Data protection in the brain
Every brain has its own data protection level: Open, Pseudonymise or Strict. It decides whether personal data from the brain reaches a model in plain text and which documents the brain accepts. This page explains the levels and their limits.
Last checked on 28 September 2026
On this page
The three levels
The levels build on each other: Strict includes everything in Pseudonymise and also refuses documents. Open suits your own records, where an IBAN may be exactly the answer you are looking for.
| Level | Personal data on its way to the model | When documents are added |
|---|---|---|
| Open | Passages reach the chosen model as stored. | All supported files, including images and scanned PDFs. |
| Pseudonymise | Custodos replaces names, IBANs, addresses and other detected personal data with placeholders before the model and puts them back in the reply. | No images and no scanned PDFs. |
| Strict | as Pseudonymise | Custodos also refuses documents carrying an AHV, IBAN, card or UID number, plus matches for the workspace's own rules. No images and no scanned PDFs. |
Choosing and changing the level
You choose the level when creating the brain, under Personal data in this brain. The default is Open. If your workspace blocks hard identifiers such as IBANs, Strict is preselected.
Later, only people with full access can change the level, in the About this brain section on the brain's page. Everyone else sees the current level there. People who may edit the brain also see a note below the document list explaining what the level does.
What pseudonymisation does
With Pseudonymise and Strict, Custodos replaces detected personal data before text from the brain reaches a model. This covers the passages the chat retrieves as well as the document summaries and, in brains with many documents, the Overview that Custodos has a model write during processing. Custodos puts the real values back into the reply.
Documents are stored with their real text. The preview in the brain and Test the Brain therefore show the original values, so everyone who may use the brain still sees them.
Brains in security mode
When a chat is in security mode, Custodos pseudonymises the passages from every attached brain, including brains set to Open. What else security mode does is described under Security mode.
Which kinds of personal data Custodos detects and how admins add their own rules is covered on the Personal data page.
The level set on the brain itself does not change. It continues to apply to every chat without security mode.
Where this stops working
The levels reduce the personal data a model gets to see. They have limits you should know before you put sensitive records into a brain.
- The search index is built from the original text. To keep the brain searchable, an embedding model computes numerical values from the text before pseudonymisation. This model also follows the workspace's processing region.
- Automatic detection does not find everything. Rare names or personal data without a typical format can go undetected and then reach the model in plain text.
- Strict only refuses documents with an AHV, IBAN, card or UID number and matches for the workspace's own rules, unless the workspace has switched the category off. Other identifiers, such as German or Austrian ones, are not on this list. Admins add their own rules for them.
- Images and scanned pages cannot be pseudonymised. That is why only brains set to Open accept them.
Which level suits which content
The overview below is a guide. Records with different protection needs are better kept in separate brains than in one brain set to the strictest level.
| Content | Level |
|---|---|
| Handbooks, policies and product information without personal data | Open |
| Your own master data, where names or IBANs are the answer | Open |
| Files where names are not needed for the answer | Pseudonymise |
| Records that should never contain account, card or AHV numbers | Strict |
| Scans and images | only Open is possible |
Read next
Still have a question? Write to us.
