Local-first AI privacy gateway

The prompt leaves.
Your secrets don't.

OwnKeep lets your team use ChatGPT, Claude and Gemini without sending client data to the cloud. Personal information is detected and masked on your own hardware before a prompt ever leaves the building - then restored in the reply, so the work feels exactly the same.

Built for Australian legal & accounting firms. On-premises, vendor-neutral, fail-closed.

Live intercept
Your staff type
"Draft a letter for Margaret Whitfield, TFN 123 456 782"
OwnKeep masks it on-device
"Draft a letter for [PERSON_1], TFN [TFN_1]"
The AI only ever sees placeholders
ChatGPT · Claude · Gemini
75%
of knowledge workers already use generative AI at work
78%
bring their own AI tools, outside any policy
52%
conceal their AI use on important tasks
US$4.8M
average cost of a data breach involving personal data

Sources: Microsoft & LinkedIn 2024 Work Trend Index; IBM Cost of a Data Breach.

The blind spot

Your data-loss tools can't see this traffic

When staff paste a client name, a contract clause or an account number into an AI tab, that data goes straight from the browser to a third party. It never touches your email gateway, your endpoint controls or a monitored SaaS API - so the tools you already pay for simply don't see it.

  • Banning AI backfires. The work doesn't stop - it moves to personal accounts on personal devices, where nobody is watching.
  • Regulators don't distinguish intent. Under GDPR, the Privacy Act and sector rules, an accidental leak carries the same liability as a deliberate one.
  • Cloud "redaction" defeats the purpose. Many controls still route your raw prompt through the vendor's cloud to inspect it first.
Your firm Public AI WITHOUT OWNKEEP OwnKeep WITH OWNKEEP [MASKED]
How it works

Five steps, all on your own infrastructure

Your team keeps using the AI tools they already know. OwnKeep sits quietly in front of them and handles the rest on every single request.

1 · Intercept

Every prompt to a known AI service passes through the gateway first.

2 · Detect locally

A model on your own hardware finds the personal data. Nothing is sent away to be scanned.

3 · Mask

Real values become typed placeholders - [PERSON_1], [TFN_1].

4 · Forward

The masked prompt goes to the AI. It answers using the placeholders.

5 · Restore

OwnKeep swaps the real values back in. Your team sees a normal, complete reply.

From your team's point of view, nothing changed. From a compliance point of view, sensitive data never left the building.

See it live

Every request, masked and logged in real time

The OwnKeep dashboard shows exactly what your staff typed, exactly what the AI received, and a full record of what was protected - so you can prove it to a regulator or an insurer.

Ownkeep LIVE
4
Requests intercepted
16
PII tokens masked
<1s
Avg detection latency
ChatGPT4 PII679 ms sarah.jones@harbourlegal.com.au
● Original prompt
Draft a client letter for Margaret Whitfield (TFN 123 456 782) about her property settlement. Reply to m.whitfield@example.com.au or call 0412 345 678.
● Masked prompt sent to LLM
Draft a client letter for [PERSON_1] (TFN [TFN_1]) about her property settlement. Reply to [EMAIL_1] or call [PHONE_1].
Claude3 PII391 ms priya.patel@harbourlegal.com.au
● Original prompt
File note: client Robert Nguyen, Medicare 2123 45670 1, attended re his estate. Send outcome to r.nguyen@example.com.
● Masked prompt sent to LLM
File note: client [PERSON_1], Medicare [MEDICARE_1], attended re his estate. Send outcome to [EMAIL_1].

A faithful view of the live OwnKeep control dashboard. Logs record the type and count of items detected - never the raw values.

Why OwnKeep

Three things that make it different

01

Local-only by design

Masking happens on-premises, before anything leaves your network. Unlike cloud "redaction" services, your raw data is never routed through a third party to be inspected - which is the whole point for data-residency and sovereignty.

02

Vendor-neutral

OwnKeep isn't tied to one model or platform. It governs traffic to whichever AI services your staff actually use - ChatGPT, Claude, Gemini - and adding a new one is a configuration change, not a re-build.

03

Transparent & auditable

The detection logic is a single, visible, editable instruction set - not an opaque black box. Every interaction produces an audit record: the evidence trail that regulators and insurers increasingly expect.

Features

A safety layer built for regulated work

Not a checkbox. The controls that matter when your core asset is confidential client data.

Detection stays on your machine

The model that finds personal data runs locally through Ollama. No prompt, and no PII, is sent to a third party to be scanned.

