FAQ

    Everything regulated experts ask about AI on confidential data.

    How cloaking differs from encryption and redaction, whether the AI ever sees your real values, where your data lives, and how each tool works — answered in one place. Every answer links to the full page when you want to go deeper.

    Start here — the essentials

    Is this the same as encryption?

    No. Encryption scrambles data into ciphertext the AI cannot reason about. Untraceable replaces each confidential value with an informative, meaning-preserving cloak — so the model still writes fluently and accurately, while your real values never leave your environment.

    Does the AI ever see my real data?

    Never. The AI model only ever receives cloaked data — never your files, never your raw values. The truth is re-inserted only on your screen, after the AI responds. We never see your real values or your keys — cloaked text passes through us, and nothing else does.

    Can anyone tell my deliverable was written with AI?

    Increasingly, yes. Anthropic began embedding a watermark in Claude's text output on 2 August 2026, Google has marked Gemini text with SynthID since 2023, and other providers are rolling out their own schemes — with detection tooling arriving behind them. The mark is coming either way; the only variable is whether you can produce the record that shows the use was authorized, scoped and clean. A detected mark alongside a certification report is a compliance record. A detected mark with no record is a problem. Untraceable does not remove the mark and would not try to — it produces the audit that makes it defensible.

    How is this different from redaction or anonymization?

    It's worth separating three things. Redaction removes the context the model needs. Opaque tokens (x7Qk, §TKN_4) leave it there but meaningless — the model treats them as real words and invents nonsense around them. Generic substitution swaps in fake values that break type and consistency, so the reasoning quietly goes wrong. Rapid and Advanced Cloaking preserve the meaning of each value — what kind of thing it is, how it relates to everything else in the document — so the model reasons correctly while your real values never leave your environment.

    Isn't this just a de-identification API?

    The idea of replacing confidential values with meaning-preserving stand-ins is not ours alone — there are APIs that do a version of it, and a research literature converging on it. But an API is a component, not a tool. To use one, a consultancy has to build the document handling, the review step, the drafting, the analysis, the restore, the audit trail — and hire the engineers to maintain it. We didn't ship the primitive. We shipped the work: VaultScribe, VaultStat, VaultDelphi and VaultAudit, built on the cloak, in the fields you actually work in.

    What happens if a cloaked document is intercepted?

    All API traffic is encrypted in transit — TLS 1.2 minimum, TLS 1.3 with AES-256-GCM negotiated by default, and TLS 1.0 and 1.1 refused outright — so interception is unlikely in the first place. The stronger answer is that it would not matter if it happened. Before anything is transmitted, a submission has to clear a cloak-coverage test, a sentinel that catches stray numerical and alphanumeric values, and a breach test in which a separate model is given the cloaked text and told to reconstruct the real values — recover even one and the submission is rejected. Zero tolerance rather than a threshold, and a compulsory human certification step on top of it. In practice you could not tell the .md file we send — no company names, every secret cloaked — from an undergraduate's homework: there is nothing in it to trace back to you, and nothing in it to read.

    Are you SOC 2 or ISO 42001 certified?Not certified

    Not yet — neither is held today, and nothing on this site should be read as claiming otherwise. What exists now is architectural rather than attested: cloaking runs client-side, so no confidential value enters our infrastructure at all; per-document keys are held in your own Microsoft 365 tenant and never by us; every submission has to clear a cloak-coverage test, a sentinel, a breach test and a compulsory human certification before transmission, with a single recoverable cloak blocking it; and the full audit trail records every cloak and every AI submission. We are a member of the Microsoft AI Cloud Partner Program. SOC 2 Type I is to be initiated in late 2026, with ISO 42001 and SOC 2 Type II planned for H1 2027.

    Which industries is Untraceable built for?

    Regulated work where confidentiality is non-negotiable: HEOR, payers and biostatistics, plus pharma and regulatory affairs — with management consulting and ESG on the way. If your work demands advanced AI on confidential data, we want to collaborate.

    Where is my data stored?

    We don't store it — and we never see it. Your documents and real values stay in your own Microsoft 365 environment; cloaking and compute happen in your browser or your M365 account, so your data never leaves where it already lives. What we keep is cloak-level — cloak labels, run identifiers and which model answered — none of which contains a single real value. Conversation transcripts are saved to your own SharePoint, not to our servers. Cloaked text passes through us; your real values and your keys never leave your computer.

    Cloaking & VaultScribe

    Full page →

    What is Cloaking?

