# curta.solutions — Full Content > Secure AI, Automation & System Integration for regulated organizations. Since 1998. > This file contains the full text content of all pages on curta.solutions. > For a structured index, see: https://curta.solutions/llms.txt ## curta.solutions — Secure AI, Automation & System Integration URL: https://curta.solutions/ > Secure system integrations, AI implementation, and automation — built for GDPR, ISO 27001, and ITILv4-aligned operations. Since 1998. Since 1998 ### Secure AI, Automation, and System Integration for Regulated Organizations By [George Curta](about.html) · Founder, curta.solutions · Updated May 24, 2026 We roll out and link modern tools. We set up AI safely. We automate work flows. **GDPR, ISO 27001, ITILv4, and audit trails built in**. [Book a Check-In Call](contact.html) [Explore Services](services.html) 700+ Endpoints Managed 26 Global Sites 80 Data Rooms Built 27+ Years Experience ITILv4 Service Value Chain How We Deliver GDPR Aligned ISO 27001 ITILv4 Service Ops Audit-Ready, day one What We Do #### Solutions that connect systems, protect data, and make AI productive ##### Deploy & Integrate Modern Platforms Microsoft 365 and Azure roll-outs. ERP link-ups. API webs. Safe shared work spaces with audit trails. ##### Implement AI Safely Prompt rules. Privacy shield patterns. Copilot roll-out. Audit-ready AI link-ups for regulated firms. ##### Automate Operations Power Platform automation. Low-code rules. Work flow control. Safe-by-design process upgrades. [Explore All Solutions →](solutions.html) Proof of Delivery #### Quantified Outcomes Results from real client work. Client names kept private — outcomes proven. 700+ Endpoints Managed Global M365 / Intune / Azure 26 Global Sites Many-country teams 80 Virtual Data Rooms SharePoint VDRs with audit 5,000 Accounts Governed User life cycle & RBAC [View Experience →](experience.html) Who We Help #### Regulated Mid-Market & Multi-Country Organizations ##### Regulated Industries Firms under GDPR, ISO 27001, NIS2 pressure. They need audit-ready docs and rules. ##### Multi-Country Operations Safety and ops patterns that scale across global sites. Shared baselines built in. ##### Data-Intensive Environments Shared work and data room rules. Access checks, logs, and keep rules. [Industries We Serve →](industries.html) #### Ready to discuss your requirements? Book a check-in call to size up your AI, safety, and link-up needs — with audit fit built in from day one. [Book a Check-In Call](contact.html) [Ask for a Review](contact.html) --- ## System Integration, AI & Automation | curta.solutions URL: https://curta.solutions/solutions.html > Solutions for system integration, AI implementation, GDPR-compliant AI, and process automation for regulated organizations. Solutions. ### Solutions that connect systems, protect data, and make AI productive Your team needs speed — but also proof: rules, logging, controls, and audit fit. We design solutions that integrate cleanly, scale world-wide, and remain audit-ready. Platform Link-up. #### Deployment & Integrations Rule-bound teams need clean link-up across Microsoft 365, Azure, ERP systems, and API ecosystems — with audit trails, role-based access, and safety controls built in from the start, not added later. [ ##### Solution Deployment & Integrations Microsoft 365 & Azure upgrade, ERP link-up, API ecosystems, and secure teamwork setups. Every rollout is logged for ITILv4 handover and post-go-live support. M365. Azure. Biz Central. API. Learn more →. ](solutions-deployment.html) AI & Auto-work. #### Enterprise AI Implementation AI adoption in rule-bound teams needs more than a model — it needs rules, data labeling, GDPR-audit-fit prompt pipelines, and an audit trail. Each solution below addresses a specific layer of that stack. [ ##### AI Implementation & Automation AI rollout strategy, Power Platform auto-work, Copilot rules, and low-code safety controls. Includes change control, user enablement, and DLP policy setup. Power Platform. Copilot. Auto-work. Learn more →. ](solutions-ai.html) [ ##### GDPR-Compliant AI Prompting Prompt policy & guardrails, logging & rules, data labeling for privacy-by-design AI usage. Defines which data categories may enter AI systems and under what terms. GDPR. Privacy. Prompting. Learn more →. ](solutions-ai-prompting.html) [ ##### GDPR-Compliant AI Integrations AI privacy shield patterns, reversible PII strip, audit-ready AI workflows with EU data residency. PII is found and stripped before data reaches the model, then reinjected in the response. Privacy Shield. PII strip. Middle-tier. Learn more →. ](solutions-ai-integrations.html) [ ##### AI in Existing Systems AI rollout in ERP, M365, and workflow layers with ID, DLP, and SIEM link-up. Avoids greenfield risk by extending existing systems rather than replacing it. ERP. M365. Workflows. Learn more →. ](solutions-ai-systems.html) [ ##### Predictions & Machine Learning Company-specific LLMs, predictive systems, and ML with rules-first approach and audit controls. Includes model selection, training data rules, and output checks pipelines. ML. LLM. Predictions. Learn more →. ](solutions-ml.html) Cross-Links. #### Related Resources ##### Delivery Methodology Learn how we structure projects with ITILv4 fit and rules-first rollout. Each buy-in follows Assess, Design, Implement, Operationalize, Improve — with docs at every stage. [View Approach →](approach.html) ##### Project Examples See anonymized case studies from firm-wide rollouts: ISO 27001 ISMS prep, M365 move with ITILv4, secure comms with trust level labels, and ML for predictive upkeep. [View Experience →](experience.html) ##### Security & Compliance Detailed info about our IT Safety & Audit fit service domain, including GDPR assessments, ISO 27001 gap study, and NIS2 readiness reviews. [View Services →](services.html) #### Need a tailored solution? Book a session to discuss your specific link-up, AI, or auto-work needs. [Book a Readiness Session](contact.html) [Request an Assessment](contact.html) --- ## Solution Deployment & Integrations | curta.solutions URL: https://curta.solutions/solutions-deployment.html > Microsoft 365 & Azure modernization, ERP integration, API ecosystems, and secure collaboration environments with audit trails. Solutions. ### Solution Deployment & Integrations Modern platform rollout with Microsoft 365 & Azure, ERP link-up, API ecosystems, and secure teamwork setups. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. What You Get. #### Capabilities ##### Microsoft 365 & Azure Modernization Tenant rules. Endpoint and ID patterns. Safety starting points. Tuning for speed, cost, and audit fit. Includes Conditional Access rules. Plus Entra ID setup. Plus Microsoft Defender hardening to fit team risk. ##### ERP Integration & Process Architecture Dynamics 365 Biz Central roll-outs and tuning. Process redesign for speed and audit fit. Link-up with finance flows. Sign-offs, match-ups, and reports are traced end-to-end. ##### API & Data Integration System-to-system auto-work. Linking finance, ERP, and bank systems. Safe, audit-ready data flows. Logged link-up design. Error-handling keeps data sound across linked systems. ##### Secure Collaboration Environments Data rooms with rights, audit trails, and audit reports. SharePoint-based virtual data rooms set up for tight outside sharing. Trust labels, keep rules, and access logs for rule-bound doc swaps. Typical Scenarios. #### Integration Patterns ##### ERP ↔ Finance ↔ Banking Auto-run match-ups, sign-offs, and audit-friendly reports. Linking Biz Central, DATEV, and bank systems. Finance teams see posted deals in real time. No manual exports. Sign-offs run role-based work flows. Full audit trail at each step. ##### Microsoft 365 ↔ External Tools One ID hub via Azure AD, RBAC, and life-cycle / off-board auto-work. Built for third-party biz apps. When a user changes role or leaves, access is pulled at the same time across all linked systems. Less shadow access. Easier audit proof. ##### SharePoint/Teams Collaboration Tight sharing, keep rules, DLP, and trust labels for in-house and outside teamwork. Guest access is run via set expiry times and sign-off flows. Outside parties keep access only for the span of a set project or buy-in. ##### When this is the right fit These link-up patterns work best in three cases. First, when a team runs many split systems with manual data transfers. Second, when GDPR, ISO 27001, or NIS2 demand logged data flows and audit trails. Third, when a cloud move to Microsoft 365 or Dynamics 365 opens the chance to build proper link-ups from the start, not to copy manual steps. ##### What this doesn't replace Roll-out and link-up work covers design, setup, and docs. It does not replace day-to-day IT support, system tracking, or help-desk work. Hardware buying, physical network gear, and third-party software licenses are also out of scope. For ops support needs, see the services page. Private Cloud. #### Private Cloud Collaboration & File Sync When data sovereignty needs that files stay under your control, we deliver self-hosted file sync & share solutions with firm-wide rules. ##### Self-Hosted Deployments On-premise or private cloud file sync & share platforms (e.g., Seafile) for rule-bound and data-touchy setups. ##### Identity Integration Link-up with directory services (LDAP/AD, Entra ID) for centralized ID and access rules. ##### Audit-Ready Operations Sharing rules, permission rules, full logging, and ops docs for audit fit. ##### Migration Paths Safe move from legacy file servers or unmanaged sync tools with data checks and parallel operation. [View Seafile Case Study →](experience-seafile.html) Outputs. #### What We Deliver ##### Integration Architecture Data flow maps, system diagrams, and tech specs for all link-ups. Each link-up is logged. Source and target systems. Data items. Mapping rules. Error handling. Steps to raise issues. The design stays usable by the in-house IT team after handover. ##### Security & Compliance Controls GDPR, ISO 27001, NIS2 controls logged and set up. Control docs hold the control goal. The tech or team step taken. The role on point. The proof shown to an auditor. The team can show audit fit, not just claim it. ##### Implementation Plan Phased rollout with cutover strategy, rollback steps, and acceptance criteria. ##### Operational Documentation Admin docs and ops runbooks for lasting ops. Fit & Limitations. #### Best fit and known limitations ##### Best for Mid-market teams upgrading Microsoft 365 and Azure. Or linking ERP and APIs. Or building safe teamwork with audit trails. ##### Not the right fit Pure greenfield startups with no Microsoft estate. Teams tied to non-Microsoft stacks (Google Workspace, AWS-first) with no plan to move. ##### Known limitations Microsoft license changes can shift cost mid-project. ERP link-up dates lean on the partner web and on source-system release pace. Some legacy connectors need a stop-gap middle layer. #### Need an integration assessment? Book a session to review your systems and find link-up chances. [Request Assessment](contact.html) [View Experience](experience.html) --- ## AI Implementation & Automation | curta.solutions URL: https://curta.solutions/solutions-ai.html > Enterprise AI implementation, Power Platform automation, Copilot governance, and low-code security controls for regulated organizations. Solutions. ### Enterprise AI Implementation & Automation AI rollout strategy, Power Platform auto-work, Copilot rules, and low-code safety controls — all with audit fit built in. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. What You Get. #### Capabilities ##### AI Rollout Strategy Biz-matched AI adoption with clear risk tolerance definition, use case prioritization, and rules framework. ##### Automation at Scale Power Platform (PowerApps, Power Auto-run, Dataverse) for firm-wide-wide process auto-work with rules. ##### Copilot Governance & Enablement Microsoft Copilot firm-wide adoption with guardrails, policies, and measurable outcomes. ##### Low-Code Governance Safety-by-design processes and controls for citizen dev work. Prevent shadow IT while letting innovation. Rollout Modules. #### Choose What You Need Module A • n8n. ##### Multi-LLM Automations with n8n Use n8n as a workflow backbone to connect biz systems with **one or multiple LLMs**, including retrieval-augmented flows and agentic auto-work. **Typical outputs:** - Reference design for n8n (self-hosted / hardening / backups / secrets control) - Reusable workflow library (intake → enrichment → approval → execution → audit logging) - LLM routing pattern (model choice by data trust level / cost / latency) - Guardrails: PII handling, output checks, escalation rules (human-in-the-loop) n8n. LangChain. Multi-LLM. Orchestration. Module B • Copilot Studio. ##### Copilot Agents + Power Platform Build task-specific agents for IT, Finance, Procurement, or Ops — grounded in governed data sources and connected through Power Platform connectors. **Typical outputs:** - Agent blueprints (use-cases, topics, actions, escalation) - Data access model (Entra ID permissions, least privilege, auditability) - Connector strategy: standard connectors, custom connectors, knowledge connectors. - Rollout plan: pilot → staged adoption → KPI-based gains. Copilot Studio. Power Apps. Power Auto-run. Agents. Module C • IT Auto-work. ##### Internal IT Onboarding Chatbot A company-in-house assistant that answers onboarding questions, guides device setup, explains policies, and routes requests — while respecting M365 data safety controls. **Typical outputs:** - Onboarding knowledge base (policies, how-tos, SOPs) with ownership and update cadence. - Ticket routing + approval workflows. - Data safety policy: trust level labels, access rights, and "no-leak" design for AI. Chatbot. Onboarding. Helpdesk. M365. Module D • Abacus.AI. ##### Abacus.AI Integrations Integrate Abacus.AI into the firm-wide setup for chat/agents, knowledge retrieval, and data-driven AI workflows, using connector models that can respect permissions and ID. **Typical outputs:** - Connector design (user-level vs org-level ingestion vs permission-aware connectors) - Link-up patterns for teamwork platforms and data sources. - Rules: RBAC fit, logging, and audit readiness. Abacus.AI. Firm-wide AI. Connectors. RBAC. Methodology. #### Automation Blueprint - **Find process candidates** — Volume, error rate, audit fit impact assessment. - **Define controls** — Roles, sign-offs, logging, data labeling needs. - **Build workflows** — Power Platform and/or n8n with rules from the start. - **Integrate with ERP/CRM** — Secure connections to biz systems. - **Operationalize** — Tracking, KPIs, ongoing gains cycle. - **Ongoing rules** — Safety reviews, change control, incident playbooks. **When this is the right fit:** Firm-wide AI rollout and auto-work is the correct buy-in type when an team has found specific processes — onboarding, sign-offs, finance reconciliation, HR support — that are high-load, error-prone, or audit fit-critical, and wants to auto-run them with proper rules built in. It is in part suited to teams already operating within Microsoft 365 who want to extend Power Platform or introduce Copilot with guardrails, or who want to deploy multi-LLM auto-work through a self-hosted workflow backbone such as n8n. **What this doesn't replace:** AI rollout strategy and auto-work rollout does not replace the team's own change control skill or in-house IT ops. Workflow auto-work tools such as Power Auto-run and n8n need ongoing administration, tracking, and update control after rollout — those ops duties remain with the team or a run service vendor. This buy-in covers strategy, design, build, and rules docs, not ongoing support or run ops post-rollout. Related Solutions. #### GDPR-Compliant AI [ ##### GDPR-Compliant AI Prompting Prompt policies, guardrails, and rules for safe AI usage without data leakage. Learn more →. ](solutions-ai-prompting.html) [ ##### GDPR-Compliant AI Integrations Privacy shield patterns and reversible PII strip for AI workflows. Learn more →. ](solutions-ai-integrations.html) [ ##### Predictions & Machine Learning Company-specific LLMs and predictive systems with rules controls. Learn more →. ](solutions-ml.html) Fit & Limitations. #### Best fit and known limitations ##### Best for Mid-market and rule-bound organisations rolling out Microsoft Copilot, Power Platform auto-work, or custom AI agents, where rules, ID, DLP, and audit fit must be wired in from day one. ##### Not the right fit Pure research labs without ops constraints; consumer-facing AI products without rule-set exposure; teams that already have a mature AI rules stack and only need point fixes. ##### Known limitations Model and feature uptime follow Microsoft's release cadence in the EU; some Copilot skills still vary by tenant region and licence; deep on-prem isolation is shipped via the [localLLM](project-localllm.html) buy-in, not this service line. #### Ready to implement AI safely? Book an AI & Safety Readiness Session to assess your team's AI maturity and audit fit posture. [Book Readiness Session](contact.html) [View Experience](experience.html) --- ## GDPR-Compliant AI Prompting | curta.solutions URL: https://curta.solutions/solutions-ai-prompting.html > Privacy-by-design AI prompting with policies, guardrails, logging, and data classification for GDPR and ISO 27001 compliance. Solutions • AI Rules. ### GDPR-Compliant AI Prompting Privacy-by-design prompting policies that prevent info leakage while letting AI productivity in rule-bound setups. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. The Problem. #### Why This Matters Teams accidentally paste private, private, or contract-relevant data into AI prompts — creating data leakage and audit risk. Without clear policies and controls, AI adoption becomes a audit fit liability. This happens across all departments. A lawyer pastes client names and case details into a public AI tool to summarize a document. An HR manager uploads employee speed data to make a review draft. A finance analyst shares contract terms to produce a summary. In each case the intent is useful, but the data handling is non-audit-fit. GDPR needs a lawful basis for processing private data, and sending that data to an outside AI model constitutes processing. Without logged policies, approved tools, and proof of user training, teams cannot show audit fit during an audit or probe. ISO 27001 clauses covering info labeling and info safety policies apply directly to AI tool usage decisions. Establishing prompting rules before AI adoption scales is a lot easier than retrofitting it after incidents occur or regulators inquire. What We Implement. #### Governance Framework ##### Prompt Policy & Guardrails - What may be prompted. - What must be anonymized/redacted. - Approved tools and setups. ##### Prompt Logging & Governance - Traceability for audits. - Role-based access controls. - Incident finding and response. ##### Data Classification in Prompts - Trust level labels link-up. - DLP controls for AI tools. - Microsoft Purview fit. Audit fit Anchoring. #### Built for Regulated Environments - **GDPR and ISO 27001 fit** as starting point needs. - **NIS2 considerations** for safety posture. - **DLP, Info Safety, Audit Logging** via Microsoft Purview. - **MIP/Trust level Labels** link-up for data labeling. Outputs. #### What You Get ##### AI Prompting Standard Full policy document defining acceptable use, prohibited practices, and rules needs. The standard specifies which data labeling levels may be entered into which AI tools, and which tools are approved for which use cases. It also defines what PII strip or redaction is needed before prompting with touchy content. ##### Prompt Templates & Training Ready-to-use templates for common use cases and user training materials. Templates target the most frequently requested AI tasks — document summarization, draft generation, policy lookup. They ship pre-cleared for use with specified data labeling levels. This removes the need for users to make individual audit fit judgments each time. ##### Governance Dashboard Concept KPIs, incident tracking, and adoption metrics for ongoing rules. The dashboard concept defines which signals to monitor through Microsoft Purview and Entra ID audit logs. It also defines what thresholds constitute a audit fit event requiring review. The final piece is how to report AI usage patterns to info safety leadership on a regular cadence. Audit fit Context. #### Regulatory Alignment Multiple rule-set frameworks applicable to rule-bound teams operating in the EU need AI prompting rules. GDPR mandates that private info is not transferred to AI systems without a lawful basis and right safeguards. ISO 27001 needs logged policies for record handling, including AI tool usage. NIS2 introduces additional needs for cybersecurity risk control that extend to AI system interactions. Microsoft Purview provides the technical layer for enforcing prompting policies. This works through trust level labels, DLP rules, and audit logging linked with Microsoft 365. Teams that set up audit-fit AI prompting standards reduce audit risk and show rule-set maturity. They also let AI adoption without exposing touchy or private data to outside model vendors. **When this is the right fit:** AI prompting rules is the correct starting point when an team is already using or planning to introduce AI tools — such as Microsoft Copilot, ChatGPT Firm-wide, or similar. The team has not yet defined which data categories may be entered into those tools, which tools are approved for which use cases, or how usage is monitored and audited. It is in part relevant for teams in legal, HR, finance, and client-facing roles where private or private data is routinely handled. **What this doesn't replace:** Prompting rules defines policies and trains users. It does not replace technical data loss prevention controls, ID and access control setup, or AI link-up design. A prompting policy alone cannot prevent a determined user from entering restricted data. It needs DLP rules, trust level label enforcement, and access controls configured at the platform level. For technical enforcement, see the GDPR-Audit-fit AI Link-ups page. Fit & Limitations. #### Best fit and known limitations ##### Best for Teams already using ChatGPT, Claude, or Copilot. They need policies, guardrails, prompt logging, and data labeling to make daily use defensibly audit-fit with GDPR and ISO 27001. ##### Not the right fit Greenfield AI build-out without existing usage (engage [AI Rollout](solutions-ai.html) rather); air-gapped or sovereign workloads (use the [localLLM](project-localllm.html) project). ##### Known limitations Cloud LLMs cannot be made fully sovereign by policy alone. High-trust level data still perks from on-prem inference. Guardrail value scales with the discipline of training, review, and policy enforcement after rollout. #### Need AI prompting governance? Book a session to assess your now AI usage and set up audit-fit policies. [Book Assessment](contact.html) [AI Link-ups →](solutions-ai-integrations.html) --- ## GDPR-Compliant AI Integrations | curta.solutions URL: https://curta.solutions/solutions-ai-integrations.html > AI privacy shield patterns, reversible anonymization, and audit-ready AI workflows for GDPR-compliant enterprise integrations. Solutions • Privacy Engineering ### GDPR-Compliant AI Integrations Integrate AI into your workflows without exposing private inputs to the model. Privacy shielding patterns for rule-bound setups. