every AI submission.
Read more: Cloaking + VaultScribe →Health economics and outcomes research (HEOR), market access, regulatory affairs, medical writing and biostatistics today, with management consulting and ESG expanding. The Grounding Codex anchors drafts to real, field-specific references rather than the model's unaided priors.
Read more: Cloaking + VaultScribe →VaultChat is a conversational AI assistant for quick questions and drafting on your own documents. Every confidential value is cloaked on your computer before the message is sent, so you get fast answers from frontier AI without exposing a thing. The truth is re-inserted only on your screen, after the model responds.
Read more: VaultChat + VaultDelphi →VaultDelphi is a multi-model consensus mode for high-stakes questions. Up to four AI models answer independently on the same cloaked input, then converge using the Delphi method — a structured process for reconciling expert opinions — to produce a more robust, defensible answer than any single model gives alone.
Read more: VaultChat + VaultDelphi →Use VaultChat for speed — quick questions, iterative drafting, everyday work. Use VaultDelphi when the answer has to hold up: a contested methodological choice, a regulatory judgment call, anything where you want several frontier models to independently agree before you rely on it. Both run entirely on cloaked data.
Read more: VaultChat + VaultDelphi →Never. Cloaking runs client-side before any message leaves your browser, so every model — one in VaultChat, up to four in VaultDelphi — receives only cloaks. Your files and real values stay in your own environment, and every submission is auditable, recording cloaks and run IDs but never a real value.
Read more: VaultChat + VaultDelphi →VaultDelphi is model-agnostic and routes through residency-proof APIs across premium and standard frontier models, so consensus is drawn from genuinely independent systems rather than several versions of one. Region is honored where a model offers an in-region endpoint; models without one run in a US region on cloaked text (disclosed) — never a silent cross-region switch.
Read more: VaultChat + VaultDelphi →VaultStat is Untraceable's statistical-analysis tool. It generates pseudo-IPD (individual patient data) on cloaked inputs and auto-produces statistical code, so you can test and validate analyses under Untraceable's quasi-encryption cloaking method without exposing real patient-level data to any AI model.
Read more: VaultStat →VaultStat is in development and coming soon. You can request early access through the demo form, and we'll bring you in as it opens to pilot users.
Read more: VaultStat →Like every Untraceable tool, VaultStat runs on the cloaking engine: confidential values are cloaked on your own computer before anything reaches an AI model. VaultStat works with pseudo-IPD and cloaked inputs, so the analysis and generated code never depend on the AI receiving a real value.
Read more: VaultStat →Blueprint is Untraceable's library of field-specific generators for report templates and AI instructions. Instead of starting from a blank page, you begin with compliance-aware structure — document scaffolds and prompt patterns tuned to regulated work in HEOR, regulatory affairs and biostatistics.
Read more: Blueprint →Blueprint is coming soon. You can request early access through the demo form and we'll bring you in as it opens to pilot users.
Read more: Blueprint →A generic prompt library gives you text to paste. Blueprint gives you field-specific report templates and AI instructions that are compliance-aware and wired into the rest of the Untraceable suite — so the structure you start from already fits the document types regulated experts have to produce, and everything downstream still runs on cloaked data.
Read more: Blueprint →VaultCanvas is Untraceable's automated reporting tool. From a single Excel source of truth it produces polished DOCX and PPT reports — including secure, customer-facing report user interfaces — so a report and its underlying numbers stay in sync from one place. It is residency-native and built on the Microsoft Graph API.
Read more: VaultCanvas →VaultCanvas is coming soon. You can request early access through the demo form and we'll bring you in as it opens to pilot users.
Read more: VaultCanvas →VaultCanvas is residency-native and works inside your own Microsoft 365 environment through the Graph API, so your source data stays where it already lives. Any AI-assisted step runs on Untraceable's cloaking engine — the AI only ever sees cloaks, never your real values.
Read more: VaultCanvas →Under most standard NDAs, yes. Sending client-confidential information to a public AI service transmits it to a third party the client never authorized, which is precisely what a non-disclosure clause forbids. The breach happens at the moment of disclosure — whether or not the AI provider stores or trains on the data.
