Request HEIMDALL.
30 minutes are enough for a first read on your policies: what is regulated today, what HEIMDALL makes of it, what your observation mode would look like.
NewFor the safe path to the cloud
HEIMDALL is the firewall for AI: it checks every request to ChatGPT, Claude, Gemini & Co. before it leaves your house. It replaces sensitive details with placeholders, translates the answer back locally and logs every decision. By your own policies, on your hardware.
The round trip of a request: inside the house it carries real names, the cloud receives only placeholders, and the answer is translated back locally.
Write a short friendly email to our customer Siemens about project P-4711. Contact is Anna Weber in Erlangen. Two sentences.
4 details protected · Policy “IT-Richtlinie §4.2 — Cloud-KI-Nutzung”
Subject: Project P-4711. Dear Anna Weber, we hope all is well in Erlangen. The project is progressing well and we are excited about what we are building together with Siemens.
Translated back locally: you read the real values.
Write a short friendly email to our customer ⟨CLIENT_A⟩ about project ⟨PROJEKT_A⟩. Contact is ⟨PERSON_A⟩ in ⟨LOCATION_A⟩. Two sentences.
That is all the provider sees.
Your people have been using cloud AI for a while now, officially or quietly. That leaves two uncertainties inside your house, and good intentions alone do not fix either of them.
Corporations negotiate their own contracts. What you get is the training toggle. Whether and how your inputs are stored and processed follows the provider’s terms. You cannot audit them.
Even trained employees slip: the customer name in the prompt, the contract excerpt in the attachment, the rush before a deadline. Training is mandatory, but it is not a safeguard.
That is the uncertainty you work with today. Every day.
HEIMDALL forbids nothing, it protects: sensitive details are replaced with placeholders before the request leaves your house, and put back in the answer. Four steps, and you can look at every one of them.
Using HEIMDALL costs you nothing in quality. That is why it gets used instead of bypassed.
One full pass, uncut: five details detected, sent protected, translated back locally.
Upload the policy, confirm the rules, start observation mode. Not a project, an appointment.
You do not write rules. HEIMDALL compiles them from the policies you already have. You review and approve.
IBANs, credit cards, tax IDs, API keys and passwords: built in, and no AI can overrule them.
A local model catches what no list contains: the project name, the internal shorthand, the delicate connection.
Every decision in the audit log: what was detected, what left the house, who decided.
Works with any provider offering an OpenAI-compatible interface. Change the model and your protection stays.
HEIMDALL does not invent new rules. It enforces what already applies in your house.
IBANs, credit cards, tax IDs, API keys, passwords: the baseline every company needs. Immutable, because no AI can overrule these rules.
Upload your IT policy, NDA templates or works agreement. HEIMDALL proposes concrete rules from them, quoting the passage it found. You confirm, adjust or discard.
When the checker spots something sensitive that no rule covers, it proposes a new one. Your policy grows with everyday work. The last word stays with you.
Internal project numbers (pattern P-XXXX) leave the house only as placeholders.
Source passage“Project designations are to be treated as confidential towards external services.”
IT Policy §4.2, transmission to external services
Uncertainty only ever errs towards caution: when the check is unsure, HEIMDALL asks. You.
HEIMDALL is built into LOKI and sits at exactly one place: where a request would leave your house. Local models never pass through it, because there is nothing to protect there. Only when you pick a cloud model in LOKI does it check every request on the way out. And on the way back the answer passes through it again: the placeholders are translated back into the real values, locally.
We refuse to run a covert filter: because of co-determination, because of transparency obligations, and because every employee should see daily that the company protects its data.
When a cloud model is active, LOKI says so openly. And it says that HEIMDALL checks every outgoing request against company policy.
In warning mode HEIMDALL asks whenever content is flagged, naming the policy that applies. Whoever decides knows why.
In regular operation “send protected” is the default: one discreet note per intervention, not one click more than necessary.
Every outgoing call appears in the compliance audit log: what was detected, what left the house, how it was decided. That is the difference between “we are careful” and evidence.
Data minimisation and accountability: placeholders instead of personal data, and every decision documented.
Trade secrets are only protected if you can demonstrate appropriate measures. HEIMDALL is such a measure, log included.
Operator duties and transparency: you know and can prove which data reached which AI system.
Control over outbound data as an auditable technical measure, not as a statement of intent.
Your existing policy, your templates. As PDF or Word, exactly as they are.
HEIMDALL proposes rules and you walk through them sentence by sentence: confirm, adjust, discard.
The system tests itself against your own policy. Accuracy is measured before anything is enforced.
In observation mode you see what HEIMDALL would have caught, without it intervening.
Observe → Warn → Enforce
Enforcement starts when your metrics reach the agreed corridor. Not before.
Accuracy here is measured, not claimed: on your policy, before activation.
LOKI for your knowledge. MINERVA for your machines. HEIMDALL for the safe path to the cloud. Each product runs on its own. Together they are one system: one machine, one login, one role model, one audit log, one works agreement. Every application inherits what is already in place.
HEIMDALL is already built into LOKI: every cloud request from LOKI passes through it.
The question is not whether your people use cloud AI. It is what they hand over when they do.
30 minutes are enough for a first read on your policies: what is regulated today, what HEIMDALL makes of it, what your observation mode would look like.
HEIMDALL runs on your hardware, as part of LOKI. We only quote accuracy figures once they have been measured on your policy. And they are measured before activation.
Still have questions?
Read the FAQ