Anonde Agent runs inside your network and anonymizes PII and secrets (names, emails, API keys) before it reaches Claude, ChatGPT, Cursor, or any model. Real values are revealed only inside your own trust boundary.
You don't change your LLM vendor. You don't add one to your audit scope. You add a PII boundary in front of what you already use.
Anonde sits between your people and whatever model you already trust. The upstream provider only ever sees tokenized text, so it never enters your audit scope as a new processor of personal data.
OpenRouter by default · BYO OpenAI, Anthropic, Azure OpenAI, AWS Bedrock · self-hosted vLLM & Ollama
PII and secrets are detected and swapped for stable placeholder tokens before the prompt leaves your network.
The tokenized payload goes to the model you chose. The provider sees structure and intent, never identities.
The response is de-tokenized inside your network, gated by actor and purpose. Raw values never touch a third party.
The Agent is deployed inside your network and intercepts LLM-bound traffic at the egress, tokenizing PII before anything leaves. Desktop apps, IDE copilots, browser chats, CLI tools: every client that routes through it is covered, with nothing to install on employee machines and no behavior change. Sensitive data never crosses the boundary.
Paste anything sensitive. PII is masked before the model sees it and revealed locally in the answer. The same engine that powers the Agent.
A public, quarterly benchmark across languages and corpora. We publish wins and losses. Accuracy is a measured artifact, not a marketing claim.
View the benchmark →Community-authored recognizers per industry, region, and language. A searchable catalog that compounds with every contribution.
Cryptographically attestable, write-once logs that map to SOC 2, HIPAA, and EU AI Act Article 12: evidence your compliance team can hand an auditor.
Leak rate is the share of PII a data anonymization engine misses, so lower is better. In our latest public benchmark, Anonde leaks less than Microsoft Presidio across clinical, legal, finance, and PII corpora in five languages.
Across the matrix, anonde-ner is the lowest-leak engine on 29 of 29 gold-annotated corpora. Rolled up, the Σ-all leak rate is 10.1% (Anonde) vs 41.5% (Presidio). The premium anonde-ner-stack image lands at 7.6%.
Leave your name and email. We'll reach out when access opens for your team.
Name + email, or continue with GitHub.
The Anonde detection-and-tokenization engine is Apache-2.0, written in Go, and runs as a library or a container on your own infrastructure. The Agent and the admin, SSO, and audit platform are the commercial layer on top.
Book 15 minutes with the founder. No pitch. We want to hear what's blocking your AI use case and what would make Anonde genuinely useful to you.