Read more: Read the full guide →Not by itself. Enterprise terms are an agreement between your firm and the AI vendor: they reduce the risk that the vendor misuses your data. Your NDA is a separate agreement between your firm and your client. Unless the client authorized disclosure to that vendor, sending their confidential data to an enterprise AI service can still be an unauthorized disclosure — with better safeguards, but a disclosure nonetheless.
Read more: Read the full guide →Information that is not confidential (public data, your own general knowledge, fully synthetic examples), information the client has authorized for the specific tool, or text from which the confidential values have been removed before it reaches the model. The last route only satisfies the NDA if the removal is complete and verifiable — and it only stays useful if the AI can still reason about what remains.
Read more: Read the full guide →Only partly. Redaction that strips names may still disclose confidential business information — pricing, strategy, unpublished results are confidential in themselves, not because a name is attached. And heavy redaction destroys the context the AI needs, degrading output quality sharply. This is the gap cloaking addresses: confidential values are replaced with semantic markers on your computer, so the model never receives them but can still reason about the document.
Read more: Read the full guide →Modern NDAs increasingly address AI directly: whether confidential information may be processed by AI systems at all, which deployment classes are permitted (public, enterprise, or architectures where the model never receives confidential values), and what audit evidence the disclosing party can request. If your NDAs are silent on AI, the general non-disclosure clause still governs — silence is not permission. Our recommendation when you adjust your NDA: don't let your secrets leak when you can get the power of AI without sharing them. Allow your data to be cloaked, but restrict any dumping of your raw data into online AI tools.
Read more: Read the full guide →No. Names are one kind of confidential value, not the definition of confidentiality. A cost model, an unpublished trial endpoint, or a pricing strategy is confidential in itself under an NDA — removing the names attached to it does not release it from the agreement.
Read more: Read the full guide →Not in general. Safe Harbor is a health-privacy standard: it removes 18 categories of identifiers so that information no longer relates to an identifiable person. An NDA protects information itself — trade secrets, business terms, unpublished results — regardless of whether any person is identifiable. The two frameworks answer different questions, and satisfying one does not satisfy the other.
Read more: Read the full guide →Privacy is about persons: it restricts the use of information that identifies or relates to an individual, and it is governed by laws like HIPAA, GDPR and PIPEDA. Confidentiality is about obligations: it restricts disclosure of information you agreed to protect, whoever it concerns, and it is governed by contracts — NDAs, engagement letters, employment terms. AI tools built for privacy (PII/PHI redaction) do not automatically address confidentiality.
Read more: Read the full guide →Semantic cloaking replaces each confidential value in a text with an informative marker — one that preserves the value's role and meaning for reasoning — before the text leaves the user's computer. The AI model receives only the cloaked text and never the underlying value; the real values are restored locally for the human operator. Unlike redaction, the model can still reason about the document; unlike fixed-identifier tokenization, it applies to any confidential value, not a fixed list of 18.
Read more: Read the full guide →It depends on the method. Blunt redaction and random tokenization destroy the context a model needs — internal benchmarks put retained writing quality near a third of baseline. Semantic cloaking, which preserves each value's meaning, retains roughly 95% of output quality (Tremblay & Harricharan, 2026). The method, not the principle, determines the cost.
Read more: Read the full guide →It depends entirely on the method. Removing or opaquely replacing information — censoring/redaction and random substitution/tokenization — collapses quality to roughly a third of baseline (about 37% and 32% respectively). Methods that hide the value but keep its meaning — sequential and semantic cloaking — retain 91–98% of baseline writing quality (Tremblay & Harricharan, 2026).
Read more: Read the full guide →Because a language model reasons from context, and redaction removes the context. Replacing values with [REDACTED] or opaque tokens (x7Qk) leaves the model with nothing to reason about, so it stalls, hedges, or invents — and the writing quality drops by roughly two-thirds.
Read more: Read the full guide →Yes: cloaking that preserves meaning. Sequential cloaking (SLC) retained 91–93% of baseline quality and semantic cloaking (SSA) 94–98% in a controlled benchmark, because the cloaks encode each value's role and position so the model can still reason — while the real value is never transmitted.
Read more: Read the full guide →Yes. It comes from Tremblay & Harricharan (2026), a preprint on Zenodo (doi:10.5281/zenodo.21343321) comparing censorship, substitution, and sequential/semantic cloaking on AI writing quality in HEOR and market access, using a composite writing-quality index across 30 tests per technique.
