1. Original data stays protected
- The original document stays in the customer environment.
- Real sensitive values stay there too.
- The private mapping is never sent to model providers.
The Semantic Privacy Shield protects document context before external AI processing. It replaces detected sensitive values inside the Vera environment. It then checks the prepared text before anything is sent.
The process is simple and visible.
Many professional files contain highly sensitive data. Examples include medical records, criminal cases, family disputes, wills and workplace health reports.
AI can help with these files. But the original document should not be sent directly to a public AI service.
Empty labels such as [PERSON_1] remove useful meaning. AI still needs to know whether a person is a client, child, heir, patient or suspect.
Privacy risk is not limited to names and ID numbers. Roles, diagnoses, allegations and family links can also identify a person.
Simple pattern matching does not understand that context.
The Shield works in three phases. All three run inside the protected Vera environment. External models receive transformed document context only after the local verification gate approves it.
Vera analyses the document inside the customer environment. It replaces detected names, dates, locations, case numbers and other sensitive values.
Synthetic values keep useful roles and relationships intact.
A local check scans the prepared text before transmission. If a detected real value remains, Vera blocks the request.
No document text is sent. There is no silent override.
The AI chain works on the synthetic version. After the answer returns, Vera restores the original values inside the protected environment.
The private mapping never goes to external model providers.
A fictional example from a family-law file. The structure, roles and relationships survive — the real people don't travel with them.
Mrs. Jansen states that her ex-partner Peter became aggressive on 12 March during the handover of her daughter Emma.
Mrs. Dylan Knoers [[DOC001_ADULT_PERSON_001]] states that her ex-partner Mr. Tobias Evers [[DOC001_ADULT_PERSON_002]] became aggressive on 06-01-2026 [[DOC001_DATE_001]] during the handover of her minor daughter Ivy Peterse [[DOC001_MINOR_CHILD_001]].
The AI still understands who has which role, what the relationship is and why the facts matter — it just never sees the real values.
The statements of Mrs. Jansen should be assessed in relation to the documented conduct of Peter during handovers involving Emma…
The same approach applies to medical and workplace health records. Vera can replace a diagnosis, medicine or incident with a synthetic value of the same type.
Useful legal and medical terms can remain when they are needed for the analysis.
Professional analysis needs context. The AI may need to know a person’s role, age band, region or legal status.
Blank labels remove too much meaning. Vera therefore preserves only the context needed for the task.
Vera is not a simple anonymiser. Vera is a meaning-preserving privacy layer for professional AI analysis.
Vera does not remove every detail. It can preserve information that the task needs, such as:
Exact identifying values are replaced locally. Each run records what was kept and what was hidden.
| Stays local (exact) | Can be preserved — where the analysis requires it |
|---|---|
| Date of birth | Age or age band at the incident or report date |
| Full name | Role: client, suspect, heir, patient, employer, ex-partner |
| Exact address | Region or type of surroundings — for claims, insurance or accessibility questions |
| Sex as an identifier | Preserved only when medically, psychologically or legally relevant |
| Exact diagnosis | Medical category, where necessary for the analysis |
Patient A [[DOC001_PATIENT_001]] — context: female, age band 40–49, region retained, relevant medical context present. Exact name, date of birth and address are shielded locally.
Each run records what was kept and what was hidden. The example below is simplified. The private vault is not sent to model providers.
{
"token": "[[DOC001_PATIENT_001]]",
"label": "patient",
"fakeValue": "Patient A",
"preservedAttributes": {
"ageBand": "40-49",
"sexContext": "female",
"role": "patient",
"relevantMedicalContext": "present (category only)",
"locationContext": "region, not exact address"
},
"withheldAttributes": {
"dateOfBirth": "shielded locally",
"fullName": "shielded locally",
"streetAddress": "shielded locally"
}
}
Vera reduces the exposure of identifying data while keeping useful context.
It does not make re-identification impossible. Unique combinations of facts may still identify someone.
A privacy layer only deserves trust if the boundary is stated plainly. Here it is.
We publish the data flow: what stays local, what leaves and in what form.
We do not publish detailed detection methods. Those methods change over time, and public details could help people bypass the control.
Each run still shows what was sent.
The Shield is designed for workflows in which confidentiality duties, professional secrecy and data-protection obligations make direct disclosure of original document values inappropriate.
External models receive transformed context only after local checks pass.
The Shield does not make an unlawful purpose lawful. Customers remain responsible for legal and professional review.
The local trace records what was transformed, what contextual attributes were preserved and whether the outbound privacy gate approved the request.
If your files contain the kind of data that ends careers when it leaks, the Shield was designed for you.
Use AI as a second reader on case files, assessments and pleadings — chronology, inconsistencies, missing substantiation — without sending client identities, minors or criminal-law context to public AI.
Check wills, deeds and powers of attorney for internal consistency and missing elements. Parties, dates and file details are shielded; legal concepts like usufruct, executor and statutory references stay intact.
Structure case material and reconstruct timelines across submissions without exposing parties, victims, suspects or minors to external AI services.
Structure and check reports while diagnoses, medicines and incidents are replaced locally. AI helps with the text, not with the patient’s identity.
Work with psychological reports and treatment context — among the most sensitive data that exists — while detected original identity values are excluded from the approved outbound context.
Analyse leaked documents and source material, extract claims and build timelines while source identities and affected persons are shielded from every model in the chain.
A verification company that oversells its own privacy layer would undermine everything it stands for. So here is the claim, precisely.
Vera replaces detected sensitive values before external processing. It checks the prepared text and blocks the request when the check fails.
Original values are restored locally. Each run leaves an audit trail in the customer environment.
We do not claim full anonymisation or perfect detection. Subtle context can be missed, and a unique set of facts can still identify someone.
The Shield reduces exposure. It does not replace professional judgement.
Direct answers about pseudonymisation, fail-closed verification, external providers and honest limitations.
Vera reduces unnecessary exposure before selected external models receive document context. The text is transformed and checked inside the customer environment. The Shield does not replace confidentiality duties or professional judgement.
It is pseudonymisation and privacy-preserving transformation. Detected values are replaced with synthetic session values. The protected mapping stays inside Vera. This is not guaranteed anonymisation.
The original document, original extracted text, detected real values, the private mapping and local check results remain inside the protected customer environment.
Providers can receive the user’s instruction and approved transformed context. They do not receive the private mapping between real and synthetic values.
Vera checks the prepared text before transmission. If the check fails, or the Shield is unavailable, no document or selection text is sent.
No. Subtle context can be missed, and a unique set of facts can still identify someone. The Shield reduces exposure but cannot guarantee perfect detection.
Yes. A selected passage goes through the same transformation and verification process as a full document.
Vera can keep useful roles, relationships, age bands, regions, medical categories and legal thresholds. Exact detected identifiers are replaced with synthetic session values.
The Semantic Privacy Shield is part of Vera's early access programme. Verified answers, shielded data, every step inspectable.
Get early access