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026 Core Concept #### AI Privacy Shield Pattern You can integrate AI into your workflows **without exposing private inputs to the model**. The pattern is to introduce a privacy layer that anonymizes signals and controls restoration. The core insight is that most AI tasks — summarizing, classifying, extracting structure, drafting responses — do not need the model to know the actual ID of the people involved. Replace names, IDs, and touchy values with deterministic pseudonymous tokens before the API call. This achieves the same biz result while keeping private records within the team's control. ##### How it works - **Pre-processing:** Detect and anonymize PII before sending to AI. - **AI call:** Send only minimized, tokenized context. - **Post-processing:** Optional tight restoration for authorized roles. Deterministic tokens — where the same input value always produces the same token — allows the AI output to reference the token consistently. Authorized roles can then perform a tight restoration pass that maps tokens back to real values. The workflow result is fully usable and attributable. The AI model itself never processes private records. Full audit logging at each stage provides the traceability needed for GDPR processing records and ISO 27001 access control proof. What We Build #### Implementation Components ##### AI Privacy Shield Pattern - PII finding and PII strip. - Deterministic tokens. - Reversible PII strip for authorized users. ##### Audit-Ready AI Workflow - Full logging. - Approval workflows. - Keep policies. - Separation of duties. ##### EU Data Residency - Secure hosting patterns. - Data sovereignty audit fit. - Regional processing options. Use Cases #### When Clients Use This ##### Legal Review Workflows Contract study and document review with AI assistance while protecting client privacy. ##### HR Support Processes Employee inquiries and docs with AI while protecting private employee records. ##### Finance Automation Invoice processing and financial study with AI while protecting touchy financial records. ##### Customer Support Knowledge work and client inquiries in rule-bound markets with data safety. Technical Foundation #### Why This Architecture Works The AI Privacy Shield pattern solves a specific problem. Rule-bound teams need AI productivity gains without accepting the sovereignty and privacy risks of sending private or private info to outside AI models. By introducing a deterministic PII strip layer between in-house systems and the AI API, teams retain control over what the model processes. Reversible PII strip — where authorized roles can restore first values from pseudonymous tokens — lets AI-assisted workflows in legal review, HR, finance, and client support without compromising privacy obligations. Full audit logging records every PII strip event, every AI call, and every restoration for audit fit reporting. EU residency options ensure processing remains within jurisdictional boundaries throughout the entire pipeline. **When this is the right fit:** GDPR-audit-fit AI link-up design is the right approach when an team wants to connect in-house biz data — such as contract repositories, HR records, or client correspondence — to an AI model for processing. Private or private data must not leave the team unprotected. It is most valuable in legal, HR, finance, and rule-bound client-support setups. These contexts have strict data safety obligations and need audit readiness. **What this doesn't replace:** The AI Privacy Shield pattern is an design and link-up pattern. It is not a substitute for organizational AI usage policies, user training, or data labeling rules. It addresses the technical data flow — PII strip, tokens, and logging. The rules layer must be set up separately. That layer defines which data categories may enter which AI workflows, and who has body to restore anonymized values. Prompting policies and data labeling taxonomies are addressed under the GDPR-Audit-fit AI Prompting solution. Fit & Limitations #### Best fit and known limitations ##### Best for Engineering teams wiring AI into existing pipelines. They need privacy-shield patterns, reversible PII strip, and audit-ready logs around every model call. ##### Not the right fit One-off prototypes without audit fit scope. Teams happy to send raw data to a cloud LLM without intermediation. Workloads that already run inside a sovereign perimeter (use [localLLM](project-localllm.html)). ##### Known limitations The privacy-shield pattern introduces latency overhead and ops depth. Reversibility implies key holding. The key itself becomes a audit fit asset to manage with the same rigour as the underlying data. #### Need GDPR-compliant AI integration? Book a session to discuss your AI link-up needs and privacy constraints. [Book Call](contact.html) [← AI Prompting](solutions-ai-prompting.html) --- ## AI in Existing Systems | curta.solutions URL: https://curta.solutions/solutions-ai-systems.html > AI implementation in ERP, Microsoft 365, and workflow systems with identity, DLP, and SIEM integration. Solutions. ### AI Implementation in Current Systems Integrate AI skills into your existing ERP, Microsoft 365, and workflow setups with proper safety controls. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. Rollout Layers. #### Where AI Integrates ##### M365 Layer Teams, SharePoint, Outlook process augmentation with Copilot and custom AI link-ups. AI skills slot into the existing Microsoft 365 rules boundary — trust level labels, DLP policies, and Entra ID access controls already in place continue to apply, ensuring AI adoption does not create new data safety exposure. Teams. SharePoint. Outlook. ##### ERP Layer Biz Central process assistance, sign-offs, and reporting enhancements with AI support. AI-assisted sign-offs operate within defined role-based approval chains, so that AI recommendations are advisory inputs to human decision-makers rather than autonomous actions, preserving the audit trail and checks needed for finance and procurement processes. Biz Central. Dynamics 365. ##### Workflow Layer Power Auto-run orchestration with AI-powered decision points and link-ups. Power Auto-run. AI Builder. ##### Security Layer ID, DLP, logging, and SIEM tracking for all AI interactions. ID. DLP. SIEM. Use Cases. #### Example Implementations Finance. ##### Compliance-Focused Finance Automation Finance auto-work tools built with auditors involved from the start. AI-assisted sign-offs, anomaly finding, and reporting with full audit trails. Role-based, logged approval workflows ensure that every decision has a named approver and a timestamp ready for an audit. Anomaly finding flags unusual deals for human review rather than blocking them auto, maintaining right human-in-the-loop oversight for rule-bound finance processes. HR. ##### HR Process Digitization PowerApps-based HR processes with Azure link-up. AI-assisted employee inquiries and document generation with privacy controls. ID link-up ensures that AI-assisted HR workflows respect role-based access controls — managers see their team's data, employees see their own records, and HR administrators operate within defined permission boundaries. Trust level labels protect personally identifiable info throughout document generation and storage. Teamwork. ##### Large-Scale Collaboration with Audit Trails Virtual Data Rooms with AI-powered search, labeling, and access control. Full audit trails for all interactions. AI-powered search surfaces relevant docs without granting broader access than the user's permission level allows, and the system logs every search query, document view, and download for audit fit reporting. Auto-run expiry rules revoke outside parties' access when a deal or project concludes. Rollout Approach. #### Governance-First AI Integration Every AI link-up into existing systems follows a set methodology: rules policies land before rollout, Microsoft Purview holds the data loss prevention controls, and ID and access control connects from the start. Trust level labels ensure AI tools operate within defined boundaries across Teams, SharePoint, and Outlook. The platform logs all AI interactions for audit purposes, with SIEM tracking providing real-time oversight across the entire setup. This approach ensures AI skills boost ops efficiency in Microsoft 365, ERP, and workflow setups without introducing new audit fit or data safety risks. Teams in rule-bound industries perk from full audit trails, role-based access controls, and audit fit fit with GDPR, ISO 27001, and NIS2 needs throughout the AI link-up lifecycle. **When this is the right fit:** AI link-up into existing systems is the correct approach when an team already operates Microsoft 365, Dynamics 365 Biz Central, or Power Platform and wants to add AI-powered decision support, auto-work, or knowledge retrieval without replacing those systems. It is in part suitable when the requirement is to boost existing finance, HR, or teamwork workflows with AI skills while maintaining the rules controls — DLP, ID, trust level labels, SIEM — already in place. **What this doesn't replace:** Integrating AI into existing systems does not eliminate the need for prompting rules policies, user training, or data labeling standards — those must be set up separately and are addressed under the GDPR-Audit-fit AI Prompting and AI Link-ups solutions. Also, this work focuses on setup, design, and rules docs; it does not cover end-user support, ongoing system administration, or run service ops post-rollout. Fit & Limitations. #### Best fit and known limitations ##### Best for Organisations embedding AI inside ERP, Microsoft 365, or workflow systems with ID, DLP, and SIEM hooks already in place. ##### Not the right fit Standalone consumer AI features; teams that lack a system of record to integrate against; setups that need an air-gapped local model (see [localLLM](project-localllm.html)). ##### Known limitations Link-up depth is bounded by the underlying system's APIs and licenses; some legacy ERPs need middle-tier or RPA before AI features become real; rollout cadence depends on the partner ecosystem around the source system. #### Want to add AI to your existing systems? Book a call to explore link-up chances in your now setup. [Book Call](contact.html) [← AI Rollout](solutions-ai.html) --- ## Predictions, LLMs & Machine Learning | curta.solutions URL: https://curta.solutions/solutions-ml.html > Company-specific LLMs, predictive systems, and machine learning with governance-first approach for regulated organizations. Solutions • Advanced AI. ### Predictions, Company-Specific LLMs & Machine Learning Governed, secure AI systems that work with your info while maintaining audit fit and auditability. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. What We Mean. #### Company-Specific AI - **Your knowledge accessible** — Docs, policies, steps become searchable through tight retrieval. - **Your data stays governed** — Labeling, keep, and access control maintained. - **Outputs are audit-fit** — All AI interactions logged and traceable. - **Matched with risk posture** — Controls match your team's risk tolerance. The split between a stock public AI and a firm-grade system is not just about input privacy. It is about fit and trust. A stock model gives broad answers. A firm-grade system gives answers tied to your real steps, vendor base, asset setups, and ops past. For rule-bound teams, that fit also means outputs can be traced to a known, audit-fit source. The source takes the place of a black-box training set. Use Case A. #### Predictive Systems for Energy Infrastructure We design prediction systems that reduce unplanned downtime. They forecast failures and find early risk signals. This lets ahead-of-time upkeep and smarter spare-part planning. ##### Typical Inputs - Asset telemetry / sensor signals (SCADA, tracking, logs) - Weather and eco signals. - Upkeep history + work orders. - Quality and service KPIs (failures, MTTR, response times) ##### Typical Outputs - Failure probability and time-to-failure estimates. - Upkeep recommendations and prioritized work orders. - Outage risk predictions and "where to look first" guidance. - Explainable dashboards for ops, engineering, and control. ##### Project Deliverables - Data readiness assessment (quality, completeness, safety) - Model starting point + review plan (accuracy, false positives, biz impact) - MLOps plan: tracking, drift finding, retraining cadence. - Ops link-up: alerts, dashboards, ticket auto-work. ##### Business Impact - Reduced unplanned downtime. - Optimized spare-part planning. - Ahead-of-time upkeep scheduling. - Proof-based resource allocation. Use Case B. #### Company-Internal LLMs + Procurement Predictions A tight in-house assistant that answers "how do we do X?" from policies and docs. It can also support procurement with proof-based insights (demand signals, supplier risk, purchase planning). ##### Two-Layer Architecture - **Knowledge Layer (RAG)** — for unstructured docs (steps, PDFs, contracts, e-mails) - **Prediction Layer (ML)** — for forecasting (demand, lead times, risk signals) where set data exists. ##### Knowledge Layer Deliverables - Data labeling and access model (who can see what, by default) - Knowledge ingestion pipeline (ownership, update cadence, audit trail) - Prompt + output standards (format, citations, escalation rules) ##### Prediction Layer Deliverables - Feature engineering from historical signals. - Forecasting model plan (features, review, ops KPIs) - Link-up with procurement workflows. Experience. #### What We've Built [ ##### Predictive Maintenance for Solar Parks ML-based predictive upkeep system developed in a research cooperation (2020). Pattern finding and failure forecasting for asset ops. Case Study. Machine Learning. Research. View Case Study →. ](case-study-predictive-maintenance.html) ##### AI-Supported Decision Models Decision support systems for engineering decision-making with explainable AI outputs and audit trails. Decision Support. Engineering. Explainable AI. Methodology. #### Governance-First ML/LLM Approach ##### Data Minimization GDPR-matched data handling with purpose limitation. Only needed data used for model training and inference. ##### Model & Prompt Risk Controls Risk assessment for model selection, prompt engineering guardrails, and output checks. ##### Logging & Monitoring Full logging of all AI interactions, speed tracking, and anomaly finding. ##### Clear Responsibility RACI matrix for AI ops, incident response steps, and escalation paths. **When this is the right fit:** Firm-grade LLMs and forecast ML fit when a team has built up set ops data. Sensor logs. Upkeep history. Buying records. Deal logs. The goal is to move from look-back reports to ahead-of-time data-driven calls. They also fit when teams spend big time searching in-house docs, steps, or rules. A tight in-house knowledge bot cuts that load. Data rules stay in force. **What this doesn't replace:** Forecast ML and in-house LLMs do not replace the team's source data quality work. Nor master data control. Nor ops steps. A model is only as good as the data it learns from. Poor, partial, or odd past data will cap forecast skill, no matter how slick the model. So a data-readiness check is a must-have, not an option. This work covers model design, build-out, and rules. Day-to-day MLOps, model hosting, and live support are split ops duties. #### Interested in predictive AI or custom LLMs? Book a call to explore how AI can work with your specific data and needs. [Book Call](contact.html) [← AI Rollout](solutions-ai.html) --- ## NIS2 Compliance Roadmap for German Mittelstand | curta.solutions URL: https://curta.solutions/solutions-nis2-compliance.html > NIS2 compliance roadmap for German Mittelstand. Scope, deadlines, ISO 27001 mapping, technical controls. Practical implementation, not consulting fluff. Solutions. ### NIS2 Compliance for German Mittelstand — Practical Implementation By [George Curta](about.html) · Founder, curta.solutions · Updated May 24, 2026. NIS2 transposed into German law as the NIS2UmsuCG. If your company is in scope, the obligations are concrete and dated. This page lays out who is affected and the deadlines. It also shows how to map your existing ISO 27001 controls to the new needs without rebuilding from scratch. Scope. #### What is NIS2 and which companies are in scope? NIS2 (Directive (EU) 2022/2555) applies to companies in 18 sectors considered "key" or "important" with at least 50 employees and EUR 10M turnover. The German transposition is the NIS2UmsuCG. It incorporates the EU directive into Federal IT Safety Law. The "key" category covers energy, transport, banking, financial market systems, health, drinking water, waste water, digital systems, ICT service control, public administration, and space. The "important" category adds postal and courier services, waste control, manufacturing of chemicals, food live, manufacturing of medical devices and machinery, digital vendors, and research organisations. Companies determine in-scope status themselves — there is no central list issued by BSI. The thresholds are headcount and turnover. Smaller items can still be designated by member states if they are sole vendors of a critical service. Companies that are unsure should run a self-labeling against the sector list in Annex I and Annex II of the directive. Group structures matter: the assessment usually applies at the legal-item level, not at the merged group level. A holding company is rarely in scope on its own, but operating subsidiaries in key sectors typically are. Timeline. #### When is the NIS2 deadline in Germany? Member states had to transpose NIS2 by 17 October 2024. The German NIS2UmsuCG entered into force in 2025. Companies in scope must list with BSI within 3 months of becoming an in-scope operator. They must also meet the technical and organisational measures listed in §30. Listing with BSI is a formal one-time step. It records the company as an in-scope operator, names a designated contact for safety incidents, and confirms the sector labeling. The 3-month clock starts when the company first meets the size and sector criteria, not when the law enters into force. Incident reporting is on a tight schedule. The deployer must issue an early warning within 24 hours of becoming aware of a big incident, a formal incident notification within 72 hours, and a final report within one month. The reporting channel is the BSI MIRP portal. Failure to report can trigger administrative fines up to EUR 10M or 2% of global turnover for "key" items. Control liability is explicit under NIS2: governing bodies must approve cybersecurity risk-control measures, oversee their rollout, and undergo regular training. Private liability for non-audit fit is one of the bigger changes versus the old IT-SiG. Control Mapping. #### How do I map our current ISO 27001 controls to NIS2 obligations? NIS2 Article 21 lists 10 technical/organisational measure areas. Most map directly to ISO 27001:2022 Annex A controls (incident handling → A.5.24-A.5.30, supply-chain safety → A.5.19-A.5.23, biz continuity → A.5.29-A.5.30, access control → A.5.15-A.5.18, etc.). A cross-walk document is the fastest way to proof coverage. The 10 Article 21 areas in short. Risk study and info system safety policies. Incident handling. Biz continuity and crisis control. Supply chain safety. Safety in network and info systems acquisition and dev work. Policies to assess the value of cybersecurity risk-control measures. Basic cyber hygiene practices and cybersecurity training. Cryptography policies. Human resources safety and access control. Use of multi-factor sign-in and secured comms. An ISO 27001:2022-certified ISMS already satisfies the vast majority of these. The gaps that typically remain are the formal supply-chain risk procedure, the 24/72-hour incident-reporting playbook, and explicit board-level oversight proof. These can be added without rebuilding the ISMS. They fit as new clauses in the Statement of Applicability and as new steps in the existing document hierarchy. For companies without ISO 27001, the BSI IT-Grundschutz starting point is an alternative reference framework that German regulators accept. It covers the same ground with German-language artefacts and a step-by-step rollout path. Buy-in. #### How does curta.solutions help with NIS2 compliance? curta.solutions runs ISO 27001 ISMS prep engagements (see case study) and produces the NIS2 cross-walk as a output. The buy-in covers gap study, control rollout, BSI listing support, and incident-reporting playbooks. A typical buy-in starts with a 2-week gap study against Article 21 and the 10 measure areas. The gap is mapped against any existing ISO 27001 or IT-Grundschutz docs. The output is a concrete control list with owners, deadlines, and proof needs. Rollout runs in 6-to-12-week sprints depending on the size of the gap. Outputs include the BSI listing package and the Article 21 cross-walk. The pack also covers the 24/72-hour incident-reporting playbook with named on-call roles, the supply-chain risk procedure, the board cybersecurity briefing pack, and the Article 4 AI literacy training material where AI is in use. The buy-in is designed for the German Mittelstand. Pragmatic outputs, docs in German where the regulator needs it, fixed scope and fixed price per sprint. It backs audit fit. The final checks sits with the company's governing body, which is what the directive needs. Trade-offs. #### Best fit and known limitations ##### Best fit German Mittelstand items in NIS2 "key" or "important" sectors. They already have some ISO 27001 or IT-Grundschutz groundwork and need to close the Article 21 gap on a fixed timeline. ##### Less suitable Pure consulting decks with no rollout work, or companies looking for a "audit fit certificate". NIS2 is not certified. It is enforced by BSI through audits and incident-reporting checks. ##### Known limitations Designed for audit fit support, not legal advice. Statutory interpretation of the NIS2UmsuCG remains the duty of the company and its legal counsel. Related Solutions. #### Adjacent Engagements [ ##### ISO 27001 / ISMS Preparation The reference buy-in for ISMS design, docs, and audit readiness that underpins NIS2 cross-walks. Learn more →. ](case-study-iso27001-isms.html) [ ##### Services Overview ITILv4-matched service catalogue covering safety, rules, and ongoing