    Cloaking is Untraceable's patent-pending method for replacing each confidential value — a name, a price, an NDA-bound term — with an informative, meaning-preserving cloak before any AI model sees the text. Two tiers: Rapid (sequential) Cloaking retains 91–93% of the model's natural writing quality, and Advanced (semantic) Cloaking retains 94–98% (Tremblay & Harricharan, 2026, doi:10.5281/zenodo.21343321). Unlike redaction, the model keeps the context it needs to write well; unlike encryption, the cloak is something the model can reason over.

    What is VaultScribe?

    VaultScribe is a field-expert AI writer built on top of Cloaking. It drafts, rewrites and reviews regulated documents — HEOR dossiers, regulatory submissions, biostatistics narratives — using Hybrid RAG and a human-anchored Grounding Codex for domain accuracy. Because it runs on cloaked data, you get frontier-model writing quality without ever sending the confidential value to the model.

    Does the AI ever see my real data with VaultScribe?

    Never. Cloaking runs client-side, in your browser, before anything is transmitted. The AI receives only cloaks; your files and real values stay in your own environment. VaultScribe re-inserts the truth on your screen after the model responds — we never see your real values or your keys, only the cloaked text on its way to the model.

    How is VaultScribe different from a de-identification API plus ChatGPT?

    De-identification strips context, which guts writing quality and invites hallucination, and it protects persons — not the information an NDA covers. VaultScribe's cloaks preserve meaning, so writing quality stays near-frontier, and it is purpose-built for the document types regulated experts actually produce, with an audit trail of every cloak and every AI submission.

    Which fields is VaultScribe fluent in?

    Health economics and outcomes research (HEOR), market access, regulatory affairs, medical writing and biostatistics today, with management consulting and ESG expanding. The Grounding Codex anchors drafts to real, field-specific references rather than the model's unaided priors.

    VaultChat & VaultDelphi

    Full page →

    What is VaultChat?

    VaultChat is a conversational AI assistant for quick questions and drafting on your own documents. Every confidential value is cloaked on your computer before the message is sent, so you get fast answers from frontier AI without exposing a thing. The truth is re-inserted only on your screen, after the model responds.

    What is VaultDelphi?

    VaultDelphi is a multi-model consensus mode for high-stakes questions. Up to four AI models answer independently on the same cloaked input, then converge using the Delphi method — a structured process for reconciling expert opinions — to produce a more robust, defensible answer than any single model gives alone.

    When should I use VaultDelphi instead of VaultChat?

    Use VaultChat for speed — quick questions, iterative drafting, everyday work. Use VaultDelphi when the answer has to hold up: a contested methodological choice, a regulatory judgment call, anything where you want several frontier models to independently agree before you rely on it. Both run entirely on cloaked data.

    Does the AI ever see my real data in VaultChat or VaultDelphi?

    Never. Cloaking runs client-side before any message leaves your browser, so every model — one in VaultChat, up to four in VaultDelphi — receives only cloaks. Your files and real values stay in your own environment; what passes through us is cloaked text and nothing else, and every submission is auditable, recording cloaks and run IDs but never a real value.

    Which models does VaultDelphi use?

    VaultDelphi calls models from Anthropic, OpenAI and Google, so consensus is drawn from genuinely independent systems rather than several versions of one. The premium tier is Claude Opus 5, Claude Opus 4.8, GPT-5.6 Sol & Terra, GPT-5.4, Gemini 2.5 Pro; the standard tier is Claude Sonnet 4.6, Claude Haiku 4.5, GPT-5.6 Luna, GPT-5.4 mini. Every one of them is a third party, which is exactly why they only ever receive cloaks — the confidential value is replaced on your own computer before any of them is called. Region is honored where a model offers an in-region endpoint; models without one run in the US or on global deployments, on cloaked text (disclosed) — never a silent cross-region switch. Which models make the list is decided by measurement: we benchmark them on HEOR writing and publish the per-model scores.

    Do all four models in VaultDelphi watermark their output?

    Treat every model's output as potentially marked. The schemes differ by provider and are rolling out at different rates — Google has marked Gemini text with SynthID since 2023, Anthropic began marking Claude output on 2 August 2026, and only models launched on or after that date carry it at launch. VaultDelphi's audit trail records which models were used on which run, and it is included in the report you get at the end of the analysis; VaultChat's audit gives you the same full traceability for a conversation. That is the record that matters if provenance is ever questioned.