Read more: Read the full guide →It is safer than consumer ChatGPT — enterprise terms include no-training commitments, retention controls and admin oversight. But 'safe' and 'authorized' are different questions. Sending a client's confidential data to any third-party AI service is a disclosure under a standard NDA, and the client's permission — not the vendor's terms — is what makes a disclosure authorized.
Read more: Read the full guide →No. Copilot's commercial data protection is a commitment from Microsoft to your organization about how prompts are handled. Your NDA is a commitment from your organization to your client about who may receive their information. Microsoft's promise cannot grant your client's consent.
Read more: Read the full guide →Three common cases: the input contains no client-confidential information; the client has authorized use of that specific AI system — which is compulsory in writing in a signed contract (an MSA or the NDA itself), with no conflicting clause between the NDA and MSA that would prevent the use; or your engagement terms expressly permit processing in approved third-party systems and the AI deployment meets those terms. Outside those cases, an enterprise licence reduces vendor risk without resolving the client obligation.
Read more: Read the full guide →A DPA (data processing agreement) and a BAA (business associate agreement) govern how a vendor processes data you send it — they sit between you and the vendor and address privacy law. An NDA sits between you and your client and addresses confidentiality. A vendor-side DPA or BAA can make the vendor a compliant processor; it cannot make your transmission to that vendor an authorized disclosure under the client's NDA.
Read more: Read the full guide →By ensuring the model never receives the confidential values. If every confidential value is replaced with a semantic cloak on the consultant's own computer before the text is transmitted, no client-confidential information is disclosed to the AI vendor — so there is nothing for the client to consent to. That is an architectural resolution rather than a contractual one.
Read more: Read the full guide →Increasingly, yes — ISPOR named AI the top HEOR trend for 2026–2027, and an ISPOR Working Group has published a taxonomy of generative AI applications across the HEOR workflow (Fleurence et al., Value in Health). Acceptance comes with conditions the field keeps repeating: human oversight, transparency about AI involvement, and traceability that survives HTA scrutiny.
Read more: Read the full guide →Anything confidential to a sponsor or client: drug names, specific mutations and targets, the target product profile (TPP), unpublished trial results and endpoints, unpublished economic and statistical results, pricing and market-access strategy, patient-level data, draft dossier content, and the sponsor's identity where the engagement itself is confidential. Under a standard NDA or engagement terms, sending these to a public AI service is an unauthorized third-party disclosure — regardless of how useful the model would be.
Read more: Read the full guide →Not by sending it to a model. Patient-level data carries both privacy obligations (HIPAA, GDPR, PIPEDA) and, in most engagements, sponsor confidentiality obligations. The workable pattern keeps the real data on your side: derive what the analysis needs locally — cloaked summaries or pseudo-IPD that preserves statistical structure — and let the model work on that instead.
Read more: Read the full guide →That every AI contribution to a deliverable can be reconstructed and defended afterwards: what was submitted to which model, when, what came back, and what a human accepted or changed. HTA bodies and sponsors increasingly expect this. In practice it requires an audit trail generated by the tooling itself — a policy document cannot reconstruct a submission after the fact.
Read more: Read the full guide →Three routes: restrict AI to public inputs only (safe but excludes most real work); obtain sponsor authorization for a specific enterprise AI deployment (valid but slow, and many sponsors decline — and it demands serious precautions with the BAA, privacy tooling and auditability, cutting no cost on advanced traceability); or cloak confidential values on the consultant's own computer so the model receives semantic and sequential markers instead of the sponsor's data. The third route preserves roughly 95% of output quality (Tremblay & Harricharan, 2026) while transmitting no confidential values at all — which is what cloaking is all about, so only you see the truth.
Read more: Read the full guide →Semantic cloaking is a technique that replaces each confidential value in a text with an informative marker — one that preserves the value's meaning and role for reasoning — before the text leaves the user's device. The AI model receives only the cloaked text and never the underlying value; the real values are restored locally, for the human operator only.
Read more: Read the full guide →Redaction removes information — it replaces a value with [REDACTED] or a black box, leaving the model nothing to reason about, so output quality collapses. Semantic cloaking removes the value but keeps an informative flag encoding what the value means and how it functions — so the model can still reason about the document while the specific confidential value is never sent.
