Protecting personal data
Custodos checks messages, attachments and text from connected sources for personal data before anything reaches a model. Detected values leave as placeholders and are put back into the reply. This page covers the protection levels, the categories detected and where the protection stops.
Last checked on 28 September 2026
On this page
How pseudonymisation works
Before sending, Custodos replaces every detected value with a placeholder naming its category, such as NAME_1 or IBAN_1. The model only sees the placeholder. In the reply, Custodos puts the original values back so you can read on as usual.
The mapping from placeholder to original value stays with Custodos, encrypted and kept separately for each chat. It is deleted together with the chat. Within one chat, the same value always gets the same placeholder.
Custodos checks your messages, attached files, the description for an image to be generated and text the model reads from connected accounts, such as cloud files or emails. Detection runs with the same rules in your browser, for the preview in the message field, and on the server. If pseudonymisation is temporarily unavailable, Custodos sends nothing.
Protection levels
Admins choose the protection level for the whole workspace. New workspaces start on Standard. Members see the active level in their account under How your data is handled here.
| Level | What happens | Images |
|---|---|---|
| Standard | Every detected category is pseudonymised, nothing is blocked. Members can send individual values unchanged. | allowed |
| Strict | As Standard. In addition, a message with an AHV number, IBAN, card number or UID number is blocked. | blocked |
| Custom | Each category is set to Ignore, Mask or Block. | as configured |
| Scanning off | Nothing is checked. Messages and files go to the model unchanged. | unchanged |
Setting the protection level
- 1
Open the settings
As an admin, click Settings and go to the Data protection section. - 2
Choose a level
Under Protection level, choose Standard, Strict or Custom. - 3
Adjust the categories
Under Categories and rules, set each category to Ignore, Mask or Block. Under Images, choose Allow or Block.
The categories
| Category | What is detected | Can be blocked |
|---|---|---|
| name | first and last name together, or a name after a title such as Mr, Mrs or Dr | no |
| address | street with house number, plus postcode and town | no |
| birth date | a date after a cue such as “born on” or “date of birth” | no |
| AHV number | Swiss social security number in the format 756.xxxx.xxxx.xx | yes |
| IBAN | IBANs, including foreign ones | yes |
| card number | credit card number with a valid check digit | yes |
| UID number | Swiss business identification number in the format CHE-xxx.xxx.xxx | yes |
| email address | email addresses | no |
| phone number | numbers with a country code or a leading zero | no |
| reference number | customer, contract, policy, invoice and similar numbers after their cue word, such as “customer number KD-4711” | no |
Custom rules
For values that only concern your organisation, admins add a rule under Custom rules with New rule. Each rule either masks or blocks what it matches. Members cannot waive a workspace rule; the chat then shows Fixed by a workspace rule.
With Try it you paste a sample text and see what a model would receive. The check runs locally in your browser; nothing is sent or stored.
| Rule type | Use it for |
|---|---|
| Prefix + digits | customer, contract or invoice numbers such as KD-482113 |
| Exact text | a project name or term that should never be sent |
| Expression | a regular expression for any other pattern |
What members see in the chat
- Before sending, a notice in the message field shows how many sensitive values were detected and of which kind. A click opens the list of values.
- In the list, Send original sends a value unchanged, unless a workspace rule fixes it. For a value that was missed, type it and click Add, or select it in your message and click Pseudonymise “…”. These choices apply to the whole chat.
- Under a sent message, Custodos states how many details were pseudonymised. Show what the model received shows the version with placeholders, Show original switches back. Under the reply, Show what the model wrote shows the text before the values were put back.
- If the workspace blocks a detail, Custodos names the kind of detail. Remove it or ask an admin.
Text with its own rules
Two kinds of text do not follow the workspace's protection level.
- Web search: search results and pages read in full are public text and are not pseudonymised. A search query containing a hard identifier or a placeholder is not sent. Details under Web search.
- Company Brain: passages from a brain follow that brain's own setting, not this page. See Data protection in a brain.
When the protection does not apply
Detection works with fixed rules. It replaces values, not context: everything else in a message reaches the model as written.
- Images: no detector reads pixels. On the Standard level, images go unchanged to models that can read images. To rule that out, block images.
- Names: a first name on its own stays as it is, and a surname without a title can be missed. Custodos recognises full names through a list of common first names; rare first names can be missed. Product and company names such as Claude or Max also stay as they are.
- Birth dates and reference numbers are only detected after a matching cue word.
- Addresses: the street with house number is detected when the street name ends in a common suffix such as -straße, -weg, -gasse or -platz, as in “Hauptstraße 5”, or starts with Rue, Via or similar. Names written as separate words, such as “Berliner Straße 5” or “Am Markt 3”, can be missed. Postcode and town are only included with a four-digit postcode, as used in Switzerland and Austria. A German five-digit postcode with its town stays as it is.
- German and Austrian identifiers such as tax or social security numbers have no category of their own. After cue words such as “Steuernummer” or “Sozialversicherungsnummer” they are pseudonymised if the number is written without spaces. For other spellings such as “Steuer-ID”, or numbers with spaces, add a custom rule.
Read next
Still have a question? Write to us.