    VaultStat

    Full page →

    What is VaultStat?

    VaultStat is Untraceable's statistical-analysis tool. It generates pseudo-IPD (individual patient data) on cloaked inputs and auto-produces statistical code, so you can test and validate analyses under Untraceable's quasi-encryption cloaking method without exposing real patient-level data to any AI model.

    Is VaultStat available yet?

    VaultStat is in development and coming soon. You can request early access through the demo form, and we'll bring you in as it opens to pilot users.

    How does VaultStat protect patient-level data?

    Like every Untraceable tool, VaultStat runs on the cloaking engine: confidential values are cloaked on your own computer before anything reaches an AI model. VaultStat works with pseudo-IPD and cloaked inputs, so the analysis and generated code never depend on the AI receiving a real value.

    Blueprint

    Full page →

    What is Blueprint?

    Blueprint is Untraceable's library of field-specific generators for report templates and AI instructions. Instead of starting from a blank page, you begin with compliance-aware structure — document scaffolds and prompt patterns tuned to regulated work in HEOR, regulatory affairs and biostatistics.

    Is Blueprint available yet?

    Blueprint is coming soon. You can request early access through the demo form and we'll bring you in as it opens to pilot users.

    How is Blueprint different from a prompt library?

    A generic prompt library gives you text to paste. Blueprint gives you field-specific report templates and AI instructions that are compliance-aware and wired into the rest of the Untraceable suite — so the structure you start from already fits the document types regulated experts have to produce, and everything downstream still runs on cloaked data.

    VaultCanvas

    Full page →

    What is VaultCanvas?

    VaultCanvas is Untraceable's automated reporting tool. From a single Excel source of truth it produces polished DOCX and PPT reports — including secure, customer-facing report user interfaces — so a report and its underlying numbers stay in sync from one place. It is residency-native and built on the Microsoft Graph API.

    Is VaultCanvas available yet?

    VaultCanvas is coming soon. You can request early access through the demo form and we'll bring you in as it opens to pilot users.

    How does VaultCanvas keep data confidential?

    VaultCanvas is residency-native and works inside your own Microsoft 365 environment through the Graph API, so your source data stays where it already lives. Any AI-assisted step runs on Untraceable's cloaking engine — the AI only ever sees cloaks, never your real values.

    Does using AI break your NDA?

    Full page →

    Is it a breach of NDA to paste client information into ChatGPT?

    Under most standard NDAs, yes. Sending client-confidential information to a public AI service transmits it to a third party the client never authorized, which is precisely what a non-disclosure clause forbids. The breach happens at the moment of disclosure — whether or not the AI provider stores or trains on the data.

    Does ChatGPT Enterprise or Microsoft Copilot make AI use NDA-compliant?

    Not by itself. Enterprise terms are an agreement between your firm and the AI vendor: they reduce the risk that the vendor misuses your data. Your NDA is a separate agreement between your firm and your client. Unless the client authorized disclosure to that vendor, sending their confidential data to an enterprise AI service can still be an unauthorized disclosure — with better safeguards, but a disclosure nonetheless.

    What can consultants safely put into AI tools?

    Information that is not confidential (public data, your own general knowledge, fully synthetic examples), information the client has authorized for the specific tool, or text from which the confidential values have been removed before it reaches the model. The last route only satisfies the NDA if the removal is complete and verifiable — and it only stays useful if the AI can still reason about what remains.

    Does anonymizing or redacting client data make it safe for AI?

    Only partly. Redaction that strips names may still disclose confidential business information — pricing, strategy, unpublished results are confidential in themselves, not because a name is attached. And heavy redaction destroys the context the AI needs, degrading output quality sharply. This is the gap cloaking addresses: confidential values are replaced with semantic markers on your computer, so the model never receives them but can still reason about the document.

    What should an AI clause in an NDA actually say?

    Modern NDAs increasingly address AI directly: whether confidential information may be processed by AI systems at all, which deployment classes are permitted (public, enterprise, or architectures where the model never receives confidential values), and what audit evidence the disclosing party can request. If your NDAs are silent on AI, the general non-disclosure clause still governs — silence is not permission. Our recommendation when you adjust your NDA: don't let your secrets leak when you can get the power of AI without sharing them. Allow your data to be cloaked, but restrict any dumping of your raw data into online AI tools.

    De-identification is not confidentiality

    Full page →

    Does removing names make client data safe to put into AI?