gains. Learn more →. ](services.html) [ ##### GDPR-Compliant AI Prompting Prompt policies and guardrails for safe AI use — backs the Article 4 AI literacy obligation. Learn more →. ](solutions-ai-prompting.html) #### Ready to scope your NIS2 gap? Book a call to walk through your sector labeling, now control set, and a fixed-price path to BSI listing. [Book a Call](contact.html) [View Experience](experience.html) --- ## EU AI Act Compliance — August 2026 Roadmap | curta.solutions URL: https://curta.solutions/solutions-eu-ai-act.html > EU AI Act compliance for August 2026. Who is in scope, what to do, how to use ChatGPT and Copilot in a German company without breaking Article 13 or 14. Solutions. ### EU AI Act Obligations from August 2026 — What Your Company Must Do By [George Curta](about.html) · Founder, curta.solutions · Updated May 24, 2026. The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024 with a staggered timeline. The clauses your company must comply with depend on two factors. The first is your role: provider, deployer, importer, or distributor. The second is the risk category of the AI system you operate. This page lays out the deadlines and obligations. It also covers the practical steps for keeping ChatGPT, Copilot, and other LLM tools in compliant use inside a German organisation. Operator Roles. #### Who is in scope: provider, deployer, importer, distributor? The EU AI Act distinguishes four operator roles: provider (placing on the EU market), deployer (using under own authority), importer, and distributor. Most German companies using ChatGPT or Copilot are deployers. This role has the lightest set of obligations. It still requires transparency (Art 50), risk awareness, and AI literacy training (Art 4). A provider is whoever develops an AI system, or has one developed, and places it on the EU market under their own name. Examples are OpenAI, Anthropic, Google, Microsoft, and Mistral. A deployer is any natural or legal person who uses an AI system under its own authority in a professional activity. Private, non-professional use is excluded. The role can shift. A deployer that fine-tunes a model, rebrands it, or substantially modifies a high-risk system can become a provider under Article 25. This is the typical trap for companies building custom Copilot agents or RAG systems on top of an off-the-shelf LLM. The risk classification (limited / high-risk / prohibited / general-purpose AI) applies on top of the role. It determines the bulk of the obligations. Importer and distributor roles apply mostly to AI systems sold as physical or embedded products. For pure software-as-a-service LLM use, the deployer role is what matters in practice. Timeline. #### When does each obligation start? The timeline has four key dates. Prohibitions and AI literacy apply from 2 February 2025. General-purpose AI obligations apply from 2 August 2025. The bulk of high-risk system obligations, including providers and deployers of Annex III systems, apply from 2 August 2026. High-risk systems embedded in regulated products apply from 2 August 2027. The 2 February 2025 milestone is already in force. Art. 5 prohibitions (social scoring, untargeted facial-recognition scraping, emotion recognition in workplaces and schools, etc.) apply now. Art. 4 AI literacy applies to all providers and deployers regardless of risk class — not optional, not deferred. The 2 August 2025 milestone added obligations for general-purpose AI models. This is where the upstream providers (OpenAI, Anthropic, etc.) have to publish training-data summaries, copyright compliance policies, and technical documentation. Deployers benefit indirectly but acquire no new direct obligation on that date. The 2 August 2026 milestone is the heavy one for deployers. It brings full applicability of high-risk-system rules in Annex III. This includes Art. 13 (transparency to deployers), Art. 14 (human oversight), and Art. 26 (deployer obligations such as record-keeping, monitoring, and DPIA where required under GDPR). It also requires EU database registration for high-risk systems. Article 13/14. #### How do I anonymise data before sending it to a cloud LLM under Article 13 or 14? To comply with Article 13 (transparency to deployers) and Article 14 (human oversight), the deployer must know what personal data is in the prompt before it leaves the perimeter. The practical way to satisfy this is a deterministic PII scrubber running between user and LLM. This is what curta.solutions' anonymize.dev, anonym.legal, and anonymize.today MCP servers do for Claude Desktop, Cursor, and OpenAI-compatible clients. The scrubber operates locally. It identifies entities (names, addresses, financials, identifiers, credentials, health data), replaces them with deterministic pseudonyms, sends the cleaned prompt to the cloud LLM, and reverses the pseudonymisation on the response. The original PII never leaves the company perimeter. This simultaneously addresses GDPR Article 5(1)(c) data minimisation. For Article 14 human oversight, the scrubber provides a deterministic audit trail. Every prompt is logged with its entity replacements before transmission. A human reviewer can verify what was sent. This is the kind of evidence the deployer needs for Article 26 record-keeping. It also supports the eventual DPIA under GDPR Article 35 where a high-risk AI system processes personal data. The MCP server form factor matters. It plugs into Claude Desktop, Cursor, and OpenAI-compatible clients without changing user workflows. Adoption costs are low and the compliance layer is consistent across tools. Cloud LLM Use. #### Can I keep using ChatGPT in a German company? Yes. ChatGPT can be used in a German company if the deployer meets four conditions. Apply privacy-by-design (data minimisation through anonymisation). Keep a record of high-risk uses under Article 26. Run the AI literacy training required by Article 4. Document the EU AI Act risk classification of every productive use case. For fully sovereign use cases, the localLLM engagement keeps the model on-premises and skips most EU AI Act risk classification for ad-hoc LLM use. A compliant ChatGPT deployment in a German company has five components. The first is an enterprise subscription (no training on customer data). The second is SSO and DLP integration. The third is a PII scrubber for prompts that may contain personal data. The fourth is a written AI use policy mapped to Article 4 and Article 26. The fifth is a register of productive use cases with their risk classification. The same pattern works for Microsoft 365 Copilot. The contractual baseline is already strong (no training, EU Data Boundary, customer-managed keys). Article 4 AI literacy and Article 26 deployer records are still required. The grounding data does not exempt the deployer from the documentation duty. For use cases where cloud is unsuitable — sovereign data, classified work, or air-gapped environments — localLLM provides an on-premises alternative. The model runs on the company's own hardware. Outbound traffic is physically blocked. This removes most of the Article 13/14 cross-border transparency questions because the system never leaves the perimeter. Tool Mapping. #### What curta.solutions tools help with EU AI Act compliance? Three curta.solutions products map directly to EU AI Act obligations. The first set is anonymize.dev, anonym.legal, and anonymize.today (Article 13-14 PII protection layer). The second is localLLM (sovereign on-premises model for cases that cannot use cloud LLMs). The third is the AI Implementation engagement (Article 4 AI literacy programme + Article 26 deployer documentation). anonymize.dev targets developer workflows — credentials, API keys, customer data in code and prompts — via MCP for Claude Desktop and Cursor. anonym.legal targets regulated text (legal, healthcare, financial) with 285+ entity types and 48 languages. anonymize.today is the simpler regex-based option for general office use. All three are deterministic, ISO 27001-certified servers in Germany, and reversible. localLLM is the engagement for sovereign use cases. It includes a codebase scanner, an OpenAI-compatible gateway with a 54-family model catalog, a plan-then-execute agentic orchestrator, and an MCP server with 38 tools. Air-gapped on-premises operation with zero cloud dependency. Designed for organisations where Article 13/14 transparency to a third-party LLM provider is not workable. The AI Implementation engagement is where the Article 4 AI literacy programme and the Article 26 deployer documentation come together. Deliverables include a written AI use policy, a risk-classified register of productive use cases, role-specific literacy training, and a quarterly review cadence. Trade-offs. #### Best fit and known limitations ##### Best fit German and EU companies running ChatGPT, Copilot, or Claude in productive workflows. They need an Article 4 / 13 / 14 / 26 compliance layer before 2 August 2026, plus a sovereign fallback for sensitive use cases. ##### Less suitable Pure providers building foundation models. This engagement is designed for deployers. Provider obligations under Title III require a different stack, including conformity assessments and EU database registration. ##### Known limitations The page is informational and the engagement supports compliance. The final risk classification and accountability under Article 26 sits with the deployer's governing body. Legal interpretation remains with company counsel. Related Solutions. #### Adjacent Engagements [ ##### GDPR-Compliant AI Prompting Prompt policies, guardrails, and AI literacy training material that doubles as Article 4 evidence. Learn more →. ](solutions-ai-prompting.html) [ ##### localLLM Sovereign on-premises LLM platform for sensitive use cases where cloud transparency is not workable. Learn more →. ](project-localllm.html) [ ##### anonymize.dev Privacy-as-Code MCP server for developer AI tools — the practical Article 13/14 PII protection layer. Learn more →. ](project-anonymize-dev.html) #### Ready to map your EU AI Act exposure? Book a consultation to walk through your operator role and your productive use cases. We will draft a fixed-price plan to be ready for 2 August 2026. [Book a Consultation](contact.html) [View Experience](experience.html) --- ## How curta.solutions Compares: Presidio, Skyflow, Piiano | curta.solutions URL: https://curta.solutions/solutions-vs-competitors.html > Comparison: curta.solutions vs Microsoft Presidio, Skyflow, Piiano, AWS Comprehend. Where we differ on EU residency, MCP support, and deployment model. Solutions ### How curta.solutions Compares: Presidio, Skyflow, Piiano, AWS Comprehend Each comparison below is one specific axis with a citation. Where a competitor's current number cannot be verified from a public reference as of May 2026, the cell is marked UNVERIFIED. Do not take this page as a vendor decision document — take it as a starting point for your own scorecard. Open-Source Upstream #### vs Microsoft Presidio (open-source upstream) Presidio is the open-source PII engine that several curta.solutions products are built on; the difference is what is wrapped around it. Axis Microsoft Presidio curta.solutions Pricing. Free, MIT licence (Ref: https://microsoft.github.io/presidio/). Free tiers on all 13 products; paid tiers from €3/mo (see [pricing](pricing.html)). Deployment model. Self-hosted library + container; you operate it (Ref: https://microsoft.github.io/presidio/). SaaS (ISO 27001 servers in Germany), Managed Private, Self-Managed (see [anonymize.solutions](project-anonymize-solutions.html)). Entity types out of the box. ~20 built-in recognisers, extensible (Ref: https://microsoft.github.io/presidio/supported_entities/). 50–390+ depending on product (see project pages: anonymize.dev 50+, anonymize.today 256, cloak.business 320+, anonym.life 390+). Language coverage. Depends on configured spaCy/transformers models; English first-class (Source: https://microsoft.github.io/presidio/analyzer/languages/). 27–67 languages depending on product, RTL on anonym.legal and anonymize.solutions. MCP Server. Not provided in upstream Presidio (Source: https://microsoft.github.io/presidio/ as of 2026-05). Shipped on anonymize.dev, anonym.legal, anonymize.today, cloak.business, anonymize.education. Enterprise features (Zero-Knowledge auth, Bates numbering, audit chain). Not in scope of upstream; user implements (Source: https://microsoft.github.io/presidio/). Zero-Knowledge on anonym.legal and anonym.life; Bates numbering on anonym.legal; tamper-evident audit log on anonymize.solutions. US Data Privacy Vault #### vs Skyflow (US data privacy vault) Skyflow positions as a managed data privacy vault for US enterprises; the comparison is about EU data residency, deployment model, and PII detection scope. Axis Skyflow curta.solutions HQ / data residency. US-headquartered; multi-region cloud presence advertised (Source: https://www.skyflow.com/data-privacy-vault as of 2026-05). Germany; ISO 27001-certified German servers; EU-only residency by default. Deployment model. Managed SaaS data privacy vault (Source: https://www.skyflow.com/data-privacy-vault as of 2026-05). SaaS, Managed Private (single-tenant in EU), Self-Managed inside customer perimeter. Vault vs detection engine. Vault + tokenisation primary; detection is part of the vault flow (Source: https://www.skyflow.com/data-privacy-vault as of 2026-05). Detection-engine-first; pseudonymisation is reversible inside the customer perimeter, no vault dependency. EU/DACH presence. UNVERIFIED — check Skyflow's current EU region availability and DPA terms. Native; German-language sales, contracts in German law, EU Data Boundary by default. MCP Server. UNVERIFIED — check Skyflow's current docs for an MCP Server endpoint (Source: https://www.skyflow.com/data-privacy-vault as of 2026-05). Shipped on multiple products for Claude Desktop, Cursor, VS Code (Continue, Cline), Windsurf. Compliance certifications. SOC 2, HIPAA, PCI per public marketing site as of 2026-05 (Source: https://www.skyflow.com/security as of 2026-05). ISO 27001 (German servers), GDPR-aligned by design; sector add-ons (FERPA, HIPAA, PCI-DSS) on relevant products. Open-Source Token Vault #### vs Piiano (open-source token vault) Piiano ships an open-source PII vault and a SaaS layer; the comparison is about integration model and managed-service depth. Axis Piiano curta.solutions Deployment. Open-source vault you self-host; SaaS layer for managed (Source: https://www.piiano.com/ as of 2026-05). SaaS (Germany), Managed Private, Self-Managed; per-product, not single-product. License. Open-source vault per public marketing site as of 2026-05 (Source: https://www.piiano.com/ as of 2026-05); specific licence UNVERIFIED — check current repo. Proprietary SaaS + on-premises licence; product-specific. Built on the open-source Microsoft Presidio engine for some products. Entity types. UNVERIFIED — check Piiano's current docs for the entity-type list (Source: https://www.piiano.com/ as of 2026-05). 50–390+ depending on product (verifiable on each project-*.html page). MCP Server. UNVERIFIED — check Piiano's current docs (Source: https://www.piiano.com/ as of 2026-05). Shipped on anonymize.dev, anonym.legal, anonymize.today, cloak.business, anonymize.education. Enterprise certifications. UNVERIFIED — check Piiano's current trust/security page (Source: https://www.piiano.com/ as of 2026-05). ISO 27001-certified German hosting on managed products. Managed NLP API #### vs AWS Comprehend (managed NLP API) AWS Comprehend is a managed NLP API with a PII detection feature; the comparison is data residency, scope, and whether you can run it without sending data to AWS. Axis AWS Comprehend curta.solutions Deployment. Managed AWS-region service; data passes through AWS (Source: https://aws.amazon.com/comprehend/ as of 2026-05). SaaS in Germany, Managed Private in customer's chosen region, Self-Managed on-premises (incl. air-gapped via anonym.plus). EU data residency. Available via EU regions per public marketing site as of 2026-05 (Source: https://aws.amazon.com/comprehend/ as of 2026-05); contractual exposure under US CLOUD Act remains. EU-only by default; no US-jurisdiction parent company. Entity types. Documented PII entity set in Comprehend Detect PII feature (Source: https://docs.aws.amazon.com/comprehend/latest/dg/how-pii.html as of 2026-05); exact current count UNVERIFIED at time of writing — check AWS docs. 50–390+ depending on product. Language coverage. Comprehend Detect PII supports a documented subset of languages (Source: https://docs.aws.amazon.com/comprehend/latest/dg/how-pii.html as of 2026-05); exact current list UNVERIFIED — check AWS docs. 27–67 depending on product, with RTL on enterprise tiers. MCP Server. Not provided as a first-class endpoint (Source: https://aws.amazon.com/comprehend/ as of 2026-05). Shipped on multiple products for Claude Desktop, Cursor, VS Code (Continue, Cline), Windsurf. FAQ #### Frequently asked questions ##### Why didn't you compare against Privitar? Privitar was acquired by Informatica in 2023; the product line continues under Informatica branding and a like-for-like comparison would require a current Informatica reference. ##### What about DataGuard or Eperi for DACH? DataGuard sells privacy management governance (DPIA, GDPR documentation); Eperi sells cloud-data encryption; neither targets the same PII-anonymisation-for-AI use case as curta.solutions, so they are not in this comparison. ##### Why does curta.solutions emphasise MCP Server support? Most curta tools ship with MCP Server endpoints so they can plug directly into Claude Desktop, Cursor, VS Code (Continue, Cline) and Windsurf without a custom integration; this is uncommon in the comparable vendor set as of May 2026. ##### Do you have a vendor-scorecard template? Yes; reach out via the contact form and we can send a blank scorecard you can fill in across vendors of your choice, not just the ones on this page. Related Solutions #### See the underlying products [ ##### anonymize.solutions Enterprise PII platform: SaaS, Managed Private, Self-Managed. 320+ entity types, 48 languages, air-gapped option. Learn more → ](project-anonymize-solutions.html) [ ##### anonym.legal Regulated-text anonymisation: 285+ entities, 48 languages with RTL, Zero-Knowledge auth, MCP Server. Learn more → ](project-anonym-legal.html) [ ##### Pricing Free tiers and paid plans across the 13-product family, plus the three consulting engagement bands. Learn more → ](pricing.html) #### Need a scorecard for your own evaluation? Send a note via the contact form and we'll share a blank scorecard template you can fill in across vendors of your choice. [Request Scorecard](contact.html) [See Pricing](pricing.html) --- ## Pricing — Tools and Engagements | curta.solutions URL: https://curta.solutions/pricing.html > Pricing for the 13-product family (free tiers + paid tiers) and consulting engagements. Discovery, implementation, custom AI engagement tiers. Pricing. ### Pricing — Tools and Engagements Most of the product family has a free tier you can use without contacting anyone. Consulting engagements are scoped per project; this page lists the bands so you know what to expect before the first conversation. Product Family. #### Product family — free tiers and paid plans Every product in the 13-tool family has a free tier; paid tiers start at €0–€3/month for personal use and scale to enterprise contracts on request. Product. Free Tier. Paid Tier Start. Notes. [anonymize.today](project-anonymize-today.html). 300 tokens/month. Contact sales. Built on Microsoft Presidio. [anonym.legal](project-anonym-legal.html). 200 tokens/cycle. Basic €3/mo (1,000 tokens, 31-day cycle); Pro €15/mo; Business €29/mo. MCP Server included. [anonym.today](project-anonym-today.html). 100 tokens/month. Contact sales. Consumer privacy tool. [cloak.business](project-cloak-business.html). 200 tokens/cycle. €49/mo unlimited. Image redaction OCR. [anonymize.dev](project-anonymize-dev.html). 200 tokens/cycle. Contact sales. Developer MCP Server. [anonymize.live](project-anonymize-live.html). 100 tokens/month. Contact sales. Chrome Extension AI chat protection. [anonymize.solutions](project-anonymize-solutions.html). Demo on request. Contact sales (enterprise). SaaS / Managed Private / Self-Managed. [anonym.life](project-anonym-life.html). Demo on request. €499/mo Starter (enterprise). Privacy middleware for transaction systems. [anonym.plus](project-anonym-plus.html). Free download. No paid tier yet. 100% offline desktop. [anonymize.education](project-anonymize-education.html). Teacher: free. School: €0.05/1k chars; District: €0.04/1k chars. Per-character pricing. [piisafe.eu](project-piisafe-eu.html). 