NewFor the safe path to the cloud

Use cloud AI. Keep your secrets.

HEIMDALL is the firewall for AI: it checks every request to ChatGPT, Claude, Gemini & Co. before it leaves your house. It replaces sensitive details with placeholders, translates the answer back locally and logs every decision. By your own policies, on your hardware.

The round trip of a request: inside the house it carries real names, the cloud receives only placeholders, and the answer is translated back locally.

Your house

Write a short friendly email to our customer Siemens about project P-4711. Contact is Anna Weber in Erlangen. Two sentences.

4 details protected · Policy “IT-Richtlinie §4.2 — Cloud-KI-Nutzung”

Answer

Subject: Project P-4711. Dear Anna Weber, we hope all is well in Erlangen. The project is progressing well and we are excited about what we are building together with Siemens.

Translated back locally: you read the real values.

The cloud
External model

Write a short friendly email to our customer ⟨CLIENT_A⟩ about project ⟨PROJEKT_A⟩. Contact is ⟨PERSON_A⟩ in ⟨LOCATION_A⟩. Two sentences.

That is all the provider sees.

Two risks

Two risks you cannot switch off.

Your people have been using cloud AI for a while now, officially or quietly. That leaves two uncertainties inside your house, and good intentions alone do not fix either of them.

The provider.

Corporations negotiate their own contracts. What you get is the training toggle. Whether and how your inputs are stored and processed follows the provider’s terms. You cannot audit them.

The human factor.

Even trained employees slip: the customer name in the prompt, the contract excerpt in the attachment, the rush before a deadline. Training is mandatory, but it is not a safeguard.

That is the uncertainty you work with today. Every day.

How it works

Replace instead of block.

HEIMDALL forbids nothing, it protects: sensitive details are replaced with placeholders before the request leaves your house, and put back in the answer. Four steps, and you can look at every one of them.

01

You ask the way you always do.

Real names, real figures. Nobody has to hold back or paraphrase to keep data in. That is exactly what makes the protection workable day to day.

02

HEIMDALL checks before anything goes out.

Whatever your policy marks as sensitive is detected and named: the finding, the rule, the placeholder. You decide: send protected, handle locally or cancel.

The compliance check dialog in LOKI: detected details (organisation, project, person) with their placeholders and the three options Cancel call, Handle locally and Send protected.
03

The cloud only sees placeholders.

⟨CLIENT_A⟩ instead of Siemens: the external model gets the structure of your request but not its substance. And it still answers at full quality.

The card “What your request looked like to the cloud” in LOKI: the external model received only placeholders such as CLIENT_A, PROJEKT_A and PERSON_A; four details were protected.
04

You read the real names.

The answer is translated back locally: your screen shows the original values, a discreet note says what was protected, and the audit log holds the evidence.

The full round trip in LOKI: the question with real names at the top, below it the card with the placeholder view the cloud received, and below that the finished answer with the real names.

Using HEIMDALL costs you nothing in quality. That is why it gets used instead of bypassed.

One full pass, uncut: five details detected, sent protected, translated back locally.

Properties

Six reasons this holds up in practice.

Live in one afternoon.

Upload the policy, confirm the rules, start observation mode. Not a project, an appointment.

Rules from your own documents.

You do not write rules. HEIMDALL compiles them from the policies you already have. You review and approve.

Hard rules for the known.

IBANs, credit cards, tax IDs, API keys and passwords: built in, and no AI can overrule them.

AI for the unexpected.

A local model catches what no list contains: the project name, the internal shorthand, the delicate connection.

Auditable evidence.

Every decision in the audit log: what was detected, what left the house, who decided.

Provider neutral.

Works with any provider offering an OpenAI-compatible interface. Change the model and your protection stays.

Rules

Three sources. One policy.

HEIMDALL does not invent new rules. It enforces what already applies in your house.

Built in

IBANs, credit cards, tax IDs, API keys, passwords: the baseline every company needs. Immutable, because no AI can overrule these rules.

Compiled from your documents

Upload your IT policy, NDA templates or works agreement. HEIMDALL proposes concrete rules from them, quoting the passage it found. You confirm, adjust or discard.