    No. Names are one kind of confidential value, not the definition of confidentiality. A cost model, an unpublished trial endpoint, or a pricing strategy is confidential in itself under an NDA — removing the names attached to it does not release it from the agreement.

    Does HIPAA Safe Harbor de-identification satisfy an NDA?

    Not in general. Safe Harbor is a health-privacy standard: it removes 18 categories of identifiers so that information no longer relates to an identifiable person. An NDA protects information itself — trade secrets, business terms, unpublished results — regardless of whether any person is identifiable. The two frameworks answer different questions, and satisfying one does not satisfy the other.

    What is the difference between privacy and confidentiality?

    Privacy is about persons: it restricts the use of information that identifies or relates to an individual, and it is governed by laws like HIPAA, GDPR and PIPEDA. Confidentiality is about obligations: it restricts disclosure of information you agreed to protect, whoever it concerns, and it is governed by contracts — NDAs, engagement letters, employment terms. AI tools built for privacy (PII/PHI redaction) do not automatically address confidentiality.

    What is semantic cloaking?

    Semantic cloaking replaces each confidential value in a text with an informative marker — one that preserves the value's role and meaning for reasoning — before the text leaves the user's computer. The AI model receives only the cloaked text and never the underlying value; the real values are restored locally for the human operator. Unlike redaction, the model can still reason about the document; unlike fixed-identifier tokenization, it applies to any confidential value, not a fixed list of 18.

    How much AI output quality is lost when data is de-identified?

    It depends on the method. Blunt redaction and random tokenization destroy the context a model needs — internal benchmarks put retained writing quality near a third of baseline. Semantic cloaking, which preserves each value's meaning, retains roughly 95% of output quality (Tremblay & Harricharan, 2026). The method, not the principle, determines the cost.

    What redaction costs your AI output

    Full page →

    How much AI output quality do you lose when you de-identify data before a prompt?

    It depends entirely on the method. Removing or opaquely replacing information — censoring/redaction and random substitution/tokenization — collapses quality to roughly a third of baseline (about 37% and 32% respectively). Methods that hide the value but keep its meaning — sequential and semantic cloaking — retain 91–98% of baseline writing quality (Tremblay & Harricharan, 2026).

    Why does redaction hurt AI output so much?

    Because a language model reasons from context, and redaction removes the context. Replacing values with [REDACTED] or opaque tokens (x7Qk) leaves the model with nothing to reason about, so it stalls, hedges, or invents — and the writing quality drops by roughly two-thirds.

    Does any de-identification method keep AI quality high?

    Yes: cloaking that preserves meaning. Sequential cloaking (SLC) retained 91–93% of baseline quality and semantic cloaking (SSA) 94–98% in a controlled benchmark, because the cloaks encode each value's role and position so the model can still reason — while the real value is never transmitted.

    Is the ~95% figure published?

    Yes. It comes from Tremblay & Harricharan (2026), a preprint on Zenodo (doi:10.5281/zenodo.21343321) comparing censorship, substitution, and sequential/semantic cloaking on AI writing quality in HEOR and market access, using a composite writing-quality index across 30 tests per technique.

    Enterprise AI licences and your client's NDA

    Full page →

    Is ChatGPT Enterprise safe for client confidential data?

    It is safer than consumer ChatGPT — enterprise terms include no-training commitments, retention controls and admin oversight. But 'safe' and 'authorized' are different questions. Sending a client's confidential data to any third-party AI service is a disclosure under a standard NDA, and the client's permission — not the vendor's terms — is what makes a disclosure authorized.

    Does Microsoft 365 Copilot's commercial data protection satisfy an NDA?

    No. Copilot's commercial data protection is a commitment from Microsoft to your organization about how prompts are handled. Your NDA is a commitment from your organization to your client about who may receive their information. Microsoft's promise cannot grant your client's consent.

    When is enterprise AI enough on its own?

    Three common cases: the input contains no client-confidential information; the client has authorized use of that specific AI system — which is compulsory in writing in a signed contract (an MSA or the NDA itself), with no conflicting clause between the NDA and MSA that would prevent the use; or your engagement terms expressly permit processing in approved third-party systems and the AI deployment meets those terms. Outside those cases, an enterprise licence reduces vendor risk without resolving the client obligation.

    What is the difference between a DPA, a BAA, and an NDA in this context?

    A DPA (data processing agreement) and a BAA (business associate agreement) govern how a vendor processes data you send it — they sit between you and the vendor and address privacy law. An NDA sits between you and your client and addresses confidentiality. A vendor-side DPA or BAA can make the vendor a compliant processor; it cannot make your transmission to that vendor an authorized disclosure under the client's NDA.

