Governed AI for confidential work

Use AI on the documents you would never paste into a chatbot.

VaultLM gives European organisations a controlled way to analyse confidential documents with approved AI models. Original files stay inside the workspace; permissions, masking and context selection determine what a model may receive; every answer can be checked against its sources.

Built for legal, HR, finance, advisory and leadership teams that cannot rely on consumer chat accounts.

Original files remain in your workspaceModels receive protected, permitted contextAnswers cite source passagesEach request leaves an audit event
Product

One governed workspace between your documents and the model.

Users work from vaults with defined permissions. VaultLM selects permitted context, masks identifying data where required and records the route. The model receives the protected input needed for the chosen workflow—not an unrestricted raw upload.

Your confidential workspace

Contracts, HR files, client records, board packs and other controlled material.

VaultLM control layer

Permissions, masking, pseudonymisation, context selection and approved model routes.

A reviewable result

Answers or derived outputs with cited passages, route information and an audit event.

What stays where
Inside VaultLMOriginal files, identity mappings, permissions, retention rules and audit evidence.
Outside the vault boundaryOnly protected excerpts or derived context required by the selected and permitted workflow.
Three governed modes

Use the source, the document workflow or approved model knowledge—deliberately.

The workspace makes the chosen mode visible so a user does not accidentally turn a document task into an unrestricted general-AI request.

Source-grounded Q&A

Ask questions answered from permitted vault sources and linked back to the exact passages used.

Governed document jobs

Run summaries, comparisons or extraction across complete documents through the controlled pipeline; a raw dossier is not simply pasted into a chat.

Approved model knowledge

Allow broader model knowledge only when the workspace policy and the user intentionally select that route.

Business impact

Stop choosing between useful AI and responsible handling of confidential data.

VaultLM turns the controls that people usually perform manually into one repeatable workspace.

Unlock blocked workflows

Analyse contracts, client files, HR records and board material that ordinary chat tools cannot responsibly handle.

Replace shadow AI and manual redaction

Give teams an approved route instead of private accounts, copied files and inconsistent redaction.

Produce evidence, not just answers

Keep the sources, model route and relevant events available for review after the answer is used.

How it works

A repeatable route from document to decision.

Every request follows visible controls. VaultLM takes over the masking, context selection and evidence capture that people otherwise do inconsistently by hand.

01

Place documents in a vault

A user or invited contributor adds documents to a vault with defined access, ownership and retention.

02

Apply the protection policy

VaultLM masks or pseudonymises identifying data before preparing any context for an external model route.

03

Select the permitted context

Only sources the user may access and context needed for the chosen task are included.

04

Review the answer and evidence

The result returns with source passages, route information and an audit event for human review.

AI access cannot expand the user’s underlying document permissions.
Who it is for

Built for teams whose most useful information is also their most sensitive.

The strongest fit is a European knowledge-intensive organisation that wants practical AI adoption without building an enterprise AI platform from scratch.

Professional services

Consultancies, legal and accounting firms, recruiters and corporate-finance teams working with confidential client files.

Confidential business functions

HR, legal, finance, compliance and board teams working with employee, contract and management information.

PE-backed and regulated SMEs

Organisations that need stronger governance than consumer AI, with faster deployment than a bespoke enterprise programme.

Strong buying signal: employees are already using AI, but confidential documents are still forbidden, manually redacted or handled through private accounts.
Security

Make the data route explainable before asking people to trust it.

VaultLM links every request to permissions, a protection policy, an approved route and reviewable evidence.

Access follows source permissions

A user cannot retrieve more through AI than they may open in the underlying vault and source set.

Required masking fails closed

If a required protection step is unavailable, the external model request stops instead of bypassing it.

Context is minimised per workflow

The selected route receives protected context needed for the task, not an unrestricted raw dossier by default.

Managed routes keep EU data residency

Managed routes are configured for EU data residency. Customer-controlled keys follow the configuration and terms of that provider route.

Evidence is attached to the answer

Source passages, route details and relevant audit events make later review possible.

Pseudonymisation still needs judgement

Reversible masking remains pseudonymisation; sensitive or high-impact conclusions still require human review.

Review the architecture, not just the marketing claim.

The public security page explains the architecture, data flow and operational controls. The downloadable one-page overview is suitable for an initial internal or procurement review.

Public security details · downloadable one-page data flow
Why the workflow matters

The model supplies intelligence. VaultLM supplies the boundary, evidence and control.

The difference is not another chat interface. It is the governed route around the model.

