Your secrets stay where they belong.
Cogni6 puts AI to work on the context of a real engagement without sending the source file as-is. The document is read on your computer, sensitive values are replaced before any external send and the result is reconstructed locally.
The native file and its name are not sent to the external model.
Only extracted and pseudonymized text can cross the sending boundary.
A failed check blocks the send instead of letting plaintext through.
64%
of surveyed privacy and security professionals worry about inadvertently sharing sensitive information publicly or with competitors when using generative AI.
Source: Cisco 2025 Data Privacy Benchmark Study. More than 2,600 respondents across 12 countries.What happens to a secret before, during and after AI
Protection does not depend on an instruction given to the model. Cogni6 enforces it at every step, from opening the file to returning the response.
- The document is read and extracted on your computer. The native file and its name do not cross the boundary to an external model.
- Cogni6 detects names, contact details, organizations and other sensitive values. You can review what it found before proceeding.
- Sensitive values are replaced with placeholders. The sending boundary accepts only this pseudonymized text and blocks the action if a check fails.
- The response returns in pseudonymized form. Cogni6 restores the values on your computer using the mapping table that remains in the vault.
Why Cogni6 keeps an audit trail
A confidential engagement must remain explainable without duplicating its secrets in every log. Cogni6 preserves the operational facts needed for evidence, not the original content.
Reconstruct. The audit trail shows which event occurred, when it happened and in which vault so the path of an action can be understood.
Attribute. A run records the selected model and its exact version. When a step requires a human decision, the model cannot assign the approval to itself.
Investigate without exposure. Logs, traces and error messages exclude sensitive values. An investigation does not require copying the client’s secret.
Produce evidence. The append-only audit trail can be exported to support a client review, an incident analysis or a governance record.
Protection does not depend on good intentions
Safeguards are built into product boundaries and verified on every change. They depend neither on a developer’s memory nor on a promise made to the model.
Each client has a distinct encrypted vault with its own key. The master key remains in the operating system’s keychain.
The model boundary accepts only text that has already been pseudonymized. Raw vault text does not match the format it can receive.
Network access is reserved for defined boundaries. An automated guard rejects a network dependency in any layer that is not authorized to have one.
Every change that touches a vault, detection or the network must include tests. A regression in those areas blocks integration.
The EU AI Act calls for evidence
The European Union’s Artificial Intelligence Act, generally known as the EU AI Act, has broadly applied since 2 August 2026. Requirements specific to Annex III high-risk uses will apply on 2 December 2027 under the revised timeline. Cogni6 supports governance and evidence; it does not classify your use or issue a compliance verdict.
Read the consolidated text of Regulation (EU) 2024/1689Qualify the use case. Obligations depend on the organization’s role, the intended purpose and the context. The same platform can be classified differently from one engagement to another.
Keep a useful record. Cogni6 preserves the model and its exact version, the pseudonymized exchange and execution events inside the vault. Secrets are not copied into the audit trail.
Maintain human oversight. When a step requires a decision, the model cannot assign the approval to itself. The professional can review, correct or reject the result.
Document capabilities and limitations. Safeguards, providers and known limitations support governance; AI literacy and legal analysis remain the organization’s responsibilities.
These mechanisms can support your governance record. They are neither a certification nor an automatic guarantee of compliance with the EU AI Act.
Bring the constraints of a real engagement
A demo can start with your actual requirements: secret type, client rules, permitted models, human approvals and expected evidence. We show the data path and what the audit trail can demonstrate.
See Cogni6 on a real engagement