20 scans/hour, 10 pages/scan. n/a. Free website PII scanner. [gtools.pro](project-gtools-pro.html). Free for all M365 administrators. n/a. Local-first M365 admin suite. EU IT Migration Master. ChatGPT subscription required. n/a. Custom GPT in ChatGPT. Engagements. #### Consulting engagements Consulting engagements are scoped per project; rates and timelines depend on scope, control framework, and how much policy/control documentation already exists. ##### Discovery **1–2 weeks · Fixed-fee** Scoping and readiness assessment. Stakeholder interviews, current-state review of the relevant control framework (ISO 27001, NIS2, EU AI Act, GDPR, or sector-specific), and a written report with a recommended next step. Fixed-fee so both sides know what they are committing to. ##### Implementation **6–24 weeks · Time-and-materials within agreed cap** Project-based delivery: anonymisation rollout, M365 hardening, Copilot governance, NIS2 control build-out, ISO 27001 ISMS preparation, or similar. Time-and-materials inside an agreed cap, with milestone-based check-ins so scope changes get re-priced explicitly rather than absorbed silently. ##### Custom AI Engagement **16–30 weeks · Time-and-materials within agreed cap** For deeper builds: localLLM (sovereign on-premises model), LocalBrain (private knowledge graph), and SLB-style sector-specific engagements all live here. The longer band reflects integration work, evaluation cycles, and the documentation that ships with the system, not extra padding. Pricing Philosophy. #### Why we don't list everything on a public page Enterprise tiers are quoted per use case because seat count, deployment model (SaaS vs Managed Private vs Self-Managed), data residency requirements, and any white-label needs change the math materially. The products with simple personal pricing show it openly. anonym.legal at €3/€15/€29 per month, cloak.business at €49/month, anonymize.education priced per character, anonym.life Starter at €499/month — these are listed because the cost is predictable and the answer is the same whether you are a one-person shop or a 50-person team. No hidden steps. Enterprise and consulting need scoping conversations to land at a fair number for both sides. A 200-seat managed-private anonymize.solutions deployment with EU-only residency, white-label branding, and integration into an existing IdP is not the same engagement as a 5,000-seat self-hosted rollout, even though the product is the same. The same is true for a 6-week NIS2 readiness sprint versus a 24-week ISO 27001 ISMS build-out. We'd rather have a 30-minute conversation and quote a real number than publish a placeholder that misleads either side. FAQ. #### Frequently asked questions ##### Is there a discount for non-profits, schools, or research? Yes; reach out via the contact form with a short description of the use case. ##### Do you offer a trial of the enterprise tier? Yes; the standard pattern is a 14-30-day proof-of-value with sandbox data, ending in a written assessment. ##### Can I self-host anonymize.solutions? Yes; the Self-Managed tier is exactly that — you host it inside your perimeter on Hetzner-compatible infrastructure or your own cloud. ##### What is the refund policy? Cancellation effective at the end of the current billing cycle; no pro-rata refund for unused token allowances. Related. #### Next Steps [ ##### Browse the Product Family Each product page lists entity counts, language coverage, deployment model, and the free-tier signup link. Learn more →. ](projects.html) [ ##### How We Compare Head-to-head against Microsoft Presidio, Skyflow, Piiano, and AWS Comprehend with citations. Learn more →. ](solutions-vs-competitors.html) [ ##### Services Overview The ITILv4 Service Value Chain wrapping each engagement tier: strategy, governance, cloud, security, automation, training. Learn more →. ](services.html) #### Ready to scope an engagement? Book a 30-minute call to walk through your use case and get a real number back — not a placeholder. [Book a Call](contact.html) [View Experience](experience.html) --- ## Services — ITILv4 Service Value Chain | curta.solutions URL: https://curta.solutions/services.html > IT services structured around ITILv4 Service Value Chain. Strategy, governance, cloud, security, automation, and training for regulated organizations. Services — ITILv4 Service Value Chain ### Structured Service Delivery Our services map to the ITILv4 Service Value Chain. This gives clear rules and metrics. It backs steady gains from plan to ops. Demand / Opportunity Plan S-01 Strategic course, portfolio calls, and resource plans tied to business goals. IT Strategy Governance Roadmap Improve Continuous Steady gains across all services. Driven by metrics, feedback, and ops insights. KPIs Optimization Documentation Engage S-07 Buy-in, training, and rollout help for lasting use. Training Enablement Coaching Design & Transition S-03 / S-04 System design, safety checks, and tight rollout to live setups. Cloud & M365 Security Compliance Zero-Trust Obtain / Build S-05 Build, link-up, and automation work. With rules built in. Low-Code Automation ERP API Deliver & Support S-02 / S-06 Ops work, SLA control, and vendor rules. Built for lasting uptime. IT Controlling Vendor Mgmt Operations SLAs Governance Layer GDPR ISO 27001 NIS2 ITILv4 #### Plan **Close Value Delivered Service Catalog #### Detailed Service Domains S-01 • PLAN ##### IT Strategy & Governance IT roadmap design and rollout. Rules and standards for cloud, safety, and dev. Working with leads at C-level. S-02 • DELIVER ##### IT Controlling & Vendor Management SLA-based checks and vendor metrics. Clear budgets and contract data. License and cloud cost rules for Microsoft stacks. S-03 • DESIGN ##### Cloud & Microsoft 365 Services Microsoft 365 and Azure ops tuning. Intune-led endpoint control at scale. Tenant moves and PowerApps tenant swaps. S-04 • DESIGN ##### IT Security & Compliance Zero-Trust design and ISO 27001 fit. Defender XDR + Sentinel SIEM watch and response. Microsoft Purview (DLP, insider risk, audit logs) + MIP labels. Backup and disaster fall-back for M365 with restore tests. Forensics, incident playbooks, crisis drills. S-05 • OBTAIN ##### Software, Low-Code & Automation Dev team buildout and life-cycle rules (CI/CD, reviews, versions). Power Platform plan and team-wide automation. ERP plan plus Business Central roll-outs and add-ons. S-06 • DELIVER ##### IT Operations & Managed Services Global ops patterns and ops resilience. Set standards, write docs, and tune over time (ITILv4 style). S-07 • ENGAGE ##### Training, Enablement & Coaching Safety training for leads and teams. Help with tool use (M365, automation, AI use rules). AI & Prompt Workshops - Prompt Engineering Workshops (GDPR-focused)** — safe prompt patterns, data cut-down, redaction and pseudo-names, plus "prompt-to-policy" rule templates - **Copilot / Agent Enablement Workshops** — how to build, govern, and safely operate internal copilots and automation agents Training Prompt Engineering Copilot GDPR #### Need a specific service? Let's talk about how we can help with your IT plan, safety, or automation needs. [Book a Consultation](contact.html) [See Our Approach](approach.html) --- ## Experience — Project Examples | curta.solutions URL: https://curta.solutions/experience.html > Anonymized project examples: global endpoint management, Zero-Trust security, data rooms, ERP integrations, and private cloud solutions. Experience ### Proof of Delivery Anonymized project examples from firm-wide rollouts. Client identities protected under NDA — outcomes verified and logged. 700+ Endpoints Run Global Microsoft 365 rollout 26 Global Locations Multi-country ops 80 Virtual Data Rooms SharePoint VDRs with audit trails 5,000 Accounts Governed ID lifecycle & RBAC Case Studies #### Project Examples [ M365 • ITILv4 • 2022–Present. ##### Microsoft 365 Migration + ITILv4 + IT Controlling Led IT controlling and a full Microsoft 365 cloud move, built an in-house IT department, optimized contracts/costs, set up ITILv4 standards and safety measures. Case Study. M365 Move. ITILv4. IT Controlling. View Full Case Study →. ](case-study-m365-migration-itil4.html) Scale • Global Ops. ##### Global Endpoint & Identity Modernization Run a global Microsoft stack supporting **700+ endpoints across 26 global locations**. Implemented ID and access patterns using Azure AD controls and Conditional Access policies. M365. Intune. Azure AD. Conditional Access. [ Safety • ISO 27001 • 2024–Present. ##### ISO 27001 / ISMS Preparation ISMS prep matched to ISO 27001: safety framework design, docs of key processes, in-house assessments, and cybersecurity training for audit readiness. Case Study. ISO 27001. ISMS. Audit-Ready. View Full Case Study →. ](case-study-iso27001-isms.html) Safety • Zero-Trust. ##### Zero-Trust Security + ISO 27001-Aligned Service Management Designed and set up a **Zero-Trust strategy** and ISO 27001-audit-fit IT service control. Implemented Defender XDR and Sentinel SIEM for finding, response, and tracking. Zero-Trust. Defender XDR. Sentinel SIEM. ISO 27001. [ M365 • Safety • 2024. ##### Microsoft 365 Secure Communication Implemented encoded comms within Microsoft 365 and introduced trust level labels for data labeling and email safety, including policy rollout and training. Case Study. Trust level Labels. Encoding. M365. View Full Case Study →. ](case-study-m365-secure-communication.html) Audit fit • Data Rules. ##### Compliance-Grade Data Governance in Microsoft 365 Implemented Purview-based DLP, audit logging, and info safety with trust level labels. Built rules processes for outside tools linked via Azure AD with RBAC + lifecycle auto-work. Purview. DLP. Trust level Labels. RBAC. Teamwork • Data Rooms. ##### SharePoint Virtual Data Rooms at Scale Designed and operated SharePoint VDRs with detailed permission models, audit trails, and auto-run audit fit reports — up to **80 VDRs** and **5,000 accounts**. SharePoint. VDR. Permissions. Audit Trails. ERP • Biz Central. ##### ERP & Enterprise Process Architecture Led introduction of **Dynamics 365 Biz Central**; tight quality, rules, and ongoing tuning. Ran study for warehouse control rollout and created an firm-wide project control framework in ERP. Biz Central. ERP. Warehouse. Project Mgmt. Link-up • Finance. ##### API-Based Finance Integrations Designed API link-ups between **DATEV**, **Biz Central**, and banking systems to auto-run financial processes and reporting with audit-ready traceability. DATEV. API. Banking. Auto-work. Auto-work • Low-Code. ##### Process Automation & Low-Code Platforms Introduced Power Platform as firm-wide auto-work layer; built finance tools and auto-run cross-system workflows. Implemented HR process digitization via PowerApps with Azure link-up. Power Platform. PowerApps. Power Auto-run. HR. [ AI • Research • 2020. ##### Predictive Maintenance for Solar Parks (ML) Developed an ML-based predictive upkeep system for solar parks in a research cooperation. Pattern finding and failure forecasting to reduce downtime and optimize upkeep. Case Study. Machine Learning. Predictive. Research. View Full Case Study →. ](case-study-predictive-maintenance.html) DR • M365 Backup. ##### Disaster Recovery for Microsoft 365 Implemented DR plan and auto-run backups (Exchange/SharePoint/OneDrive/Teams) with Veeam + Microsoft backup solutions and regular recovery tests. DR. Backup. Veeam. Recovery. [ Private Cloud • Seafile. ##### Self-Hosted Cloud Storage with Seafile (PoC) Proof of concept for self-hosted, private-cloud file sync & share based on Seafile Server. Docs-first rollout with admin runbooks and ops handover package. Case Study. Seafile. Private Cloud. Docs. View Full Case Study →. ](experience-seafile.html) Move • Legacy. ##### Earlier Integration Experience (Legacy-to-Modern) Move projects including teamwork suite moves (Google teamwork → Microsoft 365) and cloud link-ups (Egnyte, Seafile/OwnCloud). Legacy system upgrade patterns. Move. Google to M365. Legacy. Fit & Limitations #### Best fit and known limitations ##### Best for Prospective clients checking fit who want anonymised but real buy-in examples — global endpoint control, Zero-Trust safety, data rooms, ERP link-ups, and private cloud rollout in rule-bound mid-market settings. ##### Not the right fit Buyers who need named refs with public attribution (see [Refs](references.html) for testimonials we are allowed to publish) or RFP teams looking for a turnkey case-study deck. ##### Known limitations Engagements are anonymised by design — client names and exact figures are intentionally redacted. Details are illustrative, not contractual; deeper materials are shared under NDA after a qualifying conversation. #### Want to discuss a similar project? Book a session to explore how we can help with your link-up, safety, or auto-work needs. [Book a Call](contact.html) [See Our Approach](approach.html) --- ## Seafile PoC: Self-Hosted Cloud Storage | curta.solutions URL: https://curta.solutions/experience-seafile.html > Self-hosted cloud storage PoC with Seafile: endpoint synchronization, governance-ready scope control, and operational documentation. Case Study • Private Cloud ### Self-hosted cloud storage with Seafile — a documentation-first proof of concept When touchy data must stay under your control, self-hosted file sync & share becomes a strategic option. This case study shows how a Seafile-based private-cloud prototype ships with clear operating docs and an auto-work mindset. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026 #### What the client needed - Centralized, reliable syncing/backup of defined workstation data. - A self-hosted alternative to approaches that were checked but rejected. - A solution that can be operated and extended with in-house IT after handover. #### What we delivered - A validated prototype (PoC scope) for Seafile Server. - A centrally definable syncing concept (user/system/app-relevant data sets) - A full handover package: Installation and setup docs. - Administration guide (runbook) - Logged PoC results and next-step recommendations. #### Why Seafile fits this scenario Seafile is a self-hosted file sync and share platform used when teams want: - **Full data ownership** — operate on-premise or in private cloud. - **Strong safety controls** — rules-friendly administration. - **Auditability** — logging and traceability patterns. - Optional **client-side encoded libraries** for highly touchy data. #### Implementation approach The PoC was set in five phases: - **Needs:** data scope, user groups, access model, audit fit constraints. - **Design:** hosting model, ID link-up option, logging/audit needs. - **Prototype build:** server setup, client checks, syncing rules. - **Docs:** admin runbooks + ops steps. - **Handover:** training, next-step roadmap, scaling considerations. #### Outcomes - Feasibility proven within a tight PoC scope. - Ops ownership lets through clear docs. - A foundation created for scaling to additional use cases. The docs-first approach meant that the in-house IT team received not just a running system but a full grasp of how it was configured and why each decision was made. The syncing scope concept — defining precisely which user, system, and application data sets are synced — gave the team a rules-ready framework that can be adjusted as needs evolve without revisiting the entire design. #### Scope & Limitations The team scoped this buy-in as a proof of concept, not a live rollout. The PoC covered server installation, client checks, syncing rule design, and docs. It did not include ongoing system administration, user support, backup systems control, or link-up with ID vendors such as LDAP or Entra ID — the team flagged those as next-step recommendations for a live phase. Hardware provisioning and network systems were also outside scope. The output was a validated design and a full handover package that lets the in-house IT team to proceed to live rollout independently or with targeted support. Firm-wide Fit Criteria #### When Seafile Makes Sense ##### Regulated Environments Private-cloud file sync & share for data-touchy setups requiring audit fit with GDPR, ISO 27001, or industry-specific rules. ##### Identity Integration Link-up into existing directory services (LDAP/AD) and SSO vendors for centralized ID and access control. ##### Audit Requirements Audit-friendly operation with full logging, permission rules, and traceability for audit fit reporting. ##### Sensitive Data Optional client-side encoded libraries for highly touchy data sets where even administrators should not have access. FAQ #### Frequently Asked Questions When does a company need self-hosted file sync & share rather of public cloud? When data sovereignty, rule-set audit fit, or safety policies need that touchy files never leave your systems. This is common in legal, finance, healthcare, and government sectors where public cloud storage poses unacceptable risk. How do you define a audit-fit syncing scope for endpoints? By analyzing data labeling (private, private, public), user roles, application needs, and audit fit constraints. The scope defines exactly which folders and file types are synced, backed up, or excluded. What rules controls matter most? ID control (who can access), permission structures (what they can do), logging (audit trails for all actions), and keep policies (how long data is kept). These controls ensure the system is audit-ready. How do you move from file servers or unmanaged sync tools safely? Through phased move with parallel operation, data checks, user training, and rollback planning. Docs ensures the in-house IT team can operate and extend the solution independently. #### Want to evaluate private cloud file collaboration? Book a "Private Cloud Teamwork Assessment" covering needs, design, and risk review. [Book Assessment](contact.html) [View More Experience](experience.html) --- ## References & Client Voices | curta.solutions URL: https://curta.solutions/references.html > Client testimonials and active engagements with Bauer Media, Greencells, SOLOS, ArgusConcept, Streetbuzz, A6 Architekten. Partners: Haus & Gross, jemix. Refs. ### References & Client Voices Published testimonials from shipped engagements, scope of now mandates, and the technology partners we team up with. Every quote on this page is verbatim from a written reference letter, work certificate, or signed buy-in document. Published Refs. #### Quotes from Written References Three published statements from shipped engagements — released for citation by the issuing teams. Media · 2015. ##### Bauer Media Group — Self-Hosted Cloud Storage PoC **Bauer Systems KG** · ~11,000 employees, 16 countries · Mac workstation data safety (Seafile-based PoC) Designed and shipped a self-hosted cloud-storage proof of concept for the Mac workstations of Bauer Media Group, after multiple prior IT-vendor approaches had been rejected by the client. ** “Before turning to Mr. Curta, we had already discarded several approaches from other IT specialists. His smart and flexible solution exceeded our expectations. He convinced us with his outstanding expert knowledge and his flexibility in addressing our specific needs. We are extraordinarily satisfied with his work and gladly recommend his services.” Martin Behrmann** · Project Lead, IT Systems · Bauer Systems KG / Bauer Media Group · Reference Letter, 03 August 2015 Reference Letter. Seafile. Private Cloud. macOS Fleet. Renewables · 2017–2025. ##### Greencells GmbH — Head of IT & Digital Transformation **Greencells GmbH** · Solar EPC · 700+ endpoints, 26 global locations · ISO 27001 ISMS · Zero-Trust safety · M365 / Intune / Azure rules. Eight-year tenure as Head of IT: zero-trust safety strategy, ISO 27001-matched IT service control, global endpoint and ID upgrade across 26 countries, and an inspiring leadership culture with measurable cost reductions across the Microsoft 365 / Azure lineup. Two written statements were issued at the close of the buy-in — the formal work certificate (graded 1, “sehr gut”) and a separate letter of recommendation. ** “Mr. Curta’s strategic mindset, innovation drive, and unwavering commitment were instrumental in advancing our company’s digital transformation. His achievements consistently exceeded expectations in every aspect.” Greencells GmbH** · Work Certificate, April 2025 · Overall grade: 1 (very good) ** “Mr. George Curta is an exceptional IT architect, strategic consultant, and leader who understands IT not just as a technical necessity but as a value driver for the entire team. For strategic IT leadership positions such as CIO, Head of IT, or IT Director, any company seeking an efficient, secure, and strategically matched IT team will greatly perk from his expertise and vision.” Greencells GmbH** · Letter of Recommendation, April 2025 Work Certificate. Recommendation Letter. Zero-Trust. ISO 27001. M365 · Intune · Azure. 700+ Endpoints. Active Engagements. #### Current Mandates Four now or recently shipped engagements — scope, contractual basis, and technology stack logged per mandate. Renewables · 2024–Present. ##### SOLOS GmbH — Head of IT (Freelance) **SOLOS GmbH** · Losheim am See, HRB 106035 Saarbrücken · Solar (C&I) / BESS / O&M · Greencells Group spin-off. Full outside IT duty — strategy, Microsoft 365 tenant administration, vendor control, GDPR audit fit (AVV incl. TOM under Art. 28 GDPR), domain & DNS lifecycle, and the ops web stack. Single point of contact for all IT topics; steering of outside vendors, tools, and budgets. Service contract dated 23 May 2025. M365 Tenant Admin. Exchange Online. Intune. GDPR / TOM. WordPress Ops. Vendor Mgmt. Urban Planning · 2026 (Active). ##### ArgusConcept GmbH — Self-Hosted Kimai Rollout & FileMaker Migration **ArgusConcept GmbH** · Saarbrücken / Illingen · Urban & eco planning, design, IT consulting. Follow-on buy-in from a 22-year prior relationship: the now-replaced FileMaker solution was at first designed and built by the same architect (2000–2004). Today, a clean design switch to a self-hosted Kimai stack (PHP/Symfony, Docker, MariaDB, REST/JSON API) — with custom fields, role & permission models, invoicing and reporting templates translated from the legacy system, and lossless data move of clients, projects, activities, and time entries via JSON-API and CSV import. Kimai. PHP / Symfony. Docker Compose. MariaDB. LDAP / 2FA. FileMaker Move. Marketing · 2022–Present. ##### Streetbuzz GmbH — IT Controlling & M365 Cloud Migration Lead **Streetbuzz GmbH** · Marketing & street-level services · Mid-market. Led the Microsoft 365 cloud move and the build-out of an in-house IT department with optimized vendor contracts. Rollout of ITILv4 standards for incident, change, and problem control, plus risk control. Since August 2024 the focus shifted to ongoing IT controlling for ops efficiency. In parallel, dev work of the StreetBuzzConcept platform concept for shared street-level marketing, including Playwright-MCP-based QA browser auto-work. M365 Move. Entra ID. SharePoint. Power BI. ITILv4. Playwright-MCP. Design · 2024. ##### A6 Architekten — Microsoft 365 Security & DLP Implementer **A6 Architekten** · Design & planning · May–July 2024. Rollout of encoded comms and data-loss prevention in Microsoft 365 for touchy design docs and competition material. Microsoft Purview trust level labels for privacy grading of project and competition docs, DLP policies across email, Teams, OneDrive, and SharePoint, plus encoded comms via Message Encoding and S/MIME options. Know-how material and handover docs produced for the in-house team. M365. Microsoft Purview. Trust level Labels. DLP. Message Encoding. Technology Partners. #### Partner Ecosystem Selected system houses and technology partners curta.solutions collaborates with on Apple-centric rollouts, run services, and cross-platform IT engagements. System House · Saarbrücken. ##### Haus & Gross it.services **Saarbrücken, Germany** · Apple-anchored full-service system house · In operation since the early 1990s. Long-standing Apple partner that has grown into a broad-based system house. Service lineup spans Apple sales and lifecycle support, mixed Windows / macOS rollouts, virtualized server landscapes, Microsoft 365, in-house data-center hosting, and run IT with fixed-price service contracts — including IT-safety and audit fit consulting. Positioning: *“Your IT — safe, simple, run.”* Apple Partner. Run Services. Microsoft 365. Private Data Center. macOS & Windows. [**hausgross.de/it →**](https://hausgross.de/it/en) Apple Technology Partner · Hamburg. ##### jemix GmbH **Hamburg, Germany** · Additional locations: Berlin, Cologne, Palma de Mallorca · Apple Technology Partner · JAMF link-up expert. Firm-wide IT consultancy specializing in Apple systems across heterogeneous setups. Focus areas include run services (Genius Run Services), mobile device control with JAMF, Microsoft Intune and VMware Workspace ONE, cybersecurity, and cloud platforms (Microsoft 365, Google Workspace). Serves SMBs, enterprises, and startups across multiple sectors. Positioning: *“Your partner for digital transformation.”