Local-first AI privacy gateway

The prompt leaves.
Your secrets don't.

OwnKeep lets your team use ChatGPT, Claude and Gemini without sending client data to the cloud. Personal information is detected and masked on your own hardware before a prompt ever leaves the building - then restored in the reply, so the work feels exactly the same.

Built for Australian legal & accounting firms. On-premises, vendor-neutral, fail-closed.

Live intercept
Your staff type
"Draft a letter for Margaret Whitfield, TFN 123 456 782"
OwnKeep masks it on-device
"Draft a letter for [PERSON_1], TFN [TFN_1]"
The AI only ever sees placeholders
ChatGPT · Claude · Gemini
75%
of knowledge workers already use generative AI at work
78%
bring their own AI tools, outside any policy
52%
conceal their AI use on important tasks
US$4.8M
average cost of a data breach involving personal data

Sources: Microsoft & LinkedIn 2024 Work Trend Index; IBM Cost of a Data Breach.

The blind spot

Your data-loss tools can't see this traffic

When staff paste a client name, a contract clause or an account number into an AI tab, that data goes straight from the browser to a third party. It never touches your email gateway, your endpoint controls or a monitored SaaS API - so the tools you already pay for simply don't see it.

  • Banning AI backfires. The work doesn't stop - it moves to personal accounts on personal devices, where nobody is watching.
  • Regulators don't distinguish intent. Under GDPR, the Privacy Act and sector rules, an accidental leak carries the same liability as a deliberate one.
  • Cloud "redaction" defeats the purpose. Many controls still route your raw prompt through the vendor's cloud to inspect it first.
Your firm Public AI WITHOUT OWNKEEP OwnKeep WITH OWNKEEP [MASKED]
How it works

Five steps, all on your own infrastructure

Your team keeps using the AI tools they already know. OwnKeep sits quietly in front of them and handles the rest on every single request.

1 · Intercept

Every prompt to a known AI service passes through the gateway first.

2 · Detect locally

A model on your own hardware finds the personal data. Nothing is sent away to be scanned.

3 · Mask

Real values become typed placeholders - [PERSON_1], [TFN_1].

4 · Forward

The masked prompt goes to the AI. It answers using the placeholders.

5 · Restore

OwnKeep swaps the real values back in. Your team sees a normal, complete reply.

From your team's point of view, nothing changed. From a compliance point of view, sensitive data never left the building.

See it live

Every request, masked and logged in real time

The OwnKeep dashboard shows exactly what your staff typed, exactly what the AI received, and a full record of what was protected - so you can prove it to a regulator or an insurer.

Ownkeep LIVE
4
Requests intercepted
16
PII tokens masked
<1s
Avg detection latency
ChatGPT4 PII679 ms sarah.jones@harbourlegal.com.au
● Original prompt
Draft a client letter for Margaret Whitfield (TFN 123 456 782) about her property settlement. Reply to m.whitfield@example.com.au or call 0412 345 678.
● Masked prompt sent to LLM
Draft a client letter for [PERSON_1] (TFN [TFN_1]) about her property settlement. Reply to [EMAIL_1] or call [PHONE_1].
Claude3 PII391 ms priya.patel@harbourlegal.com.au
● Original prompt
File note: client Robert Nguyen, Medicare 2123 45670 1, attended re his estate. Send outcome to r.nguyen@example.com.
● Masked prompt sent to LLM
File note: client [PERSON_1], Medicare [MEDICARE_1], attended re his estate. Send outcome to [EMAIL_1].

A faithful view of the live OwnKeep control dashboard. Logs record the type and count of items detected - never the raw values.

Try it yourself

Type a prompt and watch it get masked

Put in a sentence with a name, an email, a phone number or an Australian TFN, ABN or Medicare number, and see what the AI would actually receive. Everything here runs in your browser - nothing is sent anywhere.

Try an example:
● What your staff type
● What the AI actually receives
0 item(s) masked before the prompt would leave your network

This in-browser demo uses simple pattern rules so it can run without a server - it is a simplified illustration. The real OwnKeep gateway uses a language model on your own hardware to read each prompt in context, so it catches cases plain patterns miss (like a first name on its own), backed by the same deterministic Australian checksums you see here.

