At last, the right to use
frontier AI models
on your real files.
The rest of the world works with cutting-edge AI. You're confined to a watered-down "industry" assistant — because professional secrecy bars you from the best models the moment a file actually matters. ndaact.ai lifts the ban: it redacts your clients' data locally before anything reaches ChatGPT or Claude, then restores the reply in clear. Your disciplinary risk, reduced and provable.
Clipboard + web access + text PDF · local · reversible · auditable (GDPR Art. 30) · 2 devices (work + personal)
You're not a redaction clerk.
Or a censor.
Stripping out the name, the national ID, the bank number by hand, one by one, before every prompt: it's time-consuming, it pulls you out of your work, and it never holds.
Under the pressure of a case, you ease off. You miss a line. You let a date of birth slip through. Manual redaction doesn't fail through carelessness — it fails because it isn't your job.
ndaact.ai does the redaction for you, on every send, without a second thought. Systematic where humans are fallible.
Your clients trust you with their secrets.
ChatGPT sends them to OpenAI.
Pasting a case file into a consumer LLM interface means handing personal data to an uncontrolled third party. For a regulated profession, that's not an option.
Professional secrecy
Lawyers, notaries, physicians: client data must not leave your circle of trust.
GDPR — Article 30
Transferring personal data with no legal basis and no records of processing. The risk is real.
Health data
A name tied to a condition becomes health data. It requires certified hosting.
ChatGPT Enterprise, Azure OpenAI or a self-hosted LLM reduce the contractual risk — but the identifying data still leaves the workstation. With local redaction, it never does.
Local. Reversible. Auditable.
ndaact.ai sits between you and the LLM. It redacts on every send, automatically, then rebuilds the reply for you. Nothing sensitive leaves your machine.
Detect
Checksum regex (national ID, IBAN mod-97, company number/card Luhn, email, phone, IP) + NER for names.
Tokenize
Each entity becomes {{TYPE_xxxx}}, derived via HMAC-SHA256. The token never leaves the machine.
Send
The cleaned prompt goes to OpenAI or Anthropic. The LLM works on tokens, not on your clients.
De-tokenize
The reply becomes readable again for you, with the real values re-inserted locally.
What sets us apart
Most redaction tools send your documents to a server, or settle for a pattern filter. ndaact.ai does both things differently.
100% local — nothing leaves for a server
Detection and redaction run on your machine. Unlike cloud solutions (even those hosted in France), your documents pass through no third-party service before they're cleaned. An argument you can defend before a client, a court or your professional body.
A specialized model that runs locally
Not just rules: a named-entity recognition model trained for French, embedded and run on your workstation. It spots names, addresses and organizations in natural language — where a plain filter misses them. No outbound connection for the analysis.
Deterministic regex + model, all in one
Regulated French identifiers (national ID, company number, IBAN, physician registration) are validated by their check digit — not just recognized by their shape. The specialized model handles the rest. Both layers ship together, with no second server to install or wire up.
A tool that does nothing but regular expressions catches what has a fixed shape — an email, a number. But it doesn't understand the text. In this sentence, it lets the essentials slip:
"The file for Ms. Sophie Laurent, manager of the Tilleuls property company based at 12 rue de la Paix in Lyon, concerns…"
No pattern flags that a person's name, a company name or an address are hiding inside an ordinary sentence. That's exactly what ndaact.ai's local specialized model detects — and what a pattern filter, free or paid, lets leave in plain text toward the LLM.
Built for those who can't afford to slip
ndaact.ai is aimed at professionals for whom confidentiality is an obligation, not a preference.
Lawyers
Case files, pleadings, formal notices.
Notaries
Deeds, civil-status records, estate data.
Physicians
Reports, letters, health data.
DPOs & consultants
GDPR compliance for internal AI use.
Private by design
Privacy isn't a configuration option. It's the architecture.
Tokens never leave the machine
The data ↔ token mapping vault stays local, encrypted.
Drop-in
You change a single variable. No change in your habits.
Article 30 audit trail
Every detection is logged for your records of processing.
100% local processing
Redaction runs on your machine. No cloud black box.
Frequently asked questions
What lawyers, notaries, physicians and DPOs ask us before adopting ndaact.ai.
What is ndaact.ai?
ndaact.ai is a local privacy proxy that detects and replaces personal data (name, address, national ID, bank details, company number, email, health data) in your prompts before they reach ChatGPT or Claude, then rebuilds the reply. It lets regulated professions use generative AI without exposing their clients' secrets.
Does my data get sent to a server?
No. Detection and redaction run entirely on your machine. No personal data passes through an ndaact.ai server or any third-party service before it is replaced by a token. Only the already-redacted prompt is sent to the LLM: its provider receives neither identity nor re-identification key. It's local, reversible pseudonymisation (GDPR Art. 4(5)) — the mapping table stays on your workstation.
Is ndaact.ai compatible with professional secrecy and the GDPR?
Yes. Because no identifying data leaves your workstation, using ChatGPT or Claude is no longer a disclosure to a third party. Every detection is logged locally, which feeds your records of processing under Article 30 of the GDPR. It's an argument you can defend before a client, a court or your professional body.
How is this different from a simple regular-expression filter?
A pattern filter (regex) only catches things with a fixed shape: email, bank number, ID number. It doesn't understand the text, and it lets a person's name, a company name or an address hidden in an ordinary sentence slip through. ndaact.ai combines deterministic regex and a specialized language model running locally to catch those contextual entities too.
Does the AI's reply stay readable despite the redaction?
Yes. Tokenization is reversible: ndaact.ai replaces each data point with a token before sending, then de-tokenizes the LLM's reply automatically. You get back a complete, readable text with the real values restored — while the LLM never saw the actual data.
Which professionals use ndaact.ai?
Professions for whom confidentiality is a legal duty: lawyers (case files, pleadings, formal notices), notaries (deeds, civil-status records, estate data), physicians in private practice (reports, health data) and DPOs or consultants governing internal use of generative AI.
Which tools does ndaact.ai work with?
ndaact.ai sits between you and the main in-browser AI assistants (ChatGPT on chatgpt.com, Claude on claude.ai) through a Chrome and Edge extension, and a desktop app available for macOS and Windows. You keep your usual tool; redaction happens on every send, automatically.
Available right now
ndaact.ai installs in a few minutes: desktop app (macOS, Windows) + Chrome / Edge extension. It protects your clipboard, your web access and your text PDFs, across both your machines. No commitment, cancel anytime.
- Frontier Claude and ChatGPT, on the web (Chrome / Edge extension)
- Clipboard (copy-paste, in any app) + text PDF (no images)
- 2 devices — work computer and personal PC
- Local log retention, 6 months
- General network proxy (all AI tools)
- Multiple connected devices
- Local log retention, no time limit
- Document pre-redaction (RAG)
- More coming soon
Billed by Inkan.link, in euros. Cancel anytime from your account.