Read more: Read the full guide →They are two cloak types in the same system. Every datapoint carries a sequential component (SLC) — a stable, position-aware marker that lets the AI locate, repeat and reference the value consistently across the document without knowing it. Semantic cloaks (SSA) add a semantic component on top of the sequential one, encoding the value's strategic meaning (for example, that a price is a premium launch price). In practice users cloak roughly 90% of values sequentially and reserve semantic cloaks for the ~10% of key value messages that carry strategic meaning — the best mix of protection and efficiency.
Read more: Read the full guide →Fixed-identifier tokenization and masking target a defined list — typically the 18 HIPAA identifiers — and swap them for opaque tokens (x7Qk) that carry no meaning. Semantic cloaking applies to any confidential value, not a fixed list, and its markers are informative rather than opaque, which is why AI output quality survives.
Read more: Read the full guide →No. Differential privacy adds statistical noise to protect individuals in aggregate datasets; homomorphic encryption lets computation run on encrypted data. Both are powerful for their use cases but don't fit interactive drafting with a general-purpose LLM. Semantic cloaking is a text-transformation applied before a normal model call — no noise, no special model, no encryption math on the model side.
Read more: Read the full guide →Far less than the alternatives. Because the markers preserve meaning, internal benchmarks measured roughly 94–98% of baseline writing quality retained under semantic cloaking (Tremblay & Harricharan, 2026), versus about 37% for censoring-style redaction and 32% for random tokenization.
Read more: Read the full guide →Yes. Employees are already using AI — surveys put concealed use above 50% — so the choice is between an explicit policy and an unwritten one enforced by individual judgment. A short, practical policy that tells people which tools are allowed for which data prevents both reckless use and blanket bans that push usage underground.
Read more: Read the full guide →At minimum: which data classes may go into which tool tier; the rule that client-confidential data requires either client authorization or an architecture where the model never receives it; a prohibition on public/consumer AI for any client data; a record-keeping expectation; and a named owner. It should be one or two pages, not a manual.
Read more: Read the full guide →A ban is a policy, but usually an ineffective one: it doesn't stop use, it stops disclosure of use. The measurable outcome of blanket bans is shadow AI on personal devices, which carries the highest breach cost. A permissioned policy — clear allowed tiers — protects confidentiality better than a prohibition nobody follows.
Read more: Read the full guide →It treats client-confidential data as its own tier with a hard rule: it may only be processed by AI when the client has authorized the specific system in writing, or when the confidential values never reach the model (client-side cloaking). This mirrors the legal reality that enterprise AI terms bind the vendor to you, not you to your client. However you proceed, use the data safely and make sure you have auditability and traceability — your relationship and reputation depend on it.
Read more: Read the full guide →If the data includes personal information about identifiable individuals and you're a private-sector organization operating in Canada, PIPEDA's rules on consent, purpose limitation, and safeguards apply — including when that data is processed by a third-party AI service. Sending personal information to an AI vendor is a use and often a transfer, both of which PIPEDA governs.
Read more: Read the full guide →Law 25 (the Act to modernize legislative provisions respecting the protection of personal information) adds stricter obligations for organizations handling Quebecers' personal information: mandatory privacy-impact assessments for systems and for transfers outside Quebec, transparency about automated decision-making, consent standards, and significant penalties. Processing personal data through an AI system can trigger the assessment and transparency duties.
Read more: Read the full guide →It depends on the data, the consent obtained, and the safeguards. Cross-border transfer isn't prohibited, but under PIPEDA it requires comparable protection and transparency, and under Law 25 it can require a privacy-impact assessment before the transfer. Data-residency controls (keeping processing in Canada) and, better, not transmitting the personal values at all, materially reduce this exposure.
Read more: Read the full guide →If personal values are cloaked on the user's device before any text reaches the AI model, the personal information is not transmitted to the AI vendor — so the cross-border-transfer and third-party-use questions that PIPEDA and Law 25 raise are reduced at the source. It does not remove your obligations for holding the data, but it narrows what leaves your environment to non-identifying markers.