* Apple Technology Partner. JAMF. Intune. Workspace ONE. M365 & Google Workspace. Cybersecurity. [**jemix.de →**](https://jemix.de/en/) Fit & Limitations. #### Best fit and known limitations ##### Best for Buyers who want named-source social proof from rule-bound mid-market clients (Bauer Media, Greencells), recent work certificates, and active engagements (SOLOS, ArgusConcept, Streetbuzz, A6 Architekten). ##### Not the right fit Buyers who want vendor logos at FAANG scale; teams that need named refs in industries we have not yet served — we will say so honestly during a qualifying conversation rather than stretch the list. ##### Known limitations Some clients need NDA-protected refs; quote dates are shown explicitly (Bauer Media 2015, Greencells 2025) so context is clear; active mandates are listed without quotes until the buy-in is suitable for public attribution. #### Looking for a reference contact? For deal-specific or position-specific reference checks, named contacts can be shared on request — with the prior consent of the respective client. [Request a Reference](contact.html) [See Project Examples](experience.html) --- ## ISO 27001 ISMS Preparation: Audit Ready | curta.solutions URL: https://curta.solutions/case-study-iso27001-isms.html > ISO 27001-aligned ISMS preparation: security framework design, process documentation, internal assessments, and audit readiness training. Case Study • Safety • 2024–Present ### ISO 27001 / ISMS Preparation — structure, documentation, and readiness Teams seeking ISO 27001 cert need a set foundation: safety framework, logged processes, in-house assessments, and employee training. This case study docs the prep journey toward audit readiness. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026 #### Client situation - Team needed an ISO 27001-matched ISMS foundation. - Needed real docs, assessments, and training for audit readiness. - Existing safety measures lacked formal structure and docs. Many teams reach a turning point. Informal safety practices that worked at smaller scale start to become a liability. Rule-set needs tighten. Clients demand proof of audit fit. The team wants to win contracts that need ISO 27001 cert. In this case, individual safety controls were in place. But no one had logged them, assessed them, or formally matched them to a risk-based framework. The gap study revealed that the foundation was largely sound. What was missing was the structure, proof, and docs an auditor needs. #### What was delivered - **Safety framework** matched to ISO 27001 needs. - **Logged safety processes** and controls. - **In-house assessments** (readiness review / gap study) - **Training enablement** for employees (cybersecurity best practices) The ISMS docs package covered the full mandatory set. It included an ISMS manual defining scope and context. It included a risk assessment methodology and risk list. It included a Statement of Applicability that logged the selected Annex A controls and the exclusion justifications. It included safety policies for info safety, access control, and acceptable use. It included ops steps for incident response, change control, and backup. We also developed and shipped training materials. Employees learned their duties within the ISMS. #### Governance approach - Audit fit fit to ISO 27001 (ISMS) needs. - Audit-readiness oriented docs. - Risk-based approach to control selection. - Steady gains framework. #### Outcome - Positioned the team to apply for ISO 27001 cert. - Set and audit-fit approach logged. - In-house skill built for ongoing ISMS upkeep. - Employee know-how elevated through training program. #### Scope & Limitations This buy-in covered ISMS prep. That meant framework design, docs, gap study, and training. We took the team up to readiness for a Stage 1 and Stage 2 cert audit. An accredited cert body conducts the actual cert audit. That was outside the scope of this buy-in. Technical rollout of specific controls was also out of scope where not already in place. That includes systems hardening, SIEM rollout, and ID control setup. The gap study flagged those items as client-owned action items. The team owns ongoing ISMS upkeep, in-house auditing, and control review cycles after first prep. The docs and in-house skill we built during the buy-in support that work. ISMS Parts #### What ISO 27001 Preparation Involves ##### Security Framework Design Establishing the ISMS scope, context, leadership commitment, and organizational roles. Defining the risk assessment methodology and control objectives. ##### Process Documentation Documenting safety policies, steps, and work instructions. Creating asset inventories, risk registers, and statement of applicability (SoA). ##### Internal Assessments Conducting gap study against ISO 27001 Annex A controls. Performing risk assessments and finding treatment plans for found gaps. ##### Training & Awareness Developing and delivering safety know-how training. Ensuring all employees understand their role in info safety. Typical Outputs #### ISMS Documentation Package - **ISMS Manual** — scope, context, policy framework. - **Risk Assessment** — methodology, risk list, treatment plans. - **Statement of Applicability (SoA)** — control selection and justification. - **Safety Policies** — info safety, access control, acceptable use. - **Steps** — incident response, change control, backup, access control. - **Asset Stock** — info assets, owners, labeling. - **Training Materials** — know-how program, phishing simulation, role-based training. - **Audit Proof** — logs, records, review docs. FAQ #### Frequently Asked Questions How long does ISO 27001 prep take? Depending on team size and now maturity, prep typically takes 6-12 months. This includes gap study, docs, rollout of controls, training, and in-house audit before the cert audit. What's the difference between prep and cert? Prep builds the ISMS foundation and docs. Cert is ran by an accredited cert body through Stage 1 (docs review) and Stage 2 (rollout audit) assessments. Do we need to set up all 93 Annex A controls? No. Controls are selected based on risk assessment. The Statement of Applicability docs which controls apply and provides justification for any exclusions. Can existing safety measures be linked? Yes. The gap study identifies what already exists and what needs to be added or formalized. Existing controls are logged and matched with ISO 27001 needs. #### Book an ISMS Readiness Workshop Start with a gap study and roadmap to understand your path to ISO 27001 cert. [Book Workshop](contact.html) [View More Experience](experience.html) --- ## M365 Migration, ITILv4 & IT Controlling | curta.solutions URL: https://curta.solutions/case-study-m365-migration-itil4.html > M365 cloud migration with ITILv4 implementation, IT department buildout, contract optimization, and IT controlling for operational efficiency. Case Study • M365 & ITILv4 • 2022–Present ### Microsoft 365 Migration with ITILv4 + IT Controlling — stable operations after go-live A set cutover with outside vendors needs in-house IT skill, standardized processes, and cost control. This case study docs the journey from the move through to ongoing IT controlling. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026 #### Client situation - Needed a set cutover with outside vendors involved. - Needed in-house IT skill buildout alongside the switch. - Standardized processes needed for lasting ops. - Cost control and vendor rules were critical success factors. #### What was delivered - **Microsoft 365 move leadership** and rollout. - **In-house IT department buildout**. - **ITILv4 process rollout** for IT ops. - **Contract and cost tuning** (vendor control) - **Ongoing IT controlling** for ops efficiency. - **Safety measures rollout**. #### Governance approach - ITILv4-matched process structure. - Audit fit and risk control measures. - SLA-based vendor rules. - Cost clear view and tuning cadence. #### Outcome - Successful cloud cutover done. - Streamlined IT ops with lasting controlling cadence. - Standardized processes letting consistent service rollout. - Cost tuning through vendor and license rules. We set up ITILv4 processes during the move, not after. This proved critical. Incident control, change control, and service request workflows ran from day one of the new setup. This prevented the informal practices that usually slow down post-cutover stabilization. The IT controlling cadence set a steady rhythm for license reviews, vendor speed assessments, and cost reporting. Leadership gained clear view into IT spending. No ad-hoc study was needed. #### Scope & Limitations This buy-in covered cutover leadership, ITILv4 process rollout, IT department buildout, and ongoing IT controlling. It did not include application dev work, custom software porting, or hardware procurement. Outside vendors handled end-user device control and physical systems. They operated under the vendor rules framework we set up during the buy-in. We kept the scope tight: people, processes, and rules. The goal was lasting ops after the buy-in concluded. The client should not depend on outside help for day-to-day IT ops. Project Phases #### Migration + Operations Journey ##### Phase 1: Migration Planning Assessment of now state, cutover strategy, vendor selection, risk study, and project rules setup with outside vendors. ##### Phase 2: Migration Execution Phased move of workloads to Microsoft 365, user comms, training, and cutover control with rollback planning. ##### Phase 3: IT Department Buildout Establishing in-house IT skill, defining roles and duties, hiring and onboarding, knowledge transfer from vendors. ##### Phase 4: ITILv4 Implementation Implementing service control processes: incident, problem, change, service request, and knowledge control matched to ITILv4. ##### Phase 5: Security Hardening Implementing safety starting points, access controls, tracking, and audit fit measures matched with organizational risk posture. ##### Phase 6: IT Controlling Ongoing cost rules, vendor speed measurement, SLA tracking, license tuning, and ongoing gains. Typical Outputs #### Migration + Operations Package - **Move Plan** — phased approach, timeline, resource plan, risk list. - **Vendor Contracts** — SLAs, duties, escalation paths. - **ITILv4 Processes** — logged steps, RACI, workflows. - **Safety Starting point** — controls, policies, tracking setup. - **IT Operating Model** — roles, duties, rules structure. - **Controlling Dashboard** — cost tracking, SLA speed, KPIs. - **Runbooks** — ops steps for common tasks. - **Training Materials** — user guides, IT team docs. FAQ #### Frequently Asked Questions Why combine move with ITILv4 rollout? A cutover is an chance to set up proper processes from the start. Implementing ITILv4 during the switch ensures the new setup has lasting ops from day one, rather than adding rules later. What is IT controlling in this context? IT controlling focuses on cost clear view, vendor speed measurement, SLA tracking, and ongoing tuning. It ensures IT spending delivers value and ops remain efficient over time. How do you manage outside vendors during move? Through clear contracts with defined SLAs, regular status meetings, logged duties (RACI), escalation steps, and speed measurement against agreed outputs. What happens after move is full? Focus shifts to ops: IT controlling, ongoing gains, safety upkeep, and user support. The ITILv4 processes set up during move provide the foundation for ongoing ops. #### Request an M365 Migration Review Get an assessment of your move risks and quick wins for ops gains. [Request Review](contact.html) [View More Experience](experience.html) --- ## M365 Secure Communication & Encryption | curta.solutions URL: https://curta.solutions/case-study-m365-secure-communication.html > Encrypted M365 communication with sensitivity labels for data classification and email protection. Policy implementation and user training included. Case Study • Microsoft 365 • 2024 ### Secure Microsoft 365 Communication — sensitivity labels, protection, and enablement When touchy docs are shared across teams and outside parties, encoded comms and clear labeling rules become key. This case study docs the rollout of Microsoft 365 info safety. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026 #### Client situation - Touchy docs shared across teams and outside parties. - Needed encoded comms and clear labeling rules. - Rule-set audit fit needs for data safety. - Users lacked know-how of proper data handling steps. The team shared contract drafts, financial summaries, and private data over standard email. There was no encoding, no access restrictions, and no indication of trust level level. Users had no consistent way to signal that a document needed careful handling. This applied to both in-house and outside takers. The gap created data safety risk. It also created audit gaps. No one could track which touchy docs had been shared, with whom, or under what terms. #### What was delivered - **Secure/encoded comms pattern** inside Microsoft 365. - **Trust level labels** for data labeling and safety. - **Policies** for auto and recommended labeling. - **User enablement/training** for correct usage. We designed a data labeling label set. It covered Public, In-house, Private, and Highly Private levels. The label set matched with rule-set needs and the team's own data handling practices. We configured trust level labels in Microsoft Purview with protections matched to each level. Protections included encoding, watermarks, headers and footers, and forwarding restrictions for private content. We published label policies to all users. Default labels encouraged consistent labeling from day one. Training sessions and quick reference guides helped users understand both the mechanics and the intent behind labeling. #### Governance approach - Audit fit fit with GDPR and in-house data safety needs. - Tight access for touchy comms. - Audit logging for all label applications and access attempts. - DLP link-up to prevent accidental data leakage. #### Outcome - Improved privacy for touchy document exchange. - Better data rules and rule-set audit fit. - User adoption through real training and guidance. - View into data labeling across the team. #### Scope & Limitations This buy-in covered four areas inside the existing Microsoft 365 setup: trust level label design, setup, policy publication, and user training. It did not include advanced auto-labeling with trainable classifiers. That option needs E5 licenses, which was not in place at the time. It also excluded SharePoint Info Barriers and link-up with third-party DLP tools outside Microsoft 365. The team owns ongoing label rules. That covers reviewing and updating the labeling label set as the data landscape evolves. It also covers tracking audit fit through Purview reporting. Hardware, network systems, and Microsoft licenses procurement were also outside the scope of this buy-in. Rollout Parts #### Sensitivity Labels & Information Protection ##### Data Classification Taxonomy Defining labeling levels (Public, In-house, Private, Highly Private) matched with biz needs and rule-set needs. ##### Sensitivity Labels Configuring Microsoft Purview trust level labels with right protections: encoding, watermarks, headers/footers, and access restrictions. ##### Label Policies Publishing classifications to users, setting defaults, requiring justification for downgrades, and configuring auto-tagging rules. ##### Email Protection Encoded email with trust level labels, preventing forwarding/copying for private content, and secure outside sharing. Typical Outputs #### Information Protection Blueprint - **Labeling Label set** — data categories, definitions, handling needs. - **Label Setup** — trust level labels with encoding and safety settings. - **Policy Docs** — labeling policies, auto-labeling rules, DLP policies. - **User Guides** — how to apply labels in Outlook, Office apps, SharePoint. - **Training Materials** — know-how sessions, quick reference cards. - **Audit fit Reports** — label usage analytics, safety status. FAQ #### Frequently Asked Questions What Microsoft licenses are needed for trust level labels? Basic trust level labels are included in Microsoft 365 E3. Advanced features (auto-labeling, trainable classifiers) need Microsoft 365 E5 or E5 Audit fit add-on. Can outside takers open encoded emails? Yes. Outside takers can authenticate via one-time passcode or their own Microsoft/Google account, depending on setup. The experience is seamless for most takers. How do users know which label to apply? Through clear label descriptions, training, and visual aids. Labels should be intuitive (e.g., "Private - Outside Takers Restricted"). Default labels and recommendations help guide users. Can labeling be auto-run? Yes. Auto-labeling can detect touchy content (credit cards, private data, custom patterns) and apply or recommend labels auto. This needs E5 licenses. #### Request an M365 Data Protection Blueprint Get a tailored trust level labels and policies design for your team. [Request Blueprint](contact.html) [View More Experience](experience.html) --- ## ML Predictive Maintenance for Solar Parks | curta.solutions URL: https://curta.solutions/case-study-predictive-maintenance.html > Machine learning-based predictive maintenance system for solar parks. Research collaboration to reduce failures and forecast maintenance needs. Case Study • Machine Learning • 2020. ### Predictive Maintenance (ML) for Solar Parks — research collaboration to reduce failures Asset-heavy ops where failures cause cost, downtime, and service disruption need early pattern finding and upkeep forecasting. This case study docs a machine learning system developed in a research cooperation. By [George Curta](about.html) · Founder, curta.solutions · May 24, 2026. #### Client situation - Asset-heavy ops where failures cause cost, downtime, and service disruption. - Objective: detect patterns early and forecast upkeep needs. - Need for proof-based decision support to optimize servicing schedules. Solar parks make ongoing streams of sensor data. Sun levels. Heat. Inverter output. String-level speed. Without pattern finding, this data goes unused. Field crews were reacting to faults, not heading them off. Downtime and spare-part costs grew. The team-up with a PhD researcher brought both field know-how on solar assets and the ML method to build a set forecast plan. #### What was delivered - A machine learning-based predictive upkeep system for solar parks. - Implemented together with a PhD researcher in a research cooperation (2020). - Pattern finding and failure forecasting skills. The shipped system took in past sensor data plus service records and eco signals. It used these to train models that spot fault precursors. The team built outputs anyone could read. Ranked work orders. Outage risk scores. Ops teams, not data scientists, could act on the results. An MLOps frame backed drift checks and re-training as new data came in. #### Governance approach The rollout followed a safety-by-design and rules-first approach: - ITILv4-matched dev work processes. - ISMS / ISO 27001-oriented controls for data handling. - Docs-first rollout with ops handover. #### Outcome - Improved ability to anticipate upkeep needs and failures early. - Proof-based prioritization of servicing activities. - Foundation for scaling predictive skills to additional asset types. The research team-up made a proven prototype. It showed that pattern finding and fault forecasts work with the ready sensor and service records. The docs-first handover meant the method could be grasped, grown, and tuned by the ops team on its own. #### Scope & Limitations This buy-in was a research team-up scoped as a proof-of-concept system. Live roll-out, model hosting, real-time alerts, and link-up with SCADA or ticketing tools were out of scope. The work proved feasibility and a repeatable method. It did not ship a full MLOps pipeline. Teams who need live-grade forecast upkeep tools would need a split roll-out and put-to-work phase built on this base. Typical ML Approach. #### How Predictive Maintenance Systems Work ##### Typical Inputs - Asset telemetry / sensor data (SCADA, tracking, logs). - Weather and eco signals. - Upkeep history + work orders. - Quality and service KPIs (failures, MTTR, response times). ##### Typical Outputs - Failure probability and time-to-failure estimates. - Upkeep recommendations and prioritized work orders. - Outage risk predictions and "where to look first" guidance. - Explainable dashboards for ops and control. ##### Project Deliverables - Data readiness assessment (quality, completeness, safety). - Model starting point + review plan (accuracy, false positives). - MLOps plan: tracking, drift finding, retraining cadence. - Ops link-up: alerts, dashboards, ticket auto-work. ##### Business Impact - Reduced unplanned downtime. - Optimized spare-part planning. - Ahead-of-time upkeep scheduling. - Data-driven resource allocation. FAQ. #### Frequently Asked Questions What data is needed for predictive upkeep? Typically sensor data (telemetry, SCADA), upkeep history, eco factors (weather, temperature), and ops KPIs. The team checks data quality and completeness before model dev work. How do you ensure the model stays accurate over time? Through MLOps practices: ongoing tracking, drift finding, scheduled retraining, and feedback loops from upkeep outcomes. The model improves as more data becomes ready. Can predictive upkeep be applied to other industries? Yes. The same patterns apply to manufacturing, utilities, transportation, and any asset-intensive operation. The key is having sufficient historical data and defined upkeep outcomes. What rules controls are important for ML systems? Data labeling and access control, model risk assessment, explainability needs, audit logging, and clear duty (RACI) for model decisions and incidents. #### Discuss Predictive Maintenance for Your Assets Book a call to explore how ML-based prediction can reduce downtime and optimize upkeep in your ops. [Book Call](contact.html) [View ML Solutions](solutions-ml.html) --- ## Projects — Tools & Solutions | curta.solutions URL: https://curta.solutions/projects.html > Custom tools, GPTs, and solutions developed for enterprise IT challenges. Migration assistants, governance frameworks, and automation solutions. Projects ### Tools & Solutions Custom tools, GPTs, and solutions developed for firm-wide IT challenges — from move assistants to rules frameworks and auto-work solutions. Featured Projects #### Tools & Platforms ##### anonymize.solutions Firm-wide Platform PII Finding Self-Run 48 Languages White-Label **Firm-wide PII Finding & PII strip Platform**. The umbrella platform for firm-wide PII safety. 320+ item types, 48 languages, 3 rollout models (SaaS, Run Private, Self-Run). 16 pre-built solution templates. Zero-Knowledge sign-in on the Firm-wide tier, air-gapped desktop, white-label option. Built on Microsoft Presidio. [Open anonymize.solutions →](https://anonymize.solutions/) [View Project Details](project-anonymize-solutions.html) Firm-wide pricing. Contact for assessment. ##### anonym.life Firm-wide Platform Zero Knowledge Privacy Middle-tier BYOK MPC Holding **Privacy Middle-tier for Deal Systems**. Zero Knowledge PII finding platform. Privacy middle-tier between data vendors and service vendors. 