Proposed from daily use

When the checker spots something sensitive that no rule covers, it proposes a new one. Your policy grows with everyday work. The last word stays with you.

Rule review

Internal project numbers (pattern P-XXXX) leave the house only as placeholders.

Source passage

“Project designations are to be treated as confidential towards external services.”

IT Policy §4.2, transmission to external services
This is how a review runs: one sentence, the passage it came from, your decision.
The policy editor in LOKI: the policy “IT-Richtlinie §4.2 — Cloud-KI-Nutzung” with its confidence threshold, the detected entity types such as person, location and organisation, and custom regex rules, for instance for project numbers.
Every rule stays visible and adjustable: entity types, custom patterns, confidence threshold. Per policy, per group.

Uncertainty only ever errs towards caution: when the check is unsure, HEIMDALL asks. You.

Integration

Inside LOKI. At the edge towards the outside.

HEIMDALL is built into LOKI and sits at exactly one place: where a request would leave your house. Local models never pass through it, because there is nothing to protect there. Only when you pick a cloud model in LOKI does it check every request on the way out. And on the way back the answer passes through it again: the placeholders are translated back into the real values, locally.

Day to day

Unobtrusive. Not invisible.

We refuse to run a covert filter: because of co-determination, because of transparency obligations, and because every employee should see daily that the company protects its data.

The notice in the tool.

When a cloud model is active, LOKI says so openly. And it says that HEIMDALL checks every outgoing request against company policy.

The compliance dialog.

In warning mode HEIMDALL asks whenever content is flagged, naming the policy that applies. Whoever decides knows why.

The quiet default.

In regular operation “send protected” is the default: one discreet note per intervention, not one click more than necessary.

The notice above the input field in LOKI: “Cloud model active — your messages and uploaded documents are sent to an external provider. HEIMDALL is active and checks all outgoing data against your company policies.”
No small print: the notice sits right at the input field. Every day, visible to everyone.
Evidence

Built for the audit.

Every outgoing call appears in the compliance audit log: what was detected, what left the house, how it was decided. That is the difference between “we are careful” and evidence.

The compliance audit log in LOKI: a table of all outbound calls with time, user, detected findings such as organisation, project and person, and the decision, for instance “Auto-redacted (policy default)”.
GDPR

Data minimisation and accountability: placeholders instead of personal data, and every decision documented.

Trade Secrets Act

Trade secrets are only protected if you can demonstrate appropriate measures. HEIMDALL is such a measure, log included.

EU AI Act

Operator duties and transparency: you know and can prove which data reached which AI system.

NIS2 · ISO 27001

Control over outbound data as an auditable technical measure, not as a statement of intent.

Rollout

One afternoon to running.

Upload

Your existing policy, your templates. As PDF or Word, exactly as they are.

Confirm

HEIMDALL proposes rules and you walk through them sentence by sentence: confirm, adjust, discard.

Measure

The system tests itself against your own policy. Accuracy is measured before anything is enforced.

Observe

In observation mode you see what HEIMDALL would have caught, without it intervening.

The rollout is a product property, not a project plan.

Observe → Warn → Enforce

Enforcement starts when your metrics reach the agreed corridor. Not before.

Accuracy here is measured, not claimed: on your policy, before activation.

Platform

IGNAITE is the platform.

LOKI for your knowledge. MINERVA for your machines. HEIMDALL for the safe path to the cloud. Each product runs on its own. Together they are one system: one machine, one login, one role model, one audit log, one works agreement. Every application inherits what is already in place.

HEIMDALL is already built into LOKI: every cloud request from LOKI passes through it.

The question is not whether your people use cloud AI. It is what they hand over when they do.

Next step

Request HEIMDALL.

30 minutes are enough for a first read on your policies: what is regulated today, what HEIMDALL makes of it, what your observation mode would look like.

HEIMDALL runs on your hardware, as part of LOKI. We only quote accuracy figures once they have been measured on your policy. And they are measured before activation.

Still have questions?

Read the FAQ