Built from the ground up with a zero-trust security model. Your data is protected at every layer — and the strongest layer is that the confidential value never reaches the AI at all.
We don't keep confidential data in Canada. We make sure there isn't any confidential data to keep.
Every other “compliant AI” answers the residency question with a location — a region you select and a policy you trust. Untraceable answers it upstream: the real value is cloaked on your computer before any model sees it, so the thing residency laws exist to protect never enters the pipeline.
The AI only ever receives cloaks. Real values are replaced on your own computer before anything is transmitted, so there is no confidential data in the payload to keep in one country or another. Residency stops being a promise about a database and becomes a property of the architecture.
Because no confidential value is ever disclosed to the AI, the privacy assessments that assume disclosure don't strictly attach to that step. We complete a Privacy Impact Assessment regardless — the standard we're held to is the one we choose, not the minimum the law leaves us.
Frontier providers may have Canadian capacity, but selecting a region and being held to it are not the same thing — few will contractually guarantee your data never leaves it. Untraceable routes through residency-proof APIs with a fail-closed check and no silent fallback: if a region can't be honored, the request stops. We enforce what the providers won't commit to.
Selecting a region and being held to it are not the same thing. We enforce what the providers won't commit to.
Confidentiality law — PIPEDA, Quebec Law 25, the disclosure clauses in an NDA — is built around a moment of disclosure: a confidential value leaving your control and reaching someone else. Untraceable removes that moment. The AI never receives the value, so the obligations that hinge on disclosure don't even attach to the AI step in the first place. The safest way to comply with a rule about sharing data is to never share the data.
We don't stop there. We still run the assessments, still honor residency, still keep an audit trail of every cloak and every submission — not because the law forces us to at that step, but because regulated clients deserve to see the belt and the braces. Doing the work you're not strictly required to do is the whole posture.
Every route authenticated via JWT. Least privilege on Key Vault, database, and Graph. No exceptions.
AI models receive only cloaked data — never your files, never your raw text. Documents stay in your vault.
A cloak-coverage test, a sentinel that catches stray numerical and alphanumeric values, a breach test in which a separate model tries to reconstruct the real values, and a compulsory human certification. Recover even one value and the submission is rejected — zero tolerance, not a threshold.
Contractual guarantee: your inputs are excluded from AI model training. Period.
No memory retention. Session data is cleared immediately after processing. Nothing persists.
Choose your server location: US East Coast or Canada — enforced, not just selected. West Europe (Netherlands) is planned and not yet available.
Privacy-by-design tools aligned with HIPAA, PIPEDA and GDPR principles. This is an alignment claim, not a certification: no third-party attestation is held today.
Reviewing generative AI for health technology assessment, an ISPOR Working Group notes that these models can memorise the data they were trained on and reproduce it later, and advises against putting protected health information into them at all — because absolute de-identification is not attainable and re-identification risk stays non-zero (Fleurence et al., Value in Health 2025;28(2):175–183). Contractual no-training and retention terms are worth having, and we hold them. But they are promises about what a third party will do with your data once it has it. Text that never leaves your computer cannot be memorised, cannot be reproduced, and needs no promise at all.
All document processing and cloaking runs client-side, in your browser — no installation, no plugin, and no file ever uploaded to our servers. Only cloaked values are transmitted to the AI models. Your files and real data remain local to your device for the entire workflow.
Where cloaks, audit records and compute do live, they stay put. Each region has its own isolated compute and storage — enforced. AI inference runs in-region where the provider offers it (e.g. Gemini in Canada); models without an in-region endpoint (Claude, GPT) run in a US region on cloaked text, disclosed up front — never a silent cross-region switch.
Trust center
Subprocessors, residency, retention, encryption, key custody and certification status — stated plainly. Where a row is not yet answerable it says so rather than inferring an answer.
Third parties that receive data in the course of delivering the service. AI providers receive cloaked text only — never a confidential value.
Where cloaks, audit records and compute live. AI inference runs in-region where the provider offers an in-region endpoint; where it does not, the model runs in a US region on cloaked text, disclosed up front — never a silent cross-region switch.
No third-party attestation is held today. The rows below state status, not aspiration.
Need something not listed here? Ask us directly — or read the Untraceable Protocol.