390+ item types, 317 regex matchers, 67 languages. Policy-based alias-swap, narrow release. Client-run keys (BYOK), MPC threshold holding, checksum checks, audit trail logging. [Open anonym.life →](https://anonym.life/) [View Project Details](project-anonym-life.html) Firm-wide pricing. Starter from €499/month. ##### anonymize.today SaaS Platform PII Finding PII strip GDPR ISO 27001 **Firm-wide-Grade PII Finding & PII strip**. Deterministic, regex-based safety for GDPR audit fit. No AI, no guessing — transparent, audit-fit results on ISO 27001-matched servers in Germany. 256 item types, 27 languages, 5 PII strip methods. [Open anonymize.today →](https://anonymize.today/) [View Project Details](project-anonymize-today.html) Free tier: 300 tokens/month. No credit card needed. ##### anonym.legal SaaS Platform Zero-Knowledge MCP Server 48 Languages Legal Tech **Zero-Knowledge PII PII strip with MCP Server**. Privacy-first PII finding with Zero-Knowledge sign-in and native MCP Server for AI tools (Claude Desktop, Cursor, VS Code). 48 languages with RTL support, 285+ item types, deterministic processing. [Open anonym.legal →](https://anonym.legal/) [View Project Details](project-anonym-legal.html) Free tier: 200 tokens/month. Zero-Knowledge from day one. ##### anonym.today SaaS Platform PII Finding Privacy-First 27 Languages Chrome Extension **Consumer-Friendly PII Safety & PII strip**. Simple, accessible PII finding and PII strip for everyone. 256+ item types, 27 languages, 5 safety methods. Ready as web app, desktop app, Office add-in, and Chrome extension. Zero data storage, zero tracking. [Open anonym.today →](https://anonym.today/) [View Project Details](project-anonym-today.html) Free tier: 100 tokens/month. Zero data storage, zero tracking. ##### cloak.business SaaS Platform PII Finding Image Redaction 48 Languages MCP Server **Firm-wide-Grade PII Finding & PII strip**. Regex-first PII safety with 317 deterministic pattern matchers, NLP for names and locations. 320+ item types, 48 languages, image redaction with OCR. ISO 27001-matched German servers (Hetzner, Falkenstein). Built on Microsoft Presidio. [Open cloak.biz →](https://cloak.business/) [View Project Details](project-cloak-business.html) Free tier: 200 tokens/cycle. No credit card needed. ##### anonymize.dev SaaS Platform Developer Tools MCP Server 48 Languages Credential Finding **Privacy-as-Code for Developers**. Privacy layer for AI tools. Auto detects and replaces PII in prompts — API keys, credentials, client data — before they reach outside AI services. 50+ developer-specific item types drawing on the anonym.legal engine; 48 languages. MCP Server for Claude Desktop and Cursor. ISO 27001-matched German servers. [Open anonymize.dev →](https://anonymize.dev/) [View Project Details](project-anonymize-dev.html) Free tier: 200 tokens/cycle. All features included. ##### anonymize.live SaaS Platform AI Chat Safety Chrome Extension 27 Languages Real-Time Finding **AI Chat Safety Made Simple**. Protect your privacy in AI chats. Real-time PII finding for ChatGPT, Claude, and Gemini. 256+ item types across 15 categories, 27 languages with RTL support, Chrome Extension (Developer Preview) with live de-PII strip. Zero data storage, zero tracking. GDPR audit-fit. [Open anonymize.live →](https://anonymize.live/) [View Project Details](project-anonymize-live.html) Free tier: 100 tokens/month. No installation needed. ##### anonymize.education Education Platform Student Privacy 320+ Item Types 48 Languages GDPR & FERPA **Protect Student Data. Keep Education Safe.** Data PII strip for schools and universities. 320+ item types, 48 languages, 5 PII strip methods. Desktop app, Office add-in, OpenOffice add-in, and MCP Server. No technical skills needed. Designed for GDPR, FERPA-matched, hosted on ISO 27001-matched systems (Hetzner). SOC 2 Type II in progress (Q2 2026 target). Per-character pricing for institutions; Teacher tier free. Built on anonym.legal. [Open anonymize.education →](https://anonymize.education/) [View Project Details](project-anonymize-education.html) Free tier: 200 tokens/month. Free Desktop App included. ##### anonym.plus Desktop App 100% Offline 340+ Item Types 48 UI / 44 NLP Languages Encoded Vault **Your Docs Never Leave Your Computer**. 100% offline PII finding and PII strip desktop app. Bundled Presidio + spaCy NLP engine with 340+ item types, 48 UI languages (44 NLP finding), 7 document formats plus images with OCR. Rust-native PII strip operators (reversible AES-CBC operator for Presidio compatibility) and an AES-256-GCM encoded local vault. No uploads, no cloud, no internet needed. Built on Microsoft Presidio. [Download for Free →](https://anonym.plus/) [View Project Details](project-anonym-plus.html) Free download for basic use. No account needed. Windows, macOS, Linux. ##### piisafe.eu Free Tool Website PII Scanner 131+ Item Types 41 Languages Zero Data Storage **Free Website PII Scanner**. Instantly scan any website for exposed private data. 131+ item types via the cloak.biz API, 41 languages, results typically under 60 seconds. Regex-based finding (free tier; ML augmentation via cloak.biz upstream), A-F risk grading, HTML/JSON/CSV export. GDPR, HIPAA, PCI-DSS, and CCPA audit-fit. No listing needed. [Open piisafe.eu →](https://piisafe.eu/) [View Project Details](project-piisafe-eu.html) Free: 20 scans/hour, 10 pages/scan. No account needed. ##### gtools.pro Free Tool M365 Administration Zero-Knowledge Content Backup Audit fit Export **Zero-Knowledge M365 Administration Suite**. Free Microsoft 365 administration tools. Local PowerShell collectors export Intune, Entra ID and Safety setups; a self-hosted Teams chat exporter (React + FastAPI) backs up Teams 1:1, group and channel conversations. 11 audit reports with ISO 27001 Annex A mapping (SOC 2, GDPR, HIPAA, NIS2 on the roadmap). Tenant credentials stay local; no third-party SaaS gets them. [Open gtools.pro →](https://gtools.pro/) [View Project Details](project-gtools-pro.html) Free for all M365 administrators. Credentials never leave your browser. ##### EU IT Migration Master Custom GPT M365 Move EU Focus Rules Safety-by-Design **Custom GPT for EU-Focused Migrations**. Set move coaching with focus on rules, risk control, docs, and privacy-conscious rollout. Supports teams in translating tough moves into clear, repeatable work packages. [Open in ChatGPT →](https://chatgpt.com/g/g-67c6d0462c8881919c19a30d820c26ae-eu-it-migration-master) [View Project Details](project-eu-migration-master.html) Needs ChatGPT Plus or Firm-wide subscription. ##### PropsHub Custom Software Film Live Stock Control Zero-Knowledge React 19 **The Operating System for Props Departments**. Professional platform for film and TV props control. Script-aware planning with physical asset tracking. Barcode/QR scanning, procurement tracking, budget control, and continuity tracking. Zero-knowledge design with client-side encoding. Built with React 19, TypeScript, Fastify 5, and PostgreSQL. [Open PropsHub →](https://propshub.online/) [View Project Details](project-propshub-online.html) Custom dev work project for film and TV live. ##### localLLM Custom AI Solution Sovereign Local AI Self-Improving RAG Agentic Orchestration In Rollout **Sovereign AI Inside the Client Perimeter**. A turnkey platform that scans the client’s codebases and docs, maintains a self-improving RAG knowledge base per project, and serves a project-aware assistant through an OpenAI-compatible gate. A curated list of 54 model families, semantic routing across 30 task types, a plan-then-execute agentic orchestrator with grammar-constrained tool calls, an MCP server with 38 tools, and a bundled VS Code extension — air-gapped on-premises operation; no tokens, prompts, or context ever leave the client’s network. [View Project Details →](project-localllm.html) [Discuss a Similar Buy-in](contact.html) Custom AI rollout project · Now in dev work · Air-gapped on-premises operation. ##### LocalBrain Custom AI Solution Knowledge Graph E-Scan Workflow Local-Only Operation In Active Dev work **A Living Knowledge Graph and FRCP-Matched E-Scan Workbench**. A custom AI buy-in at v6.2, in active use. Years of firm email and document history become a fully-local knowledge graph — force-directed graph navigation, Leiden community finding, participant-gap anomaly alerts, hybrid BM25 + vector search with RRF fusion, chat-first console with slash commands and voice input. On top of it sits an e-scan workbench designed against FRCP 26: matter scoping, custodian chain-of-holding ledger, five-state privilege workflow, monotonic Bates numbering, audit-tracked redaction overlay, privilege log and live-set CSV. Three-class provenance with six mandatory fields on every edge. Runs on the operator’s hardware; no data leaves the client perimeter. [View Project Details](project-localbrain.html) [Discuss a Similar Buy-in →](contact.html) Custom AI rollout project · v6.2 (May 2026), in active use · On-premises operation inside the client perimeter. ##### SuperLocalBrain Custom AI Solution Knowledge Brain Local-Only Operation Cited Answers In Active Dev work **A Private Knowledge Brain for Small Professional Teams**. SuperLocalBrain is the knowledge-brain sibling to [LocalBrain](project-localbrain.html), at v6.5 (May 2026), concept locked. It is built for a small professional-services firm or family office: 6–10 people, fifteen years of mixed private and company files, three storage generations. The week-one problem it solves is the everyday one. *Where is the thing I half-remember, and what does it actually say?* Drop a folder. Ask in plain English. Get back an answer with citations clickable to the source file. Every claim in the graph carries a trust tier (deterministic, rule-derived, or LLM-inferred) and six fields of proof. Four memory tiers (L0–L3) hold a bi-temporal record, so superseded values are never overwritten. Forensic chain stays out of scope; that is LocalBrain’s territory. Designed against EU AI Act 2 Aug 2026 readiness, on the operator’s own hardware. [View Project Details](project-slb.html) [Discuss a Similar Buy-in →](contact.html) Custom AI rollout project · v6.5 (May 2026), concept locked · On-premises operation inside the client perimeter. About These Projects #### Why We Build Tools ##### Repeatable Delivery Tools encode proven methodologies into reusable assets, ensuring consistent quality across engagements. ##### Governance by Default Built-in audit fit considerations, docs standards, and audit-ready outputs from the start. ##### Knowledge Transfer Tools help clients internalize best practices, letting lasting ops after project completion. ##### Efficiency at Scale Set approaches reduce depth, speed up rollout, and minimize rework. Fit & Limitations #### Best fit and known limitations ##### Best for Visitors deciding which curta.solutions tool fits their use case — the product family is deliberately wide, with each tool tuned to a specific persona, rollout model, and audit fit profile. ##### Not the right fit Buyers expecting one universal SKU; teams that do not have a privacy or sovereignty constraint to begin with and would be over-served by zero-knowledge design. ##### Known limitations Some products are SaaS, some are desktop, some are custom engagements — choose by rollout model first; free tiers vary across platforms; most firm-wide features sit behind contact-sales rather than self-serve checkout. #### Need a custom solution? Let's discuss how tailored tools can speed up your IT efforts while maintaining rules and audit fit. [Book a Call](contact.html) [View Solutions](solutions.html) --- ## anonymize.today — PII Anonymization | curta.solutions URL: https://curta.solutions/project-anonymize-today.html > Deterministic PII anonymization for GDPR compliance. 256 entity types, 27 languages. ISO 27001-aligned servers in Germany. Free tier: 300 tokens/month. Project • SaaS Platform • Data Safety ### anonymize.today — Simple, Transparent PII Detection & Anonymization Deterministic, regex-based safety for GDPR audit fit. No AI, no guessing—just transparent, audit-fit results on ISO 27001-matched servers in Germany. SaaS Platform PII Finding PII strip GDPR ISO 27001 Microsoft Presidio #### Platform Overview **anonymize.today** is a simple, transparent PII (Personally Identifiable Info) finding and PII strip platform built on Microsoft Presidio technology. The platform uses predefined regex patterns — deterministic output, reproducible for the same input on the same ruleset version. Fully audit-fit for rule-set audit fit. 256 Item Types 27 PII Finding Languages 48 UI Languages 5 PII strip Methods Core Skills #### PII Detection & Anonymization Methods ##### PII Detection Detect 256 item types across private IDs, financial data, government IDs (30+ global variations), location info, digital IDs (IP, MAC, URLs), team data, and temporal data. Item count grows as new patterns ship; now list defined in the live items table. ##### 5 Anonymization Methods - **Replace** — Substitute with placeholder. - **Redact** — Remove fully. - **Hash** — SHA-256 hashing. - **Encrypt** — AES-256-GCM encoding. - **Mask** — Partial masking. ##### Multi-Language Support 27 languages including English, German, Spanish, French, Italian, Japanese, Chinese, Korean. RTL support for Arabic. Auto language finding. ##### Detection Presets Default and public presets for common audit fit scenarios. 89 built-in presets optimized for local PII patterns. Real-time processing without data storage. Why Regex, Not AI? #### Deterministic Approach The platform deliberately uses regex-based finding rather of AI/ML for critical audit fit perks. ##### Regex-Based Approach - Deterministic, reproducible results (same input + same ruleset version) - Fully audit-fit for audit fit. - No training data needed. - Transparent decision making. - Fast, predictable speed. - No model drift over time. ##### AI/ML Approaches (Avoided) - Results vary between runs. - Black box decision making. - Needs training data. - Difficult to audit. - Higher compute costs. - Model drift over time. Product Offerings #### Platform Components ##### Desktop App **Windows, macOS, Linux**. Process PDF, DOCX, XLSX, CSV, JSON, XML, TXT files locally with AES-256-GCM encoding. Secure vault and offline skill for air-gapped setups. ##### Office Add-in **Word, Excel & PowerPoint**. Anonymize directly in Microsoft Office. 256 item types, 27 languages, and reversible encoding without leaving your document. ##### Chrome Extension Developer Preview **ChatGPT, Claude & Gemini**. Protect your AI conversations auto. Real-time PII finding and PII strip before messages reach AI chatbots. Reversible AES-256 encoding, file PII strip (.txt, .md, .csv, .json, .xml, .log, .yaml), and 89 built-in presets. ##### API Integration **RESTful Endpoints** JWT sign-in and rate limiting. Integrate PII strip into your workflows and CI/CD pipelines. How It Works #### The 10-Step Process - **Input Text** — Submit your document via web interface, API, Word Add-in, or Chrome Extension. - **Language Finding** — System identifies the document language for optimal processing. - **Tokens** — Text is broken into tokens for pattern matching. - **Pattern Matching** — Regex patterns scan for 256 item types. - **Context Study** — Surrounding text improves finding accuracy. - **Confidence Scoring** — Each finding gets a confidence score. - **Item Labeling** — Found items are categorized by type. - **Review Results** — See all detections with positions and scores. - **Apply PII strip** — Choose your method: Replace, Redact, Hash, Encrypt, or Mask. - **Output Document** — Download your anonymized document. [View detailed process docs →](https://anonymize.today/how-it-works) ##### Have Questions? Ask our AI assistant about PII finding, PII strip methods, GDPR audit fit, or pricing. anonymize.today Assistant For detailed technical docs, visit [docs.anonymize.today](https://docs.anonymize.today/) Use Cases #### Industries & Applications ##### Enterprise GDPR audit fit & data safety at scale. Process millions of docs across HR, legal, and finance departments. ##### Developers Testing setups & CI/CD pipelines. Make safe test datasets without live PII exposure. ##### Legal Contract PII strip & e-scan. Redact touchy info from court filings and scan docs. ##### Healthcare Patient data workflows matched to HIPAA PHI handling. Let research while protecting patient info. ##### Financial PCI-DSS-matched PAN/PII redaction for fraud-prevention workflows. Protect deal records and client data. ##### Research Academic data sharing & publication. Share datasets while protecting participant privacy. ##### Government Public records & FOIA audit fit. Auto-run redaction for FOIA requests and inter-agency sharing. Systems & Audit fit #### Security & Trust ##### ISO 27001-Aligned Infrastructure All processing happens in Hetzner's ISO 27001-certified data centers in Germany. Your data stays in the EU with no surprise law area issues. ##### Designed for GDPR Supports data-subject-rights workflows. EU data residency option. Real-time processing without data storage. ##### Microsoft Presidio Built on Microsoft's open-source Presidio framework. Transparent pattern matching with no black-box algorithms. ##### Enterprise Security AES-256-GCM encoding, modern TLS for all connections, full audit logging, two-factor sign-in, and custom encoding keys on the Pro plan. Uptime targets are logged in the live status page rather than published as a contractual SLA. Pricing #### Transparent Token System Pay for what you use with a transparent token system. Each operation costs tokens based on text length, items found, and operation type. A 50% discount is applied to all ops. No hidden fees. ##### Free €0/month 300 tokens per 30-day cycle. - Online account & dashboard. - Analyzer & Anonymizer tools. - 27 PII finding languages. - Default finding presets. - AI chatbot support. - Desktop App (Win, Mac, Linux) - 5 history entries. ##### Basic Most Popular €3/month 500 tokens per 31-day cycle + top-ups (+200 for €1) - All Free features. - Default + public presets. - Office Add-in (Word, Excel, PowerPoint) - Chrome Extension (Developer Preview) - Batch processing (100 items) - API access. - 10 history entries. ##### Pro Best Value €9/month 2,000 tokens per 31-day cycle. - All Basic features. - Full API access. - Custom encoding keys. - Priority support. - Batch processing (500 items) - Token top-ups ready. - 50 history entries. ##### Business Team €29/month 10,000 tokens per 31-day cycle. - All Pro features. - Advanced API access. - Batch processing (5,000 items) - Token top-ups ready. - 100 history entries. - Firm-wide support. Access #### Try anonymize.today Start with 300 free tokens per month. No credit card needed. [Start Free Trial →](https://anonymize.today/) [View All Features](https://anonymize.today/features) [View Docs](https://docs.anonymize.today/) **Related Platform:** [anonym.legal](project-anonym-legal.html) — Zero-Knowledge sign-in, MCP Server for AI tools, 48 languages with RTL support Fit & Limitations #### Best fit and known limitations ##### Best for Quick, transparent, deterministic PII scrubbing with no signup overhead — pilots, light use, and education or research teams running short experiments before scaling. ##### Not the right fit Image redaction with OCR (use [cloak.biz](project-cloak-business.html)); firm-wide audit logging or MCP link-up (use [anonym.legal](project-anonym-legal.html)); workloads that need broad multilingual coverage beyond Latin scripts. ##### Known limitations Regex-only finding misses ambiguous names without ML support; coverage is 27 languages versus 48 on the firm-wide platforms; the free tier resets every 30 days. #### Need enterprise data anonymization? Let's discuss how anonymize.today can support your GDPR audit fit and data safety needs. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonym.legal — Enterprise PII Platform | curta.solutions URL: https://curta.solutions/project-anonym-legal.html > Enterprise PII anonymization: 285+ entity types, 48 languages with RTL, MCP Server for AI tools. ISO 27001-aligned German servers. Project • SaaS Platform • Legal Tech ### anonym.legal — Enterprise-Grade PII Detection & Anonymization Regex patterns for set data, proven ML models for names. Transparent, audit-fit results on Hetzner's ISO 27001-matched servers in Germany. 285+ item types, 48 languages with RTL support, MCP Server for AI tools. SaaS Platform Zero-Knowledge MCP Server 48 Languages RTL Support Legal Tech #### Platform Overview **anonym.legal** is a Zero-Knowledge PII finding and PII strip platform designed for legal professionals and privacy-conscious teams. Features native MCP Server link-up for AI tools (Claude Desktop, Cursor, VS Code via Continue and Cline) and advanced Zero-Knowledge sign-in where your password never leaves your device. 285+ Item Types 48 Languages + RTL 5 PII strip Methods Key Differentiators #### What Makes anonym.legal Unique ##### Zero-Knowledge Authentication Your password **never leaves your device**. Built with Argon2id + XChaCha20-Poly1305 encoding and AES-256-GCM vault encoding. 24-word recovery phrase for account recovery. ##### MCP Server for AI Tools Native link-up with Claude Desktop (stdio), Cursor, and VS Code via Continue and Cline extensions (HTTP). 