Why OwnKeep

Three things that make it different

01

Local-only by design

Masking happens on-premises, before anything leaves your network. Unlike cloud "redaction" services, your raw data is never routed through a third party to be inspected - which is the whole point for data-residency and sovereignty.

02

Vendor-neutral

OwnKeep isn't tied to one model or platform. It governs traffic to whichever AI services your staff actually use - ChatGPT, Claude, Gemini - and adding a new one is a configuration change, not a re-build.

03

Transparent & auditable

The detection logic is a single, visible, editable instruction set - not an opaque black box. Every interaction produces an audit record: the evidence trail that regulators and insurers increasingly expect.

Features

A safety layer built for regulated work

Not a checkbox. The controls that matter when your core asset is confidential client data.

Detection stays on your machine

The model that finds personal data runs locally through Ollama. No prompt, and no PII, is sent to a third party to be scanned.

Australian identifiers

Names, emails, phones, addresses - plus TFN, ABN and Medicare numbers, validated with real checksums, not just guessed by pattern.

Fail-closed by default

If the shield can't check a prompt, the prompt is held back rather than sent unprotected. Safety is the default, not the exception.

Compliance-ready audit trail

A record of what was intercepted - the type and count of items - without ever storing the raw values in the log.

Blocks risky file uploads

Attaching a document would bypass text masking, so OwnKeep stops those uploads before a file can reach the AI provider.

Works with the big three

ChatGPT, Claude and Gemini through one gateway. Your team keeps the tools and the workflow they already use.

Measured on our test corpus: 100% of non-adversarial PII values masked (97.9% of names)
Why not just...

The alternatives, side by side

Most firms are choosing between four options right now. Here is how they compare on the things that actually carry the risk.

Ban AI Do nothing Cloud redaction tool OwnKeep
Sensitive data stays on your hardware Yes No No - raw prompt is sent to the vendor to inspect Yes - detection runs locally
Staff keep using ChatGPT, Claude, Gemini No Yes Sometimes - often one tool only Yes - vendor-neutral
Shadow AI use is reduced, not pushed underground No - work moves to personal devices No Partly Yes - the sanctioned path is the easy path
Audit trail for regulators and insurers No No Held by the vendor Yes - kept on-premises, counts not raw values
Fails safe if the check cannot run n/a No Varies Yes - fail-closed by default
Blocks risky file uploads that bypass masking n/a No Rarely Yes

"Cloud redaction tool" refers to services that detect or redact PII by first sending the prompt to the provider's own cloud. Capabilities across such tools vary - the point of difference with OwnKeep is that the raw data never leaves your perimeter to be inspected in the first place.

Architecture

The sensitive data never leaves your perimeter

Your staff

Type into ChatGPT, Claude, Gemini as usual

prompt

OwnKeep gateway

Detects & masks locally on your hardware · keeps the audit trail

masked only

Public AI

Only ever receives placeholders

Runs on-premises with Docker or natively - your servers, your hardware. GPU optional; sub-second on a laptop-class machine.

Trust & compliance

Built to help you meet your obligations

OwnKeep is designed around the principle regulators keep returning to: keep personal data under your control. Here is where it fits, stated plainly.

Australian Privacy Act & APPs

Supports your handling of personal information under the Privacy Act 1988 and the Australian Privacy Principles by keeping identifiers inside your perimeter.

  • Data minimisation at the point of use
  • No disclosure of raw PII to overseas AI providers
  • Evidence trail of what was protected

GDPR & data residency

For firms with EU or cross-border exposure, detection and masking happen locally, so personal data is not transferred to a third party to be processed.

  • Processing stays in your chosen jurisdiction
  • Reduces cross-border transfer risk
  • You remain the data controller

Security posture

We are honest about our stage. OwnKeep is early-access, running pilots - these are the controls in place today and what is next.

  • Encrypted audit store, no raw PII in logs In place
  • Fail-closed, token-gated services In place
  • SOC 2 / ISO 27001 alignment On the roadmap

OwnKeep is a technical control that supports your compliance programme; it is not legal advice and does not by itself make a firm compliant. We are happy to work through your specific obligations during a pilot.