    How can consultants use AI without triggering the client-consent problem at all?

    By ensuring the model never receives the confidential values. If every confidential value is replaced with a semantic cloak on the consultant's own computer before the text is transmitted, no client-confidential information is disclosed to the AI vendor — so there is nothing for the client to consent to. That is an architectural resolution rather than a contractual one.

    AI for HEOR

    Full page →

    Which AI model writes HEOR best?

    We measure it rather than assert it. General leaderboards score reasoning, code and trivia; none score whether a model can write a defensible HEOR or market-access deliverable. Our benchmark runs the same controlled task set across frontier models and scores the output with an AI-Delphi panel, and we publish the per-model results — including for models we do not offer and models that scored badly. In the 2026-06 round, unanchored scores ran from 66.3 to 79.1 across sixteen runs, with Claude Opus 4.8 on the Untraceable Grounding Codex at the top. The table is updated as new models arrive.

    Does a retrieval or grounding layer make an AI model better at HEOR writing?

    It depends on the model, and a vendor claiming a uniform uplift has not measured it per model. In our 2026-06 round, six models were scored both with and without the Untraceable Grounding Codex — a curated HTA, methods and reporting-standards layer retrieved at generation time. It raised three and lowered three. The gains landed on the strongest models (+4.7 on Claude Opus 4.8) and the losses on the smallest, because a retrieved knowledge layer is only worth what the model can do with it: a lighter model spends capacity reading the context instead of reasoning over it.

    Is AI use accepted in HEOR?

    Increasingly, yes — ISPOR named AI the top HEOR trend for 2026–2027, and an ISPOR Working Group has published a taxonomy of generative AI applications across the HEOR workflow (Fleurence et al., Value in Health, 2025;28(11):1601–1610, doi:10.1016/j.jval.2025.04.2167). The same group's HTA report is explicit about the conditions: foundation models should augment human activities for which humans remain fully accountable; reporting guidance and checklists should cover validation, reproducibility and bias; and it advises against putting protected health information into these models at all, because absolute de-identification is not attainable and re-identification risk stays non-zero (Fleurence et al., Value in Health, 2025;28(2):175–183, doi:10.1016/j.jval.2024.10.3846). Acceptance comes with conditions the field keeps repeating: human oversight, transparency about AI involvement, and traceability that survives HTA scrutiny.

    What HEOR data should never go into a public AI tool?

    Anything confidential to a sponsor or client: drug names, specific mutations and targets, the target product profile (TPP), unpublished trial results and endpoints, unpublished economic and statistical results, pricing and market-access strategy, patient-level data, draft dossier content, and the sponsor's identity where the engagement itself is confidential. Under a standard NDA or engagement terms, sending these to a public AI service is an unauthorized third-party disclosure — regardless of how useful the model would be.

    Can I use AI on patient-level data (IPD) in HEOR work?

    Not by sending it to a model. Patient-level data carries both privacy obligations (HIPAA, GDPR, PIPEDA) and, in most engagements, sponsor confidentiality obligations. The workable pattern keeps the real data on your side: derive what the analysis needs locally — cloaked summaries or pseudo-IPD that preserves statistical structure — and let the model work on that instead.

    What does 'traceability' mean for AI-assisted HEOR deliverables?

    That every AI contribution to a deliverable can be reconstructed and defended afterwards: what was submitted to which model, when, what came back, and what a human accepted or changed. HTA bodies and sponsors increasingly expect this. In practice it requires an audit trail generated by the tooling itself — a policy document cannot reconstruct a submission after the fact.

    How do HEOR consultancies use AI without breaching sponsor confidentiality?

    Three routes: restrict AI to public inputs only (safe but excludes most real work); obtain sponsor authorization for a specific enterprise AI deployment (valid but slow, and many sponsors decline — and it demands serious precautions with the BAA, privacy tooling and auditability, cutting no cost on advanced traceability); or cloak confidential values on the consultant's own computer so the model receives semantic and sequential markers instead of the sponsor's data. The third route preserves roughly 95% of output quality (Tremblay & Harricharan, 2026) while transmitting no confidential values at all — which is what cloaking is all about, so only you see the truth.

    Semantic cloaking, explained

    Full page →

    What is semantic cloaking?

