Product sheet · Datasheet
As of 07/2026
PII anonymisation · Switzerland
Sovereign Cockpit
Anonymise, review and release confidential data locally: the raw text never leaves your control, and you can prove it.
A controlled workflow before any cloud model or dispatch: confidential data anonymised locally, every step provable in the audit trail, release only on your click.
01
Replace locally
With the on-premise option, confidential data is detected locally and replaced with placeholders.
02
Review & release
Only your click at the human gate releases the anonymised version; the mapping with the original values stays on the server.
03
Re-identify
Paste the external model's response back in: Sovereign Cockpit restores the original values.
What it delivers
Enforced human gate. Nothing leaves the server without your release.
Tamper-evident audit trail. HMAC-chained, provably unaltered, PII-free.
Your own standard terms. Company name, clients, product codes: entered once, anonymised everywhere.
Swiss data types built in. AHV, IBAN, CHE-UID, GLN/ZSR and more.
Everything encrypted at rest. AES-256-GCM, key held separately from the data volume, deletable per click.
Offline-capable sign-in. In-app users, Argon2id, no external service.
German & English. Fully bilingual interface.
Data kept in Switzerland. On-premise or hosted (your choice).
Noticeably less review effort. One card per company and person instead of long candidate lists per type.
Deployment options
Highest sovereignty
On-premise
App and name detection run entirely on your side, your own hardware.
Hybrid
Your DC + Swiss cloud
App in your data centre, detection via a Swiss cloud API (Infomaniak).
Hosted · CH
Single-tenant
Isolated instance per customer in Switzerland, own key and audit trail.
Indicative pricing
Hosted (CH)
from CHF 250 / month · annual plan
Isolated instance, data kept in Switzerland, 5 users included. Operated by iConference.
On-premise
from CHF 180 / month · annual plan
Runs on your hardware (requirements on consultation), 5 users included.
Indicative per instance/company. Concrete quote after a short conversation.
Sovereign Cockpit
Technology & security
Security architecture
Several independent layers, not one model
Deterministic CH recognisers
→
NER (person/location/org)
→
Local free-text pass
→
Merge
Human gate
→
Manual masking
→
Independent egress backstop
The egress backstop is a second, deliberately broader check before release, independent of the main recogniser, so a gap does not sit twice in the same layer.
What stays protected
Everything encrypted at restAll case data (original through standard terms) with AES-256-GCM, kept locally in your instance only; key held separately from the data volume. Deleted per click, verifiable in the audit chain.
Tamper-evident audit trailHMAC-chained log, PII-free, every change provable.
Fail-closed everywhereIf a step fails (detection, scanned PDF without a text layer), the case aborts, rather than passing on unchecked data.
Egress control before releaseIf protected values remain in plain text, release is held and put to you for approval, recorded in the audit trail.
Detected data types (Swiss focus)
AHV number
CH IBAN
CHE-UID
GLN
ZSR
Credit card
VAT ID
Case number
E-mail / phone
Address / ZIP
Property ID
Building insurance number
Company
Person (NER)
Location (NER)
Organisation (NER)
Free-text names
Your own protected terms can be stored as standard terms: encrypted, for all future documents.
Names, places and companies are detected language-independently by NER. Country-specific identifiers (e.g. German tax ID, commercial-register number) are available as a recogniser module for your country on request.
Newly detected: case numbers also in slash format, one- and two-digit date entries, and Romance-language land-register terms such as foglio and particella. Surnames stay protected across every spelling variant, even when a line break in the PDF splits them apart.
Formats & limits
Supported: PDF with a text layer, Word (DOCX), Markdown, text, Excel (XLSX).
Scanned PDFs without a text layer are deliberately rejected (fail-closed). OCR is on the roadmap.
Limit 150,000 characters or 25 MB per upload.
Models
Name detection either fully local or via a Swiss cloud API.
Model-independent: protection rests on several independent check layers, not on a single model. You are not tied to any particular AI model.
Positioning
A pre-stage tool, not a platform
Sovereign Cockpit sits in front of anything you send out (a cloud model, email or handover) and replaces neither chatbot, RAG nor DMS. At its core: an enforced release by a human in the reversible flow and a tamper-evident audit trail; Swiss identifiers are recognised out of the box.