Who it's for

Made for firms whose data must stay confidential

Professional-services firms of roughly 50 to 500 staff, where the core asset is client confidentiality and the partners are personally on the hook for it.

Legal

Law firms & in-house counsel

Let lawyers use AI to draft, summarise and research - without client names, matters or file notes ever reaching a third party.

"Summarise this matter for [PERSON_1] and draft advice on the [ADDR_1] settlement."
Accounting

Accounting & advisory practices

Prepare BAS, letters and analysis with AI while TFNs, ABNs and account numbers stay inside the practice.

"Draft an overdue notice for [ENTITY_1], ABN [ABN_1], account [ACCOUNT_1]."
Financial advice

Advisers & wealth firms

Use AI across statements of advice and client comms while personal and financial identifiers are masked on the way out. (on the roadmap)

"Explain the strategy for [PERSON_1] holding account [ACCOUNT_1]."
Healthcare admin

Clinics & practice groups

Support administration and correspondence with AI while patient names and Medicare numbers never leave the building. (on the roadmap)

"Draft a recall letter for [PERSON_1], Medicare [MEDICARE_1]."
Plans

Start with a pilot, scale by seat band

On-premises deployment, delivered directly or through your managed IT partner. Pricing is tailored to your firm - talk to us.

Start here

Pilot

A hands-on proof, on your data
  • Deploy in your environment
  • Live masking against your real prompts
  • Measured detection report
  • Guided setup & support
Request a pilot
Team

Team

Up to 100 seats
  • Full gateway & dashboard
  • On-prem, channel-delivered
  • Audit trail & reporting
  • Email support
Talk to us
Firm

Firm

100 to 500 seats
  • Everything in Team
  • On-prem with priority support
  • Vertical detection tuning
  • Compliance reporting pack
Talk to us
Enterprise

Enterprise

500+ seats
  • High availability
  • Integration & SSO
  • Delivered via MSSP / SI
  • Custom reporting & SLAs
Contact sales
FAQ

Questions we get asked

Does any of our data leave the building? +

No. Detection runs on a model hosted on your own hardware, and masking happens before the prompt leaves your network. The public AI only ever receives placeholders. There is no external call - not even to a detection service.

Which AI tools does it cover? +

ChatGPT, Claude and Gemini today, through a single vendor-neutral gateway. Because it governs traffic by destination, adding another AI service is a configuration change rather than a re-build.

Is this just regex redaction? +

No. A local language model reads the prompt in context, so it catches things a rules-based system misses - like "my client Bob" or an identifier phrased in an unusual way. Deterministic checks (including Australian TFN/ABN/Medicare checksums) run underneath as a safety net.

What happens if the detector fails or is unavailable? +

It fails closed. If a prompt can't be checked, it is blocked rather than forwarded unprotected. Safety is the default behaviour, and it's tested.

Is it a finished, perfect filter? +

No detector is perfect, and we don't claim otherwise. OwnKeep is an early-access product now running pilots with regulated firms. We compete on measured recall, fail-closed safety and a clean audit trail - all checkable - rather than a claim of perfection.

How is it deployed? +

On-premises, via Docker or a native install, on your servers. A GPU helps but isn't required; detection is sub-second on laptop-class hardware. It can be delivered directly or through your existing managed IT/security provider.

Built by

Who is behind OwnKeep

AB

Dr Asim Baig

Founder

OwnKeep is founder-led by Dr Asim Baig, who holds a PhD and has spent more than two decades building data, machine-learning and privacy-focused systems. OwnKeep grew out of a simple observation: regulated firms want to use AI, but cannot afford to send client data to the cloud to do it. The product is built in Australia, for the firms that carry that risk personally. If you are evaluating OwnKeep, you will be talking to the person who built it.

See it run on your own data

Book a pilot and watch a real prompt get masked, sent and restored - live, in your environment. No client data leaves the room.

We will only use your details to respond to this enquiry. Or email hello@ownkeep.com.au.