    Semantic cloaking is a technique that replaces each confidential value in a text with an informative marker — one that preserves the value's meaning and role for reasoning — before the text leaves the user's device. The AI model receives only the cloaked text and never the underlying value; the real values are restored locally, for the human operator only.

    How is semantic cloaking different from redaction?

    Redaction removes information — it replaces a value with [REDACTED] or a black box, leaving the model nothing to reason about, so output quality collapses. Semantic cloaking removes the value but keeps an informative flag encoding what the value means and how it functions — so the model can still reason about the document while the specific confidential value is never sent.

    What is the difference between sequential and semantic cloaking?

    They are two cloak types in the same system. Every datapoint carries a sequential component (SLC) — a stable, position-aware marker that lets the AI locate, repeat and reference the value consistently across the document without knowing it. Semantic cloaks (SSA) add a semantic component on top of the sequential one, encoding the value's strategic meaning (for example, that a price is a premium launch price). In practice users cloak roughly 90% of values sequentially and reserve semantic cloaks for the ~10% of key value messages that carry strategic meaning — the best mix of protection and efficiency.

    How is it different from tokenization or masking?

    Fixed-identifier tokenization and masking target a defined list — typically the 18 HIPAA identifiers — and swap them for opaque tokens (x7Qk) that carry no meaning. Semantic cloaking applies to any confidential value, not a fixed list, and its markers are informative rather than opaque, which is why AI output quality survives.

    Is semantic cloaking the same as differential privacy or homomorphic encryption?

    No. Differential privacy adds statistical noise to protect individuals in aggregate datasets; homomorphic encryption lets computation run on encrypted data. Both are powerful for their use cases but don't fit interactive drafting with a general-purpose LLM. Semantic cloaking is a text-transformation applied before a normal model call — no noise, no special model, no encryption math on the model side.

    Does semantic cloaking reduce AI quality?

    Far less than the alternatives. Because the markers preserve meaning, internal benchmarks measured roughly 94–98% of baseline writing quality retained under semantic cloaking (Tremblay & Harricharan, 2026), versus about 37% for censoring-style redaction and 32% for random tokenization.

    AI use policy for consulting firms

    Full page →

    Does a consulting firm need an AI use policy?

    Yes. Employees are already using AI — surveys put concealed use above 50% — so the choice is between an explicit policy and an unwritten one enforced by individual judgment. A short, practical policy that tells people which tools are allowed for which data prevents both reckless use and blanket bans that push usage underground.

    What should an AI use policy for consultants cover?

    At minimum: which data classes may go into which tool tier; the rule that client-confidential data requires either client authorization or an architecture where the model never receives it; a prohibition on public/consumer AI for any client data; a record-keeping expectation; and a named owner. It should be one or two pages, not a manual.

    Can we just ban AI instead?

    A ban is a policy, but usually an ineffective one: it doesn't stop use, it stops disclosure of use. The measurable outcome of blanket bans is shadow AI on personal devices, which carries the highest breach cost. A permissioned policy — clear allowed tiers — protects confidentiality better than a prohibition nobody follows.

    How does this template handle client NDAs?

    It treats client-confidential data as its own tier with a hard rule: it may only be processed by AI when the client has authorized the specific system in writing, or when the confidential values never reach the model (client-side cloaking). This mirrors the legal reality that enterprise AI terms bind the vendor to you, not you to your client. However you proceed, use the data safely and make sure you have auditability and traceability — your relationship and reputation depend on it.

    PIPEDA, Law 25 and generative AI

    Full page →

    Does PIPEDA apply to using AI on client data?

    If the data includes personal information about identifiable individuals and you're a private-sector organization operating in Canada, PIPEDA's rules on consent, purpose limitation, and safeguards apply — including when that data is processed by a third-party AI service. Sending personal information to an AI vendor is a use and often a transfer, both of which PIPEDA governs.

    What does Quebec's Law 25 add for AI?

    Law 25 (the Act to modernize legislative provisions respecting the protection of personal information) adds stricter obligations for organizations handling Quebecers' personal information: mandatory privacy-impact assessments for systems and for transfers outside Quebec, transparency about automated decision-making, consent standards, and significant penalties. Processing personal data through an AI system can trigger the assessment and transparency duties.

    Can I send Canadians' personal data to a US-based AI model?

    It depends on the data, the consent obtained, and the safeguards. Cross-border transfer isn't prohibited, but under PIPEDA it requires comparable protection and transparency, and under Law 25 it can require a privacy-impact assessment before the transfer. Data-residency controls (keeping processing in Canada) and, better, not transmitting the personal values at all, materially reduce this exposure.