6 operators: encode, hash, mask, redact, replace, keep. Item groups and presets (UNIVERSAL, FINANCIAL, DACH, FRANCE, NORTH_AMERICA). ##### 48 Languages + RTL Support Extended language support including Arabic, Hebrew, Persian, and Urdu with right-to-left rendering. Powered by spaCy, Stanza, and XLM-RoBERTa transformers. ##### Legal-Focused Design Optimized for contract PII strip, e-scan, and FOIA audit fit. Audit trails and reproducible results for legal document live. MCP Server Link-up #### Privacy-First AI Workflow The MCP Server acts as a privacy shield between your AI tools and touchy data. - **AI Tool Request** — Claude Desktop, Cursor, or VS Code (via Continue/Cline) sends request containing touchy data. - **MCP Interception** — MCP Server intercepts and analyzes content for PII. - **PII Tokens** — Touchy data replaced with tokens (e.g., PII_PERSON_001, PII_EMAIL_001) - **AI Processing** — AI processes only anonymized info. - **Response Return** — Response flows back through MCP Server. - **Optional De-tokens** — First values can be restored if needed. // Before MCP Server "Process payment for John Doe, email john@example.com..." // After MCP Server "Process payment for PII_PERSON_001, email PII_EMAIL_001..." NLP Technology Stack #### Multi-Engine Language Processing anonym.legal uses three NLP engines optimized for other language families with lazy-loaded models for efficiency. Regex patterns for set data, ML models for names and teams. ##### spaCy Engine 25 Languages Fast industrial-strength NLP for European languages and major world languages. ##### Stanza Engine 7 Languages Stanford NLP engine for focused language processing and academic accuracy. ##### XLM-RoBERTa Transformer 16 Languages Cross-lingual transformer for low-resource languages and multilingual docs. Core Skills #### PII Detection & Anonymization ##### 285+ Entity Types Names, emails, phone numbers, credit cards, SSNs, IBANs, IP addresses, and more. Pattern-based finding for set data, ML-based NER for names and teams. Confidence scoring for all detections. ##### 5 Anonymization Methods - **Replace** — Substitute with fake data. - **Redact** — Full removal. - **Hash** — SHA-256 hashing. - **Encrypt** — AES-256-GCM encoding. - **Mask** — Partial obscuring. ##### RTL Language Support Full right-to-left support for Arabic, Hebrew, Persian, and Urdu. Auto language finding for mixed-language docs. ##### Deterministic Results Regex patterns for set data give deterministic, reproducible results (same input + same ruleset version). ML-based NER provides high consistency for names. Fully audit-fit for audit fit. Rollout Options #### Platform Components ##### Web Application **Cloud-Based Processing** Full-featured web interface with Zero-Knowledge sign-in. No software installation needed. ##### Desktop App **Windows 10+, macOS 10.15+, Linux (Ubuntu 20.04+)** Docs stay on your device while using cloud-powered item finding. Only extracted text is sent for study. AES-256-GCM encoding with Argon2id key derivation. Supports PDF, DOCX, XLSX, TXT, CSV, JSON, XML. ##### Office Add-in **Word, Excel & PowerPoint**. Real-time PII finding directly in Microsoft Office. Anonymize without leaving your document. ##### MCP Server **Claude Desktop, Cursor, VS Code (Continue & Cline)** Native stdio link-up for Claude Desktop. HTTP endpoints for Cursor and VS Code via Continue and Cline extensions. 6 operators with item groups and presets. ##### Chrome Extension Developer Preview **ChatGPT, Claude & Gemini**. Auto detect and anonymize PII before sending messages to AI chatbots. Real-time interception with response de-PII strip. ##### REST API **JWT Sign-in** RESTful endpoints for workflow auto-work and CI/CD pipeline link-up. ##### Batch Processing **Up to 100 Docs (Firm-wide)** Multi-document upload with parallel processing. Plan limits: Free (2), Basic (5), Pro (10), Biz (50). Use Cases #### Industries & Applications ##### Legal Contract PII strip & e-scan. Redact touchy info from court filings and scan docs with audit trails. ##### Enterprise GDPR audit fit at scale. Centralized PII finding across departments with role-based access control. ##### Healthcare Patient data workflows matched to HIPAA PHI handling. Medical records PII strip for research and administrative docs. ##### Financial PCI-DSS-matched PAN/PII redaction for fraud-prevention workflows. Deal and client data safety with rule-set reporting. ##### Government Public records & FOIA audit fit. Auto-run redaction for FOIA requests and inter-agency data sharing. ##### Developers Testing setups & CI/CD pipelines. Safe test dataset generation without live PII exposure. Systems & Safety #### Zero-Knowledge Architecture ##### Password Never Leaves Device True Zero-Knowledge sign-in. Your master password is used locally to derive encoding keys. Server never sees your password. ##### Argon2id + XChaCha20-Poly1305 Argon2id (64 MB / 3 iterations) for memory-hard key derivation; XChaCha20-Poly1305 for authenticated encoding. ##### 24-Word Recovery Phrase BIP-39 compatible recovery phrase for account recovery. No password reset emails — you control your keys. ##### ISO 27001-Aligned Hosted in Hetzner data centers in Germany. Designed for GDPR with EU data residency. ISO 27001 fit without a third-party certificate — framework controls set up, formal cert not yet obtained. Pricing #### Transparent Token System Think of tokens like game coins. Each operation costs tokens based on text length, items found, and ops applied. AI Item Creation costs 50 tokens per request. ##### Free €0/month 200 tokens per 30-day cycle. - Online account. - Analyzer & Anonymizer. - 48 languages - Default presets. - Batch processing (2 texts) - TXT files only. - 1 MB max file size. ##### Basic Most Popular €3/month 1,000 tokens per 31-day cycle + top-ups (+250 for €1) - All Free features. - Batch processing (5 texts) - Public presets & items. - API access. - PDF/DOCX/TXT/CSV support. - 5 MB max file size. - 50 files/day ##### Pro Best Value €15/month 4,000 tokens per 31-day cycle + top-ups (+300 for €1) - All Basic features. - MCP Server access. - Batch processing (10 texts) - All file types supported. - 10 MB max file size. - Unlimited uploads. ##### Business Enterprise €29/month 10,000 tokens per 31-day cycle + top-ups (+350 for €1) - All Pro features. - Batch processing (50 texts) - 20 MB max file size. - 1,000 history entries. - Priority support. - Custom link-ups. Platform Comparison #### anonym.legal vs anonymize.today Both platforms share the same core technology but serve other use cases. Feature anonym.legal anonymize.today **Focus** Legal & Privacy-First. Simple & Transparent. **Languages** 48 + RTL Support. 27 **Item Types**. 285+ 256 **Zero-Knowledge Auth**. Yes No **MCP Server**. Yes (Claude, Cursor, VS Code + extensions) No **Basic Tier Tokens**. 1,000 500 **Recovery Method**. 24-word phrase. Email-based [View anonymize.today details →](project-anonymize-today.html) Access #### Try anonym.legal Start with 200 free tokens per month. No credit card needed. Zero-Knowledge from day one. [Open anonym.legal →](https://anonym.legal/) [View All Features](https://anonym.legal/features) [How It Works](https://anonym.legal/how-it-works) **Related Platform:** [anonymize.today](https://anonymize.today/) — Firm-wide-grade PII finding with 256 item types Fit & Limitations #### Best fit and known limitations ##### Best for Legal, audit fit, and rule-bound teams that need verifiable Zero-Knowledge processing with native MCP link-up into Claude Desktop, Cursor, and VS Code; matters where audit trails and 48-language coverage including RTL scripts are non-negotiable. ##### Not the right fit Casual single-user PII scrubbing without audit fit scope (use [anonymize.today](project-anonymize-today.html) rather) or workflows that need image OCR redaction (use [cloak.biz](project-cloak-business.html)). ##### Known limitations The free tier is capped at 200 tokens per month; the deterministic regex layer needs manual tuning for niche jurisdictional formats; ML name finding accuracy varies by language and perks from human review on long-tail surnames. #### Need privacy-first data anonymization? Let's discuss how anonym.legal can support your legal audit fit and Zero-Knowledge needs. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonym.today — Protect Private Data | curta.solutions URL: https://curta.solutions/project-anonym-today.html > Protect personal data automatically: 256+ entity types, 27 languages, 5 protection methods. Web app, desktop, Office add-in, and Chrome extension. Project • SaaS Platform • Privacy Safety ### anonym.today — Protect Your Private Information Before Sharing Find and hide names, addresses, phone numbers, and 256+ other types of private data auto. 27 languages, 5 safety methods — ready as web app, desktop app, Office add-in, and Chrome extension. Zero data storage, zero tracking. SaaS Platform PII Finding Privacy-First 27 Languages Chrome Extension #### Platform Overview **anonym.today** is a consumer-friendly PII finding and PII strip platform designed for simplicity and accessibility. No tough setup, no tracking, no data storage — just paste your text and protect your private info. Ready across multiple platforms including a Chrome extension for real-time browser safety. 256+ Item Types 27 Languages 5 Safety Methods 15 PII Categories Core Skills #### PII Detection & Protection Methods ##### PII Detection Detect 256+ item types across 15 categories including names, emails, phone numbers, credit cards, IBANs, IP addresses, medical terms, and government IDs from multiple countries. ##### 5 Protection Methods - **Partial Hide** — One-way transformation showing limited characters. - **Replace with Label** — Substitutes data with placeholders like [PERSON] - **Use Fake Data** — Generates realistic test info. - **Scramble** — Randomizes touchy content. - **Lock (Encrypt)** — Reversible encoding for secure archival. ##### Multi-Language Support 27 languages including English, German, Spanish, French, Italian, Japanese, Chinese, Korean, Portuguese, Dutch, and more. Auto language finding for mixed-language content. ##### Multi-Platform Access Use anywhere: web app, desktop app (Windows), Microsoft Office add-in (Word, Excel, PowerPoint), and Chrome extension for real-time browser safety. 256+ item types across all platforms. Product Offerings #### Platform Components ##### Web App **Browser-Based Processing** Full-featured web interface. No installation needed — paste text, detect PII, and anonymize instantly. Works on any device with a browser. ##### Desktop App **Windows** Process PDF, DOCX, XLSX, CSV, JSON, XML, and TXT files locally. Encoded local vault for offline skill in touchy setups. ##### Office Add-in **Word, Excel & PowerPoint**. Anonymize directly in Microsoft Office docs. 256+ item types without leaving your document workflow. ##### Chrome Extension Developer Preview **ChatGPT, Claude & Gemini**. Protect your AI conversations auto. Detect and anonymize private data before it reaches AI chatbots. Zero-knowledge safety with reversible encoding. Use Cases #### Who Uses anonym.today ##### Legal Professionals Contract PII strip, e-scan, and court filing redaction. Audit-ready output for rule-set audit fit. ##### Healthcare Workers Patient data safety for medical records, research docs, and administrative comms. ##### Developers Make safe test datasets without live PII exposure. API link-up for CI/CD pipelines and auto-run workflows. ##### Enterprise Teams GDPR audit fit across departments. Batch processing for HR, finance, and ops data safety. ##### Students & Researchers Anonymize interview transcripts, survey data, and research docs for academic publications and thesis work. ##### General Users Protect private info before sharing docs online. Chrome extension for everyday browsing privacy. Systems & Safety #### Privacy-First Architecture ##### Privacy-First Design Zero data storage, zero tracking, zero analytics. Your text is processed and immediately discarded. No logs, no history on our servers. ##### Designed for GDPR Designed for GDPR with EU data residency. Real-time processing without data keep. Data-subject-rights workflows fully supported. ##### End-to-End Encryption All data transmitted over TLS 1.3. Encoding at rest with AES-256-GCM for any stored preferences or account data. ##### German Servers Hosted on ISO 27001-certified servers in Germany. EU law area only — no data leaves the European Union. Pricing #### Simple, Transparent Pricing Start free with 100 tokens per month. Upgrade as you grow. No hidden fees. Annual billing saves 20%. ##### Free €0/month 100 tokens per month. - 5 batch items. - 3 presets - 5 custom items. - 27 languages, 256+ item types. - History & document storage. ##### Basic €3/month 500 tokens per month + token top-ups. - All Free features. - 10 batch items. - 10 presets - 20 custom items. - Token top-ups ready. ##### Pro Most Popular €9/month 2,000 tokens per month. - All Basic features. - 50 batch items. - 50 presets - 100 custom items. - Priority support. ##### Business €29/month 10,000 tokens per month. - All Pro features. - Unlimited batch items. - Unlimited presets. - Unlimited custom items. - Priority support. Access #### Try anonym.today Start with 100 free tokens per month. No credit card needed. Zero data storage, zero tracking. [Try Free — No Signup Needed →](https://anonym.today/) [View All Features](https://anonym.today/features) [How It Works](https://anonym.today/how-it-works) **Related Platform:** [anonymize.today](project-anonymize-today.html) — Firm-wide-grade PII finding with 256 item types, deterministic regex-based processing on ISO 27001-certified servers Fit & Limitations #### Best fit and known limitations ##### Best for Individual professionals who want one-click PII scrubbing before sharing screenshots, draft contracts, or chat exports — no signup, no cloud upload, Windows desktop only. ##### Not the right fit Firm-wide rules, multi-user rollouts, MCP/IDE link-up, or image redaction with OCR (use [anonym.legal](project-anonym-legal.html), [cloak.biz](project-cloak-business.html), or [anonym.plus](project-anonym-plus.html)). ##### Known limitations Windows desktop only; the free tier is capped at 100 tokens per month; coverage is 27 languages rather of the 48 supported by the firm-wide products; no API and no centralised audit logging. #### Need simple, accessible data protection? Let's discuss how anonym.today can help protect private info across your team. [Book a Call](contact.html) [← All Projects](projects.html) --- ## cloak.business — Enterprise PII Platform | curta.solutions URL: https://curta.solutions/project-cloak-business.html > Enterprise PII anonymization + image redaction. 320+ entities, 317 regex, 48 languages. ISO 27001-aligned Hetzner Falkenstein servers. Project • SaaS Platform • Firm-wide Privacy ### cloak.business — Enterprise-Grade PII Detection & Anonymization Regex-first PII safety with 317 deterministic pattern matchers, NLP for names and locations. 320+ item types, 48 languages, image redaction with OCR. Built on Microsoft Presidio. ISO 27001-matched German servers (Hetzner, Falkenstein). SaaS Platform PII Finding Image Redaction 48 Languages MCP Server Microsoft Presidio #### Platform Overview **cloak.biz** is an firm-wide-grade PII finding and PII strip platform built on Microsoft Presidio. Features a regex-first approach with 317 deterministic pattern matchers for set data, complemented by NLP engines for names and locations. Includes image redaction with Tesseract OCR, native MCP Server link-up for AI tools, and Zero-Knowledge sign-in. 320+ Item Types 48 Languages 5 PII strip Methods 317 Regex Matchers Key Differentiators #### What Makes cloak.business Unique ##### Regex-First Detection 317 deterministic pattern matchers process set data (emails, IBANs, credit cards, SSNs) before NLP engines handle names and locations. **Predictable, audit-fit results** with no model drift. ##### Image Redaction Extract text from images using Tesseract OCR in **38 languages**, detect PII, and redact directly on the image. Supports JPEG, PNG, BMP, TIFF, and WebP formats. ##### MCP Server for AI Tools Native link-up with Claude Desktop (stdio), Cursor, and VS Code via Continue and Cline extensions (HTTP). 6 operators: encode, hash, mask, redact, replace, keep. Item groups and presets. ##### Zero-Knowledge Authentication Your password **never leaves your device**. Built with Argon2id + XChaCha20-Poly1305 encoding and AES-256-GCM vault encoding. 24-word recovery phrase for account recovery. Regex-First Approach #### How Detection Works cloak.biz uses a 10-step pipeline that prioritizes deterministic regex matching before engaging NLP engines. Built on Microsoft Presidio. - **Input Reception** — Text received via web app, API, MCP Server, or batch upload. - **Language Finding** — Auto identification of text language for engine selection. - **Regex Scanning** — 317 pattern matchers scan for set PII (emails, IBANs, SSNs, credit cards, phone numbers) - **Checksum Checks** — Found patterns validated using checksums (Luhn, IBAN, SSN format rules) - **Context Enhancement** — Surrounding text analyzed to boost or reduce confidence scores. - **NLP Processing** — spaCy, Stanza, or XLM-RoBERTa processes text for names, teams, and locations. - **Result Merging** — Regex and NLP results merged with conflict resolution (regex wins for set data) - **Confidence Scoring** — Each finding gets a confidence score (0.0 to 1.0) - **PII strip** — Selected method applied: replace, redact, hash, encode, or mask. - **Output Rollout** — Anonymized text returned with finding report and audit trail. // Before cloak.biz "Invoice for John Doe, IBAN DE89 3704 0044 0532 0130 00, email john@example.com..." // After cloak.biz (regex-first) "Invoice for PII_PERSON_001, IBAN PII_IBAN_001, email PII_EMAIL_001..." NLP Technology Stack #### Multi-Engine Language Processing cloak.biz uses three NLP engines optimized for other language families with lazy-loaded models. Regex handles set data, NLP handles names and teams. Built on Microsoft Presidio. ##### spaCy Engine 25 Languages Fast industrial-strength NLP for European languages and major world languages. ##### Stanza Engine 7 Languages Stanford NLP engine for focused language processing and academic accuracy. ##### XLM-RoBERTa Transformer 16 Languages Cross-lingual transformer for low-resource languages and multilingual docs. Core Skills #### PII Detection & Anonymization ##### 320+ Entity Types Names, emails, phone numbers, credit cards, SSNs, IBANs, IP addresses, medical records, and more. 317 regex matchers for set data, NLP-based NER for names and teams. Confidence scoring for all detections. ##### 5 Anonymization Methods - **Replace** — Substitute with fake data. - **Redact** — Full removal. - **Hash** — SHA-256 hashing. - **Encrypt** — AES-256-GCM encoding. - **Mask** — Partial obscuring. ##### 70+ Countries Country-specific matchers for national IDs, tax numbers, social safety numbers, and regional data formats across 70+ countries. ##### Deterministic Results 317 regex matchers give deterministic, reproducible results for set data (same input + same ruleset version). NLP provides high consistency for names. Fully audit-fit for audit fit. No model drift. Image Redaction #### OCR-Powered Image Anonymization Extract text from images, detect PII, and redact directly on the image. Powered by Tesseract OCR. ##### 38 OCR Languages Tesseract OCR extracts text from images in 38 languages, letting PII finding on scanned docs, screenshots, and photos. ##### Supported Formats JPEG, PNG, BMP, TIFF, and WebP. Upload images and receive redacted versions with PII masked or removed. ##### Visual Redaction Found PII is redacted directly on the image with configurable redaction boxes. First text positions preserved for accurate coverage. Rollout Options #### Platform Components ##### Web Application **Cloud-Based Processing** Full-featured web interface with Zero-Knowledge sign-in. No software installation needed. ##### Desktop App **Windows 10+ · macOS** Docs stay on your device while using cloud-powered item finding. Only extracted text is sent for study. AES-256-GCM encoding with Argon2id key derivation. Supports PDF, DOCX, XLSX, TXT, CSV, JSON, XML. ##### Office Add-in **Word, Excel & PowerPoint**. Real-time PII finding directly in Microsoft Office. Anonymize without leaving your document. ##### MCP Server **Claude Desktop, Cursor, VS Code (Continue & Cline)** Native stdio link-up for Claude Desktop. HTTP endpoints for Cursor and VS Code via Continue and Cline extensions. 6 operators with item groups and presets. ##### REST API **JWT Sign-in** RESTful endpoints for workflow auto-work and CI/CD pipeline link-up. ##### Batch Processing **Multi-Document Upload** Multi-document upload with parallel processing. Plan limits apply per tier. ##### Image Redaction **Tesseract OCR — 38 Languages**. Upload images, extract text via OCR, detect PII, and receive redacted images. JPEG, PNG, BMP, TIFF, WebP supported. Use Cases #### Industries & Applications ##### Enterprise GDPR audit fit at scale. Centralized PII finding across departments with role-based access control and batch processing. ##### Developers REST API and MCP Server for CI/CD pipelines. Safe test dataset generation without live PII exposure. ##### Legal Contract PII strip & e-scan. Redact touchy info from court filings and scan docs with audit trails. ##### Healthcare Patient data workflows matched to HIPAA PHI handling. Medical records PII strip for research and administrative docs. ##### Financial PCI-DSS-matched PAN/PII redaction for fraud-prevention workflows. Deal and client data safety with rule-set reporting. ##### Research Anonymize research datasets for publication. Remove private IDs while preserving data utility for study. ##### Government Public records & FOIA audit fit. Auto-run redaction for FOIA requests and inter-agency data sharing. Systems & Safety #### Zero-Knowledge Architecture ##### Password Never Leaves Device True Zero-Knowledge sign-in. Your master password is used locally to derive encoding keys. Server never sees your password. ##### Argon2id + XChaCha20-Poly1305 Argon2id (64 MB / 3 iterations) for memory-hard key derivation; XChaCha20-Poly1305 for authenticated encoding. ##### 24-Word Recovery Phrase BIP-39 compatible recovery phrase for account recovery. No password reset emails — you control your keys. ##### ISO 27001-Aligned Hosted in Hetzner data centers in Germany. Designed for GDPR with EU data residency. AES-256-GCM encoding. TLS 1.2+. Pricing #### Transparent Token System Each operation costs tokens based on text length, items found, and ops applied. ##### Free €0/month 200 tokens per cycle. - Online account. - Analyzer & Anonymizer. - 48 languages - 317 regex matchers. - Image redaction. - No credit card needed. ##### Basic Most Popular €3/month 1,000 tokens per cycle. - All Free features. - API access. - Batch processing. - PDF/DOCX/TXT/CSV support. - Token top-ups ready. ##### Pro Best Value €15/month 4,000 tokens per cycle. - All Basic features. - MCP Server access. - All file types supported. - Unlimited uploads. - Token top-ups ready. ##### Business Enterprise €29/month 10,000 tokens per cycle. - All Pro features. - Priority support. - Custom link-ups. - Extended history. - Token top-ups ready. Platform Comparison #### cloak.business vs anonym.legal vs anonymize.today Three platforms, other strengths. All built for GDPR audit fit on German servers. Feature cloak.biz anonym.legal anonymize.today **Focus** Firm-wide & Developers. Legal & Privacy-First. Simple & Transparent. **Item Types**. 320+ 285+ 258 **Languages** 48 48 + RTL 27 **Regex Matchers**. 317 n/a n/a **Image Redaction**. Yes (38 OCR langs) No No **MCP Server**. Yes Yes No **Zero-Knowledge Auth**. Yes Yes No **Desktop App**. Windows Win/Mac/Linux Win/Mac/Linux **Office Add-in**. Word/Excel/PPT Word/Excel/PPT Word/Excel/PPT **Free Tokens**. 