Read more: Read the full guide →It solves one step, not the job. A de-identification or crypto-token API scrubs a value and hands it back — you still have to build the drafting, statistics, reporting and audit workflow around it, integrate the API, and maintain it. That's a months-long engineering project before a single deliverable ships. And redaction alone strips the context the model reasons from, so output quality drops to roughly a third of baseline. Untraceable is the workspace, not the pipe: cloaking plus the tools, turnkey.
Read more: See the full comparison →Copilot is the strongest mainstream posture — tenant isolation, Purview governance, a no-training contract — and the best generic assistant a consultant can buy. But governance controls who can access data; it does not stop the model from receiving your raw data. Under a client NDA, the exposure remains, and reaching that posture takes the full E5 + Purview stack. Untraceable is complementary: it cloaks the confidential values before the text ever reaches Copilot or any model, so the model never sees the secret.
Read more: See the full comparison →No. An enterprise agreement is between your firm and the AI vendor. Your NDA is between your firm and your client. A vendor's promise not to train on your data does not grant your client's consent to send their confidential data to that vendor — and the model still receives every value in full. Architecture, not a contract, is what removes the disclosure.
Read more: See the full comparison →It goes deep in one regulated field at a time. Blueprint provides guideline-anchored report templates — ask for a Canadian budget-impact analysis and you get the template pre-loaded with AI instructions; feed it your primer and it produces the BIA skeleton, roughly half of work that used to take an analyst weeks. A field-specific Hybrid RAG bundles the relevant guidelines, agency recommendations and laws, and the Grounding Codex — an expert-approved field encyclopedia — feeds the AI authoritative definitions and sources as it writes. Generic tools do none of this.
Read more: See the full comparison →No. The infrastructure players ship an API you have to wrap in your own AI workflow — an expensive, months-long build. Untraceable is turnkey: cloaking plus eight tools (drafting, chat, multi-model consensus, templates, reporting, statistics, and audit) work out of the box inside your Microsoft 365 environment, with nothing to build or maintain.
Read more: See the full comparison →Only if the redaction is complete and verifiable — and even then the output usually suffers, because a model can't reason about what's been blanked out. Manual redaction is slow, error-prone, and one missed value is a disclosure. Cloaking that preserves meaning protects the value without gutting the output.
Read more: See the full breakdown →No. An enterprise agreement is between your firm and the AI vendor; your NDA is between your firm and your client. A vendor's promise not to train on your data does not grant your client's consent to send their confidential data to that vendor. The data still reaches the model in full.
Read more: See the full breakdown →It rarely fits real practice. Provisioning is slow, it covers one client, and you can't run a practice across several sponsors' separate sandboxes. It's a valid option for a single long engagement, not a way to work.
Read more: See the full breakdown →You can, and it's compliant — but it only helps with the work that was already easy. The confidential 80% (the analysis, the argument, the numbers) is exactly the part AI can't touch under that approach.
Read more: See the full breakdown →A ban doesn't stop AI use; it stops supervised AI use. The work moves to a personal device with no log, no policy and no oversight — the exposure doesn't disappear, it just goes where nobody can see it.
Read more: See the full breakdown →The Untraceable Protocol is an open specification for auditable AI use on confidential data. It defines the record an organization should be able to produce for any AI-assisted deliverable: what was cloaked, what was submitted to which model, what returned, and who reviewed it — with confidential values never appearing in the record. It is a conformance target, not only a product feature.
Read more: Read the Protocol →Because the problem it solves — defending AI-assisted regulated deliverables to HTA reviewers, sponsors and compliance teams — is industry-wide, and a specification others can conform to is more useful (and more citable) than a proprietary feature. Untraceable implements the Protocol, but the Protocol is written so any tool or team can meet it.
Read more: Read the Protocol →No. The Protocol requires the record to reference cloak labels and run identifiers only — never real confidential values. That is what makes the record safe to retain, share with a client's compliance officer, or hand to a regulator.
Read more: Read the Protocol →Certification is a series of completeness and AI-breach tests: an opening screening that cloaks all values, a closing sentinel that catches anything the user may have missed, a cloak-coverage test confirming the AI receives exactly what the user reviewed, and a breach test confirming the AI cannot reconstruct any value. A certified run is one you can defend, and its certification report is part of the audit trail.
Read more: Read the Protocol →Longer-form guides, the plain-facts sheet, and the compliance protocol.
Tell us about your confidential-data workflow and we'll show you exactly how the cloak keeps it out of the model.