ControlStandalone AIWith VaultLM
DocumentsFiles are copied or uploaded into an individual chatSources remain in a workspace with permissions, ownership and retention
Identifying dataPeople redact manually, inconsistently or not at allMasking and pseudonymisation are applied before protected external processing
Model contextThe service receives whatever the user sendsThe route receives selected and permitted protected context
EvidenceDepends on the chat product and user behaviourAnswers retain source passages, route information and recorded use
OrganisationKnowledge stays in private accounts and copied chatsVaults, roles and policies create a reusable organisational workflow
Pricing

Start with one professional. Add central governance as the organisation grows.

Each plan includes the secure workspace and managed AI capacity. Team and Organisation add shared vaults, permissions, policies and central controls.

Professional

For one adviser or specialist working with confidential documents.

16
per user / monthBilled annually
  • 1 user
  • Private vaults and persistent chats
  • Data masking, citations and audit trail
  • 10 GB storage
  • Managed AI usage included
Request access

Organisation

For multiple teams with central governance.

33
per user / monthBilled annually
  • 11–100 users
  • Organisation-wide policies and model routes
  • Advanced audit, retention and usage controls
  • Priority onboarding and support
  • Higher workspace limits
Request access

Enterprise

For custom security, deployment, contracts or volume.

Contact us
 
  • Custom users and capacity
  • Security and architecture review
  • Custom DPA, SLA and procurement support
  • Dedicated or customer-controlled routes
  • Contracted usage and support
Contact us

A seat covers the secure workspace. AI capacity covers model use.

You do not need to count tokens yourself. VaultLM translates model usage into a workspace budget, warns administrators at 80% and does not create uncontrolled overage by default.

Prices exclude VAT. Annual plans are billed yearly. Managed AI usage is subject to fair-use and workspace limits; administrators receive a warning before additional capacity is used.

During the final test phase, access requests are reviewed and new workspaces are opened selectively.

AI Act

AI governance is becoming part of everyday operations.

The AI Act is risk-based. Which duties apply depends on your organisation’s role, intended use and the system’s risk category. VaultLM helps put practical controls around confidential document use without claiming automatic compliance.

VaultLM supports operational controls. It is not a compliance certificate.

VaultLM supports access control, data minimisation, logging, source traceability and human review. Legal classification, risk assessment and the duties that follow still require an organisation-specific assessment.

Q&A

Questions security, legal and business teams ask before a pilot.

Clear answers about the data boundary, whole-document workflows, model routes and AI Act positioning.

What does VaultLM do?

VaultLM creates a governed workspace between confidential documents and AI models. It applies document permissions, protection policies and model routes, then returns results with sources and an audit trail.

Who is VaultLM designed for?

VaultLM is designed for European professional-services firms and confidential HR, legal, finance, compliance and leadership workflows. The strongest fit is a team that already sees demand for AI but cannot responsibly use ordinary chat accounts with its documents.

What does a whole-document workflow mean?

It means VaultLM can run a governed task across a complete document or document set, such as summarisation, comparison or extraction. It does not mean a raw dossier is simply pasted into an unrestricted chat prompt.

Does the full document go to an external AI provider?

The route receives the protected context required by the selected workflow and policy. In source-grounded Q&A this is normally selected, permitted passages; governed document jobs process the complete task through the controlled pipeline rather than treating the raw document as a free-form chat upload.

Is the data anonymised?

VaultLM uses data masking and pseudonymisation when it keeps a reversible identity mapping. Legal anonymisation depends on the context and cannot be assumed automatically.

Can the model use knowledge beyond my documents?

Yes, where the workspace policy and the user deliberately select an approved model-knowledge route. Source-grounded mode remains available when answers should be limited to vault sources.

Where is data processed?

Managed VaultLM routes use EU data residency. Customer-controlled provider keys or dedicated routes follow the configuration and contractual terms of that selected route.

Is VaultLM “AI Act compliant”?

There is no useful blanket compliance label for every workflow. VaultLM supports operational controls such as access control, data minimisation, logging, source traceability and human review; the legal classification and duties depend on the organisation, use case and system.

What happens if masking is unavailable?

A required protection step fails closed. The external model request stops instead of forwarding unprotected context.

How can I access VaultLM?

Request access through the VaultLM app. During the final test phase, requests are reviewed before a workspace is created.

Start with one blocked workflow

Bring one confidential workflow—not an enterprise transformation programme.

Tell us which documents, users and review steps are involved. We use that to assess the data route and choose the smallest suitable workspace.

  • Verify a work email and organisation
  • Describe one document workflow and its users
  • Review the data route, model route and security needs
Request accessSign in to VaultLMAccess requests are reviewed and workspaces are opened selectively during the final test phase.
Request access