Redact the document before the AI reads it

You have a bundle of clinical records and a report to write. A language model would save you hours on the chronology — but the bundle has the patient's name, NHS number and address in it, and those cannot go to a model provider. This is the pipeline that takes them out first and puts them back afterwards, on your own machine.

  1. Your document goes in. PDF, Word or plain text, opened on your own computer. Nothing is uploaded anywhere.
  2. Identifiers come out. Names, NHS and NI numbers, your own reference formats, phones, addresses, dates — each one replaced by a stable marker, so the same person reads as the same marker everywhere in the bundle.
  3. The model sees only markers. The cleaned text goes to Claude or Bedrock using your own API key, with your prompt. The provider never receives a real identifier.
  4. Real values come back. The answer is rewritten on your machine, markers swapped back for the real names and numbers, ready to work with.

What you get

Rules for your own formats

Every practice numbers things its own way. Your local record IDs, matter references and claim numbers are written as rules during setup, alongside the formats that are the same everywhere — NHS numbers, NI numbers, UK postcodes and phone numbers.

Names, not just numbers

Names have no shape to match on, so a model finds them instead. On a 191-line synthetic psychiatric discharge summary written for testing, all 32 identifiers in the document were replaced, including every person named in it.

Special category attributes

Ethnicity, religion, sexual orientation and trade union membership are Article 9 data and are redacted as their own categories. The term list comes with it and is yours to edit.

Nothing leaves your machine

There is no service to sign up for and no document upload. The pipeline runs locally and reaches exactly one service outside it: the model provider you chose, with your key, carrying text that has already been cleaned.

What this is not

The honest list, because finding it out later is worse.

Not a hosted service

No uploads, no accounts, no dashboard, and no uptime promise. If that is what you want, this is the wrong tool.

No OCR for scans

A scanned page with no text layer has nothing to read. Documents need extractable text, and the work is in English.

It cannot read between the lines

An identifier with a shape, a name, or a term on the list comes out. A fact that merely implies something — a birthplace, a religious practice described in passing — does not, and no threshold will find it.

Keep a copy of your key

The table that maps markers back to real values is encrypted with a key that lives on your machine. Lose that key and previously processed documents cannot be restored. The same document run again produces the same markers, so the work is repeatable — but the old map is gone.

What setting it up costs

Configuration work, not a software licence. There is nothing to subscribe to.

£2,000

Setup, once

Two to three weeks. Rules for your formats, the application on your machine, one model connection, and the round trip working end to end on your own document.

£600

A second model

Only if you want both Claude and Bedrock wired up, or a connection to the Claude desktop app as well.

£120

A month, if you want it

Rule changes when your formats change, and a reply when something misbehaves. Cancel whenever; nothing stops working without it.

No subscription for the software itself, and nothing is charged per document.

What you provide: one representative document to build the rules against, the list of identifier formats your practice uses, and your own Claude or Bedrock key — the model is billed to you, not resold through us.

See it on your own document

The honest way to judge this is to watch it run on a file you recognise — 20 minutes, screen shared, your own document or one like it. It costs nothing and commits you to nothing; if it is not for you, that is a useful answer for both of us. Pick whichever way suits you.

Book 20 minutes →

A call with the person who wrote it. No sales pitch and no deck.

Describe your documents →

Four questions, two minutes, no call. Useful if you would rather know whether this fits before speaking to anyone.

Or write to ilya.ploskovitov@pii-shield.com if email suits you better.