iConference AG
PII anonymisation · Switzerland

Sovereign Cockpit: anonymise confidential data before it leaves the house

Anonymise, review and release confidential data locally. The raw text never leaves your control, and you can prove it.

A controlled workflow before any cloud model or dispatch: confidential data is anonymised locally, every step stays provable in the audit trail. Only the sanitised version goes out, on your click.
How it works
01

Replace locally

Confidential data is detected on this machine and replaced with placeholders, nothing is sent to the cloud.

02

Review & release

Only your click at the human gate releases the anonymised version; the mapping with the original values stays on the server.

03

Re-identify

Paste the external model's response back in. Sovereign Cockpit restores the original values.

What it delivers
Enforced human gate. Nothing leaves the server without your release.
Tamper-evident audit trail. HMAC-chained, provably unaltered, PII-free.
Your own standard terms. Company name, clients, product codes: entered once, anonymised in every document.
Swiss data types built in. AHV, IBAN, CHE-UID, GLN/ZSR and more.
Everything encrypted at rest. All case data AES-256-GCM, master key held outside the data volume; all case data never leaves the instance; entire cases deleted per click, auditable.
Offline-capable sign-in. In-app users, Argon2id, no external service.
German & English. Fully bilingual interface.
Data kept in Switzerland. On-premise or hosted, your choice.
Noticeably less review effort. One card per company and person instead of long candidate lists per type.
Deployment options
Highest sovereignty

On-premise

App and name detection run entirely on your side. No data egress, your own hardware.

Hybrid

Your DC + Swiss cloud

App in your data centre, name detection via a Swiss cloud API.

Hosted · CH

Single-tenant

We run an isolated instance per customer in Switzerland: own key, own audit trail.

Indicative pricing
Hosted (CH)
from CHF 250 / month · annual plan
Isolated instance, data kept in Switzerland, 5 users included. Operated by iConference.
On-premise
from CHF 180 / month · annual plan
Runs on your hardware (requirements on consultation), 5 users included.

Indicative per instance/company. Concrete quote after a short conversation.

Security architecture

Several independent layers, not one model

Deterministic CH recognisers NER (person/location/org) Local free-text pass Merge
Human gate Manual masking Independent egress backstop

The egress backstop is a second, deliberately broader check before release, independent of the main recogniser, so a gap does not sit twice in the same layer.

What stays protected
Everything encrypted at restAll case artefacts (original, anonymised, re-identified, source file, mapping, metadata, user list, standard terms) with AES-256-GCM, kept locally in your instance only; the master key is held separately from the data volume. Cases are retained until you delete them; deleting a case removes the entire record per click and remains verifiable in the tamper-evident audit chain.
Tamper-evident audit trailHMAC-chained log, PII-free, every change provable.
Fail-closed everywhereIf a step fails (detection, scanned PDF without a text layer), the case aborts, rather than passing on unchecked data.
Egress control before releaseIf protected values remain in plain text, release is held and put to you for approval; a deliberate release is recorded in the audit trail.
Detected data types (Swiss focus)
AHV number CH IBAN CHE-UID GLN ZSR Credit card VAT ID Case number E-mail / phone Address / ZIP Property ID Building insurance number Company Person (NER) Location (NER) Organisation (NER) Free-text names

Names, places and companies are detected language-independently by NER. Country-specific identifiers (e.g. German tax ID, commercial-register number) are available as a recogniser module for your country on request.

Formats & limits

Supported: PDF with a text layer, Word (DOCX), Markdown, text, Excel (XLSX).

Scanned PDFs without a text layer are deliberately rejected (fail-closed), OCR is on the roadmap.

Limit 150,000 characters or 25 MB per upload.

Models

Name detection either fully local or via a Swiss cloud API.

Model-independent: protection rests on several independent check layers, not on a single model, you are not tied to any particular AI model.

Positioning

A pre-stage tool, not a platform

Sovereign Cockpit sits in front of anything you send out (a cloud model, email or handover) and replaces neither chatbot, RAG nor DMS. At its core: an enforced release by a human in the reversible flow and a tamper-evident audit trail; Swiss identifiers are recognised out of the box.

Frequently asked questions about Sovereign Cockpit

How can I have a cloud model process confidential documents?

By replacing the protection-worthy details locally beforehand. Sovereign Cockpit detects them on your instance, replaces them with placeholders and presents the result for your approval. Only your click releases it. You paste the external model's answer back in, and the original values are restored.

What does Sovereign Cockpit cost?

Hosted in Switzerland from CHF 250 per month on an annual plan, on-premise from CHF 180 per month on an annual plan. Both options include five users. These are guide prices per instance and company; a concrete quote follows after a short conversation. A 30-day trial is free.

Which file formats does Sovereign Cockpit process?

PDF with a text layer, Word (DOCX), Excel (XLSX), Markdown and plain text. Scanned PDFs without a text layer are deliberately rejected so that no unchecked data slips through. OCR is on the roadmap. Each upload is limited to 150,000 characters or 25 MB.

Does the system detect Swiss identifiers?

Yes, out of the box: AHV number, Swiss IBAN, CHE-UID, GLN, ZSR, credit card, VAT ID, case reference, email, phone, address and postcode. Names, places and organisations are detected by NER regardless of language. You enter your own standard terms such as client names or product codes once, and they are anonymised in every document thereafter.

Where is the data stored?

On your instance, with data held in Switzerland. Three options are available: fully on-premise, hybrid with your data centre plus a Swiss cloud API for name detection, or hosted as an isolated single-tenant instance with its own key. All case data is encrypted at rest with AES-256-GCM.

Does Sovereign Cockpit replace a chatbot or a RAG system?

No. It sits in front of them. Sovereign Cockpit is a pre-stage tool for the moment data leaves the house, whether to a cloud model, by email or for handover. Chatbot, RAG and document management remain untouched. The core is enforced human approval plus a tamper-evident audit trail.