    How does client-side cloaking help with PIPEDA and Law 25?

    If personal values are cloaked on the user's device before any text reaches the AI model, the personal information is not transmitted to the AI vendor — so the cross-border-transfer and third-party-use questions that PIPEDA and Law 25 raise are reduced at the source. It does not remove your obligations for holding the data, but it narrows what leaves your environment to non-identifying markers.

    The AI governance gap

    Full page →

    Does confidential-AI tooling replace our identity and access management?

    No. Identity controls govern who and what may reach a model — credentials, non-human identities, agent permissions, shadow-agent discovery. Untraceable governs what the model actually receives once they do. Both layers are necessary, and they are complements rather than substitutes.

    Why do employees use unapproved AI tools?

    Okta's AI Agents at Work 2026 asked them. 80% said it is easier to use their own accounts, 78% that their team already uses it, 57% that approval is too slow, and 49% that the approved tools do not meet their needs. Only 6% did not know approval was required — so only 6% of it is an awareness problem, and the rest is a product problem that stricter policy will not solve.

    How big is the gap between what executives believe and what staff do?

    Okta's AI Agents at Work 2026 found 90% of executives confident in their visibility into which AI tools are in use and 95% confident their employees use AI responsibly — while 52% of knowledge workers reported using AI without IT approval, and 24% do so regularly. Among those using unapproved tools, 39% shared confidential company documents including financials and contracts. The study screened for knowledge workers who already use AI, so those worker percentages describe AI users rather than a general workforce.

    Can we prove compliant AI use to an auditor?

    Yes. Protocol Certification produces a permanent, shareable report certifying that the cloak held under breach testing, and the audit trail records every AI submission at cloak level. Both are designed to be handed to a client or a compliance officer without further preparation.

    Does the audit trail itself contain confidential data?

    No. It records cloak labels and run identifiers only, never real values. It is safe to share by construction. Audit records are stored in your project's region, United States or Canada, and never contain a raw value; conversation transcripts are saved to your own SharePoint.

    Is Untraceable affiliated with Okta?

    No. Okta's published research is cited as independent third-party evidence, with attribution. Okta is not a partner, sponsor, endorser or affiliate of Untraceable, has no commercial relationship with us, and has not reviewed or approved our use of their findings. Any interpretation of their data is ours alone.

    How Untraceable compares

    Full page →

    Isn't a redaction or de-identification API enough to use AI on confidential data?

    It solves one step, not the job. A de-identification or crypto-token API scrubs a value and hands it back — you still have to build the drafting, statistics, reporting and audit workflow around it, integrate the API, and maintain it. That's a months-long engineering project before a single deliverable ships. And redaction alone strips the context the model reasons from, so output quality drops to roughly a third of baseline. Untraceable is the workspace, not the pipe: cloaking plus the tools, turnkey.

    Does Microsoft Copilot solve confidential AI use for a regulated consultant?

    Copilot is the strongest mainstream posture — tenant isolation, Purview governance, a no-training contract — and the best generic assistant a consultant can buy. But governance controls who can access data; it does not stop the model from receiving your raw data. Under a client NDA, the exposure remains, and reaching that posture takes the full E5 + Purview stack. Untraceable is complementary: it cloaks the confidential values before the text ever reaches Copilot or any model, so the model never sees the secret.

    Does an enterprise ChatGPT or Copilot licence satisfy my client's NDA?

    No. An enterprise agreement is between your firm and the AI vendor. Your NDA is between your firm and your client. A vendor's promise not to train on your data does not grant your client's consent to send their confidential data to that vendor — and the model still receives every value in full. Architecture, not a contract, is what removes the disclosure.

    What makes Untraceable 'vertical' rather than a generic AI tool?

    It goes deep in one regulated field at a time. Blueprint provides guideline-anchored report templates — ask for a Canadian budget-impact analysis and you get the template pre-loaded with AI instructions; feed it your primer and it produces the BIA skeleton, roughly half of work that used to take an analyst weeks. A field-specific Hybrid RAG bundles the relevant guidelines, agency recommendations and laws, and the Grounding Codex — an expert-approved field encyclopedia — feeds the AI authoritative definitions and sources as it writes. Generic tools do none of this.

    Do I have to build or integrate anything to use Untraceable?