Australian identifiers

Names, emails, phones, addresses - plus TFN, ABN and Medicare numbers, validated with real checksums, not just guessed by pattern.

Fail-closed by default

If the shield can't check a prompt, the prompt is held back rather than sent unprotected. Safety is the default, not the exception.

Compliance-ready audit trail

A record of what was intercepted - the type and count of items - without ever storing the raw values in the log.

Blocks risky file uploads

Attaching a document would bypass text masking, so OwnKeep stops those uploads before a file can reach the AI provider.

Works with the big three

ChatGPT, Claude and Gemini through one gateway. Your team keeps the tools and the workflow they already use.

Measured on our test corpus: 100% of non-adversarial PII values masked (97.9% of names)
Architecture

The sensitive data never leaves your perimeter

Your staff

Type into ChatGPT, Claude, Gemini as usual

prompt

OwnKeep gateway

Detects & masks locally on your hardware · keeps the audit trail

masked only

Public AI

Only ever receives placeholders

Runs on-premises with Docker or natively - your servers, your hardware. GPU optional; sub-second on a laptop-class machine.

Who it's for

Made for firms whose data must stay confidential

Professional-services firms of roughly 50 to 500 staff, where the core asset is client confidentiality and the partners are personally on the hook for it.

Legal

Law firms & in-house counsel

Let lawyers use AI to draft, summarise and research - without client names, matters or file notes ever reaching a third party.

"Summarise this matter for [PERSON_1] and draft advice on the [ADDR_1] settlement."
Accounting

Accounting & advisory practices

Prepare BAS, letters and analysis with AI while TFNs, ABNs and account numbers stay inside the practice.

"Draft an overdue notice for [ENTITY_1], ABN [ABN_1], account [ACCOUNT_1]."
Financial advice

Advisers & wealth firms

Use AI across statements of advice and client comms while personal and financial identifiers are masked on the way out. (on the roadmap)

"Explain the strategy for [PERSON_1] holding account [ACCOUNT_1]."
Healthcare admin

Clinics & practice groups

Support administration and correspondence with AI while patient names and Medicare numbers never leave the building. (on the roadmap)

"Draft a recall letter for [PERSON_1], Medicare [MEDICARE_1]."
Plans

Start with a pilot, scale by seat band

On-premises deployment, delivered directly or through your managed IT partner. Pricing is tailored to your firm - talk to us.

Start here

Pilot

A hands-on proof, on your data
  • Deploy in your environment
  • Live masking against your real prompts
  • Measured detection report
  • Guided setup & support
Request a pilot
Team

Team

Up to 100 seats
  • Full gateway & dashboard
  • On-prem, channel-delivered
  • Audit trail & reporting
  • Email support
Talk to us
Firm

Firm

100 to 500 seats
  • Everything in Team
  • On-prem with priority support
  • Vertical detection tuning
  • Compliance reporting pack
Talk to us
Enterprise

Enterprise

500+ seats
  • High availability
  • Integration & SSO
  • Delivered via MSSP / SI
  • Custom reporting & SLAs
Contact sales
FAQ

Questions we get asked

Does any of our data leave the building? +

No. Detection runs on a model hosted on your own hardware, and masking happens before the prompt leaves your network. The public AI only ever receives placeholders. There is no external call - not even to a detection service.

Which AI tools does it cover? +

ChatGPT, Claude and Gemini today, through a single vendor-neutral gateway. Because it governs traffic by destination, adding another AI service is a configuration change rather than a re-build.

Is this just regex redaction? +

No. A local language model reads the prompt in context, so it catches things a rules-based system misses - like "my client Bob" or an identifier phrased in an unusual way. Deterministic checks (including Australian TFN/ABN/Medicare checksums) run underneath as a safety net.

What happens if the detector fails or is unavailable? +

It fails closed. If a prompt can't be checked, it is blocked rather than forwarded unprotected. Safety is the default behaviour, and it's tested.

Is it a finished, perfect filter? +

No detector is perfect, and we don't claim otherwise. OwnKeep is an early-access product now running pilots with regulated firms. We compete on measured recall, fail-closed safety and a clean audit trail - all checkable - rather than a claim of perfection.

How is it deployed? +

On-premises, via Docker or a native install, on your servers. A GPU helps but isn't required; detection is sub-second on laptop-class hardware. It can be delivered directly or through your existing managed IT/security provider.

See it run on your own data

Book a pilot and watch a real prompt get masked, sent and restored - live, in your environment. No client data leaves the room.

Request a pilot
or email hello@ownkeep.com.au