    No. The infrastructure players ship an API you have to wrap in your own AI workflow — an expensive, months-long build. Untraceable is turnkey: cloaking plus eight tools (drafting, chat, multi-model consensus, templates, reporting, statistics, and audit) work out of the box inside your Microsoft 365 environment, with nothing to build or maintain.

    How Untraceable is different

    Full page →

    Can I use a public AI chatbot if I redact the client data first?

    Only if the redaction is complete and verifiable — and even then the output usually suffers, because a model can't reason about what's been blanked out. Manual redaction is slow, error-prone, and one missed value is a disclosure. Cloaking that preserves meaning protects the value without gutting the output.

    Does my company's enterprise AI licence cover my client's NDA?

    No. An enterprise agreement is between your firm and the AI vendor; your NDA is between your firm and your client. A vendor's promise not to train on your data does not grant your client's consent to send their confidential data to that vendor. The data still reaches the model in full.

    Should I just wait for the client's own AI environment?

    It rarely fits real practice. Provisioning is slow, it covers one client, and you can't run a practice across several sponsors' separate sandboxes. It's a valid option for a single long engagement, not a way to work.

    Can I use AI only for the non-confidential parts?

    You can, and it's compliant — but it only helps with the work that was already easy. The confidential 80% (the analysis, the argument, the numbers) is exactly the part AI can't touch under that approach.

    My firm banned AI — is using it anyway a problem?

    A ban doesn't stop AI use; it stops supervised AI use. The work moves to a personal device with no log, no policy and no oversight — the exposure doesn't disappear, it just goes where nobody can see it.

    The Untraceable Protocol

    Full page →

    What is the Untraceable Protocol?

    The Untraceable Protocol is an open specification for auditable AI use on confidential data. It defines the record an organization should be able to produce for any AI-assisted deliverable: what was cloaked, what was submitted to which model, what returned, and who reviewed it — with confidential values never appearing in the record. It is a conformance target, not only a product feature.

    Why publish it as a specification instead of a feature?

    Because the problem it solves — defending AI-assisted regulated deliverables to HTA reviewers, sponsors and compliance teams — is industry-wide, and a specification others can conform to is more useful (and more citable) than a proprietary feature. Untraceable implements the Protocol, but the Protocol is written so any tool or team can meet it.

    Does the audit record contain confidential data?

    No. The Protocol requires the record to reference cloak labels and run identifiers only — never real confidential values. That is what makes the record safe to retain, share with a client's compliance officer, or hand to a regulator.

    What does Protocol Certification mean?

    Certification is a series of completeness and AI-breach tests: an opening screening that cloaks all values, a closing sentinel that catches anything the user may have missed, a cloak-coverage test confirming the AI receives exactly what the user reviewed, and a breach test confirming the AI cannot reconstruct any value. The breach test is pass/fail with zero tolerance — a single recoverable cloak blocks the submission. A certified run is one you can defend, and its certification report is part of the audit trail.

    Does cloaking remove the AI watermark?

    No, and deliberately so. Cloaking governs what the model receives, not what it emits — the text that comes back is watermarked like any other model output. The mark is statistical, a bias in which candidate word the model selects, and it carries no identifying information, so it reveals nothing about you, your client or the document. Removing a provider watermark would defeat a transparency mechanism the industry and regulators are now building on, and it is not something we will do. As a consultant or a regulated-industry expert, it is not something you should be approaching either — the goal is to use AI safely and legally while preserving your secrets, not to hide that you used it.

    Is it illegal to remove an AI watermark?

    As of August 2026 no general US or Canadian statute makes removal a criminal or civil offence on its own — which is the weakest reason not to do it. It breaches every frontier provider's terms of use, and that can mean throttling, suspension or termination of access. California's AI Transparency Act builds the consequence into the supply chain: a covered provider that learns a licensee has stripped or disabled a latent disclosure must revoke that licensee's access within 96 hours, so the sanction arrives through your vendor rather than a regulator. In the EU, Article 50 of the AI Act places the marking duty on providers, and the emerging reading is that deployers must not suppress or defeat provider-embedded disclosures — where you carry your own disclosure duty, removal works directly against it. The sharpest point for regulated work is simpler: deliberate removal is evidence of intent to conceal, which converts a policy question into a bad-faith question in front of a regulator, an HTA agency, a government body, or a client that simply wants transparency. The tools that strip marks are betting against the direction of regulation, and a regulated consultancy cannot afford that bet.

    Still have a question?

    Tell us about your confidential-data workflow and we'll show you exactly how the cloak keeps it out of the model.