200/cycle 200/cycle 300/month **Technology** Microsoft Presidio. Presidio-based Regex-based [View anonym.legal details →](project-anonym-legal.html)  | [View anonymize.today details →](project-anonymize-today.html) Access #### Try cloak.business Start with 200 free tokens per cycle. No credit card needed. Zero-Knowledge from day one. [Open cloak.biz →](https://cloak.business/) [View All Features](https://cloak.business/features) [How It Works](https://cloak.business/how-it-works) **Related Platforms:** [anonym.legal](https://anonym.legal/) — Zero-Knowledge PII PII strip with MCP Server  |  [anonymize.today](https://anonymize.today/) — Simple, transparent PII finding Fit & Limitations #### Best fit and known limitations ##### Best for Ops and SecOps teams that need image redaction with OCR alongside text PII finding, plus an MCP server for AI tooling, hosted on ISO 27001-matched German servers (Hetzner, Falkenstein). ##### Not the right fit Browser-only or developer-IDE flows (use [anonymize.live](project-anonymize-live.html) or [anonymize.dev](project-anonymize-dev.html)); pure consumer use without audit fit overhead ([anonym.today](project-anonym-today.html) fits better). ##### Known limitations OCR accuracy depends on image quality and language; the free tier is capped at 200 tokens per cycle; 320+ items is an firm-wide-tier catalogue and may exceed simple use-case needs. #### Need enterprise-grade PII detection? Let's discuss how cloak.biz can support your audit fit, image redaction, and API link-up needs. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonymize.dev — Privacy-as-Code | curta.solutions URL: https://curta.solutions/project-anonymize-dev.html > PII privacy layer for AI tools. Detects API keys, credentials, customer data in prompts. MCP Server for Claude & Cursor. 48 languages. ISO 27001. Project • SaaS Platform • Developer Tools ### anonymize.dev — Privacy-as-Code for Developers Privacy layer for developers using AI tools. Auto detects and replaces PII in prompts — API keys, credentials, client data — before they reach outside AI services. 50+ item types, 48 languages, MCP Server for Claude Desktop and Cursor. SaaS Platform Developer Tools MCP Server 48 Languages Zero-Knowledge Credential Finding #### Platform Overview **anonymize.dev** is a privacy layer for developers who use AI tools like Claude Desktop, Cursor, or ChatGPT. It auto detects and replaces personally identifiable info in prompts sent to AI models, then restores first values in responses. Designed for developers who work with real client data, API keys, and systems credentials in their daily AI workflows. 50+ Item Types 48 Languages 5 PII strip Methods Key Differentiators #### What Makes anonymize.dev Unique ##### Credential & Secret Detection Detects API keys, SSH keys, JWT tokens, AWS secrets, OAuth tokens, private keys, client secrets, and database URLs. **Prevents accidental credential leakage** to AI services. ##### MCP Server Integration Native link-up with **Claude Desktop** and **Cursor** via MCP Server. Install via npm package, configure with your API key, and PII is intercepted auto. ##### Zero Data Leakage No real PII ever leaves your machine. AI models only see anonymized tokens. First values are stored locally and restored in responses. ##### Custom Entity Patterns Define your own regex patterns for proprietary IDs — in-house IDs, project codes, client refs. Extend finding beyond built-in item types. MCP Server Workflow #### How It Works anonymize.dev acts as a privacy shield between your AI tools and outside AI services. Four steps, fully auto. - **You Write a Prompt** — Your prompt contains touchy data: client names, API keys, emails, database credentials. - **MCP Server Anonymizes** — PII is found and replaced with tokens (e.g., [PERSON_1], [EMAIL_1], [API_KEY_1]). First values stored locally. - **AI Processes Safely** — Claude, Cursor, or ChatGPT gets only the anonymized version. No real PII ever leaves your machine. - **Response Restored** — Tokens in the AI response are replaced with first values. You get full context back. // Your prompt (before anonymize.dev) "Review the contract for John Smith (john@acme.com), API key sk-1234abcd..." // What AI sees (after anonymize.dev) "Review the contract for [PERSON_1] ([EMAIL_1]), API key [API_KEY_1]..." // AI response (restored) "The contract for John Smith includes..." Finding Categories #### What anonymize.dev Detects ##### Secrets & Credentials - **API_KEY** — API keys and tokens. - **SSH_KEY** — SSH private/public keys. - **JWT_TOKEN** — JSON Web Tokens. - **AWS_SECRET** — AWS access keys. - **DATABASE_URL** — Connection strings. - **OAUTH_TOKEN** — OAuth credentials. - **PRIVATE_KEY** — Private keys. - **CLIENT_SECRET** — Client secrets. ##### Infrastructure & Network - **IP_ADDRESS** — IPv4 and IPv6. - **MAC_ADDRESS** — Hardware addresses. - **HOSTNAME** — Server hostnames. - **URL** — In-house URLs and endpoints. - **FILE_PATH** — File system paths. - **CONTAINER_ID** — Docker/container IDs. ##### Customer PII - **PERSON** — Full names. - **EMAIL** — Email addresses. - **PHONE** — Phone numbers. - **ADDRESS** — Physical addresses. - **CREDIT_CARD** — Card numbers. - **IBAN** — Bank accounts. - **SSN** — Social safety numbers. - **PASSPORT** — Passport numbers. ##### Custom Entities Define your own regex patterns for proprietary IDs. Detect in-house project codes, client reference numbers, and team-specific data formats. Extend the built-in 50+ item types with unlimited custom patterns. Core Skills #### PII Detection & Anonymization ##### 50+ Entity Types Credentials, systems data, client PII, and custom patterns. Purpose-built for developer workflows where code meets client data. ##### 5 Anonymization Methods - **Replace** — Substitute with fake data. - **Redact** — Full removal. - **Hash** — SHA-256 hashing. - **Encrypt** — AES-256-GCM encoding. - **Mask** — Partial obscuring. ##### 48 Languages Detect PII across 48 languages. Handle multilingual codebases, comments, docs, and client data in any language. ##### Automatic Restoration AI responses auto de-tokenized. First values restored seamlessly so you get full context back without manual work. Rollout Options #### Platform Components ##### MCP Server **Claude Desktop & Cursor**. Main link-up method. Install via npx @anonym-legal/mcp-server, add your API key to claude_desktop_config.json or Cursor settings. Auto PII interception. ##### REST API **JWT Sign-in** RESTful endpoints for CI/CD pipeline link-up, auto-run testing setups, and custom workflow auto-work. ##### Desktop App **Drag-and-Drop Processing** Drag files for quick PII strip. Docs stay on your device while using cloud-powered item finding. ##### Office Add-in **Word, Excel & PowerPoint**. Real-time PII finding directly in Microsoft Office. Anonymize docs and specs without leaving your document. Use Cases #### Developer Scenarios ##### AI-Assisted Coding Paste code containing client data into Claude or Cursor without leaking real names, emails, or API keys to outside AI services. ##### Code Review Share code snippets with AI for review without exposing live credentials, database URLs, or systems details. ##### CI/CD Pipelines Integrate via REST API to scan logs, test data, and setup files for PII before they enter version control or shared setups. ##### Test Data Generation Create safe test datasets from live data. Replace real client info with realistic fake data for dev work setups. ##### Documentation Anonymize technical docs, API specs, and in-house wikis before sharing with outside contractors or AI tools. ##### Compliance GDPR audit fit for dev work teams. Ensure no client PII leaks through AI tool usage, code sharing, or log study. Systems & Safety #### Zero-Knowledge Architecture ##### No PII Leaves Your Machine First values stored locally on your device. Only anonymized tokens are sent to AI services. Zero data leakage by design. ##### Zero-Knowledge Authentication Your password never leaves your device. Argon2id key derivation; AES-256-GCM vault encoding. ##### ISO 27001-Aligned Hosted in Hetzner data centers in Germany. Designed for GDPR with EU data residency. ##### npm Package Distribution MCP Server distributed via npm (@anonym-legal/mcp-server). Standard package control, easy updates, transparent dependencies. Pricing #### Transparent Token System All tiers include the same features — API, Desktop App, Office Add-in, and MCP Server. Pay only for load. ##### Free €0/month 200 tokens per cycle. - MCP Server access. - REST API access. - Desktop App. - Office Add-in. - 48 languages - No credit card needed. ##### Basic Most Popular €3/month 1,000 tokens per cycle. - All Free features. - Token top-ups ready. ##### Pro Best Value €15/month 4,000 tokens per cycle. - All Basic features. - Token top-ups ready. ##### Business Enterprise €29/month 10,000 tokens per cycle. - All Pro features. - Priority support. - Token top-ups ready. Platform Comparison #### anonymize.dev vs cloak.business vs anonym.legal Same product family, other focus areas. All hosted on ISO 27001-certified German servers. Feature anonymize.dev cloak.biz anonym.legal **Focus** Developers & AI Tools. Firm-wide & Developers. Legal & Privacy-First. **Item Types**. 50+ 320+ 285+ **Languages** 48 48 48 + RTL **Credential Finding**. Yes (API keys, SSH, JWT, AWS) Yes Limited **Image Redaction**. No Yes (38 OCR langs) No **MCP Server**. Yes (main link-up) Yes Yes **Custom Items**. Yes (regex) Yes Yes **Zero-Knowledge Auth**. Yes Yes Yes **Auto De-tokens**. Yes Optional Optional **Free Tokens**. 200/cycle 200/cycle 200/cycle [View cloak.biz details →](project-cloak-business.html)  | [View anonym.legal details →](project-anonym-legal.html) Access #### Try anonymize.dev Start with 200 free tokens per cycle. All features included. No credit card needed. [Open anonymize.dev →](https://anonymize.dev/) **Related Platforms:** [cloak.biz](https://cloak.business/) — Firm-wide PII finding with image redaction  |  [anonym.legal](https://anonym.legal/) — Zero-Knowledge PII PII strip for legal Fit & Limitations #### Best fit and known limitations ##### Best for Engineers shipping AI-powered features who must keep API keys, credentials, and client data out of LLM prompts — Cursor and Claude Desktop users who want finding inside the IDE before traffic leaves the machine. ##### Not the right fit Long-form document PII strip (use [anonym.legal](project-anonym-legal.html) or [cloak.biz](project-cloak-business.html)); use cases that need 200+ item types or image OCR; non-developer audiences. ##### Known limitations The catalogue is curated to ~50 dev-focused item types rather of the full 320+ firm-wide list; the free tier is 200 tokens per cycle; MCP link-up today targets Claude Desktop and Cursor namely. #### Need privacy-as-code for your dev team? Let's discuss how anonymize.dev can protect your AI workflows and minimize data exposure. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonymize.live — AI Chat Privacy | curta.solutions URL: https://curta.solutions/project-anonymize-live.html > Real-time PII protection for AI chats. Chrome Extension for ChatGPT, Claude & Gemini. 256+ entity types, 27 languages. Zero data storage. GDPR compliant. Project • SaaS Platform • AI Chat Privacy ### anonymize.live — AI Chat Protection Made Simple Protect your privacy in AI chats. Real-time PII finding for ChatGPT, Claude, and Gemini. 256+ item types across 15 categories, 27 languages with RTL support, Chrome Extension (Developer Preview) with live de-PII strip. Zero data storage, zero tracking. SaaS Platform AI Chat Safety Chrome Extension 27 Languages Real-Time Finding Zero Storage #### Platform Overview **anonymize.live** is an AI chat safety platform that auto detects and anonymizes PII before it reaches ChatGPT, Claude, or Gemini. Designed for everyday users who want privacy without depth. Real-time finding as you type, live de-PII strip in responses, and a Chrome Extension (now in Developer Preview) that works directly in AI chat interfaces. Zero data storage, zero tracking. 256+ Item Types 27 Languages 5 Safety Methods 15 Finding Categories Key Differentiators #### What Makes anonymize.live Unique ##### Real-Time Detection PII is found **as you type**, not after submission. Immediate visual feedback shows what's being protected before you send anything to an AI service. ##### Chrome Extension for AI Chats Works directly inside **ChatGPT, Claude, and Gemini**. Zero-knowledge safety with live de-PII strip — AI responses are restored with first data auto. ##### Zero Data Storage Your data **never leaves your control**. No data stored on servers, no tracking, no logs. GDPR audit-fit and end-to-end encoded. ##### Live De-Anonymization AI responses are auto de-anonymized in real time. See the AI's answer with your **first names, addresses, and data restored** seamlessly. How It Works #### Three Simple Steps No technical setup needed. Paste, protect, and download — or use the Chrome Extension for auto AI chat safety. - **Paste Your Text** — Copy your document, email, or any text into the box. You can also drag and drop files. - **We Find Private Info** — The system auto detects names, addresses, phone numbers, and 250+ other private details. - **Download Protected** — Get your protected text instantly. Copy it or download as a file. Safe to share with anyone. // Your message to ChatGPT / Claude / Gemini "Review this contract for Sarah Johnson, email sarah@company.com, SSN 123-45-6789..." // What the AI sees (anonymize.live active) "Review this contract for [PERSON_1], email [EMAIL_1], SSN [SSN_1]..." // AI response (live de-PII strip) "The contract for Sarah Johnson includes..." Finding Categories #### What anonymize.live Detects 256+ item types across 15 categories. Pattern-based precision finding with support for 27 languages including RTL. ##### Names & Contact - First, last, and full names. - Email addresses. - Phone numbers. - Fax numbers. ##### Addresses - Street addresses. - City and state. - Postal codes. - Country names. ##### Financial Data - Credit card numbers. - IBAN / bank accounts. - Account numbers. - Financial IDs. ##### IDs & Documents - Passport numbers. - Social safety numbers. - Tax IDs. - License plates. ##### Medical Records - Health record IDs. - Patient IDs. - Medical reference numbers. - Health insurance IDs. ##### Technical Data - IP addresses. - URLs and domains. - 240+ additional types. - Custom item patterns. Core Skills #### PII Detection & Anonymization ##### 256+ Entity Types Full PII finding across 15 categories. Names, emails, phone numbers, addresses, financial data, IDs, medical records, and 240+ additional types. Pattern-based precision finding. ##### 5 Protection Methods - **Replace** — Substitute with fake data. - **Redact** — Full removal. - **Hash** — SHA-256 hashing. - **Encrypt** — AES-256-GCM encoding. - **Mask** — Partial obscuring. ##### 27 Languages + RTL Detect PII across 27 languages including right-to-left support for Arabic and Hebrew. Auto language finding for multilingual content. ##### High Performance Process up to 1 million characters in seconds. Optimized engine for real-time finding without noticeable delay, even on large docs. Rollout Options #### Platform Components ##### Web Application **Browser-Based, No Installation**. Full-featured web interface. Paste text, drag and drop files, and download protected results. Works in any browser. ##### Chrome Extension **ChatGPT, Claude & Gemini**. Real-time AI chat safety with zero-knowledge safety. Auto PII finding and live de-PII strip directly in AI chat interfaces. ##### Office Add-in **Word, Excel & PowerPoint**. Right-click menu link-up. Anonymize content directly in Microsoft Office with format preservation. Use Cases #### Who Uses anonymize.live ##### AI Chat Users Protect private data when chatting with ChatGPT, Claude, or Gemini. No more worrying about names, emails, or addresses reaching AI servers. ##### Legal Professionals Anonymize court docs and contracts before AI-assisted review. Maintain client privacy while using AI tools. ##### Healthcare Workers HIPAA-aware PII finding for patient data. Anonymize medical records before sharing or AI study. ##### Developers Clean up logs, API responses, and test data. Remove client PII from code snippets before pasting into AI assistants. ##### Enterprises GDPR audit fit for teams using AI tools. Custom item patterns for team-specific data safety needs. ##### Everyday Users Simple privacy safety for anyone sharing text that contains private info. No technical knowledge needed. Privacy & Safety #### Zero-Storage Architecture ##### No Data Stored Your text is never stored on any server. Processing happens and results are shipped — nothing is retained, logged, or tracked. ##### End-to-End Encrypted All data in transit is encoded. Zero-knowledge safety ensures even the service cannot read your content. ##### GDPR Compliant Fully audit-fit with EU data safety rules. Based in Saarbrücken, Germany — EU law area. ##### Zero Tracking No analytics trackers, no usage profiling, no advertising. Your privacy is the product, not the price. Pricing #### Simple Token Plans All plans include 27 languages, 256+ item types, 5 safety methods, and history. Higher tiers unlock more tokens, batch items, presets, and custom items. ##### Free €0/month 100 tokens per month. - 5 batch items. - 3 presets - 5 custom items. - 27 languages - 256+ item types. ##### Basic €3/month 500 tokens per month. - 10 batch items. - 10 presets - 20 custom items. - Token top-ups ready. ##### Pro Most Popular €9/month 2,000 tokens per month. - 50 batch items. - 50 presets - 100 custom items. - Priority support. ##### Business Enterprise €29/month 10,000 tokens per month. - Unlimited batch items. - Unlimited presets. - Unlimited custom items. - Priority support. Platform Comparison #### anonymize.live vs anonym.today vs anonymize.today Three consumer-friendly platforms, other strengths. All focused on simple, accessible PII safety. Feature anonymize.live anonym.today anonymize.today **Focus** AI Chat Safety. Consumer Privacy. Simple & Transparent. **Item Types**. 256+ 256+ 256 **Languages** 27 + RTL 27 27 **Chrome Extension**. Yes (AI chats) Yes Yes (Dev Preview) **Live De-PII strip**. Yes No No **Real-Time Finding**. Yes (as you type) No No **Custom Items**. Yes (up to unlimited) Yes No **Desktop App**. No Windows Win/Mac/Linux **Free Tokens**. 100/month 100/month 300/month **Data Storage**. Zero Zero Minimal [View anonym.today details →](project-anonym-today.html)  | [View anonymize.today details →](project-anonymize-today.html) Access #### Try anonymize.live Start with 100 free tokens per month. No installation needed. Zero data storage from day one. [Open anonymize.live →](https://anonymize.live/) **Related Platforms:** [anonym.today](https://anonym.today/) — Consumer privacy with Chrome Extension  |  [anonymize.today](https://anonymize.today/) — Simple, transparent PII finding Fit & Limitations #### Best fit and known limitations ##### Best for Knowledge workers using ChatGPT, Claude, or Gemini in the browser who want PII intercepted before each prompt is sent — including live de-PII strip of the model's reply inside the chat window. ##### Not the right fit Desktop apps, mobile chat clients, or non-Chromium browsers; document-PII strip workflows; backend API pipelines (use [anonymize.dev](project-anonymize-dev.html) or [anonym.legal](project-anonym-legal.html)). ##### Known limitations Chrome and Chromium-based browsers only; the free tier is capped at 100 tokens per month; coverage is 27 languages and limited to the supported chat sites. #### Need AI chat privacy for your team? Let's discuss how anonymize.live can protect your team's AI workflows with zero data storage. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonymize.solutions — Enterprise PII | curta.solutions URL: https://curta.solutions/project-anonymize-solutions.html > Enterprise PII anonymization: 320+ entities, 48 languages, 3 deploy models. Zero-Knowledge. MCP Server, REST API. Built on Presidio. Project • Firm-wide Platform • Multi-Rollout Privacy ### anonymize.solutions — Enterprise PII Detection & Anonymization Platform The umbrella platform for firm-wide PII safety. 320+ item types, 48 languages, 3 rollout models (SaaS, Run Private, Self-Run). 16 pre-built solution templates from Chrome Extension to Government Multi-Tenant. Zero-Knowledge sign-in (Firm-wide tier). Built on Microsoft Presidio. Firm-wide Platform PII Finding Self-Run 48 Languages MCP Server White-Label #### Platform Overview **anonymize.solutions** is the firm-wide umbrella platform for PII finding and PII strip. It pulls all roll-out models under one roof. Ready as SaaS, Run Private, or fully Self-Run on your own systems. It pairs NLP and Pattern finding engines built on Microsoft Presidio. Plus Zero-Knowledge sign-in. Plus 16 ready solution packs, from healthcare to government. 320+ Item Types 48 Languages 7 PII strip Methods 3 Rollout Models 16 Solution Templates Key Differentiators #### What Makes anonymize.solutions Unique ##### 3 Deployment Models **SaaS, Run Private, or Self-Run.** Pick hosted ease. Or private isolation with run updates. Or full systems control with KMS/HSM link-up. All plans pack both NLP and Pattern finding engines. ##### 16 Solution Templates Ready packs from **5-minute Chrome Extension** roll-out to **firm-wide Multi-Tenant Government** platforms. Healthcare (HIPAA). Legal (e-Scan). Finance (PCI-DSS). School (FERPA). And more. ##### Air-Gapped Desktop **100% offline**. No internet link needed. Local NLP models (spaCy + regex) for 15+ tongues. No account needed. Forever license. Unlimited use. ##### White-Label & Reseller Run Private with **custom branding**. Multi-tenant setup control, reseller partner program, load-based pricing, and per-client preset setup. Three-Step Workflow #### How It Works anonymize.solutions follows a three-step workflow: Analyze, Anonymize, Decrypt. Built on Microsoft Presidio with dual finding engines. - **Analyze** — Find and highlight PII items using NLP Engine (names, teams, locations) and Pattern Engine (emails, IBANs, SSNs, credit cards). 320+ item types across 48 languages. - **Anonymize** — Apply policy-based processing using five methods: Replace (synthetic data), Redact (removal), Mask (partial obscuring), Hash (SHA-256), or Encrypt (AES-256-GCM reversible). - **Decrypt / Unlock** — Tight recovery of encoded values. Role-based decryption keys, department-level access control, and full audit trails for every decryption event. // Before anonymize.solutions "Contract between John Doe, IBAN DE89 3704 0044 0532 0130 00, and Acme Corp..." // After anonymize.solutions (policy-based) "Contract between [PERSON_001], IBAN [IBAN_001], and [ORG_001]..." NLP Technology Stack #### Multi-Engine Language Processing anonymize.solutions uses three NLP engines optimized for other language families. Pattern Engine handles set data, NLP handles names and teams. Built on Microsoft Presidio. ##### spaCy Engine 25 Languages Fast industrial-strength NLP for European languages and major world languages. ##### Stanza Engine 7 Languages Stanford NLP engine for Arabic, Hebrew, Hindi, Indonesian, Persian, Thai, Vietnamese. ##### XLM-RoBERTa Transformer 16 Languages Cross-lingual transformer for low-resource languages and multilingual docs. Rollout Models #### SaaS, Managed Private, or Self-Managed ##### Online Hosted (SaaS) **Fast time-to-value** Run service with hosted ops. Optional Firm-wide IAM/SSO. Zero systems to manage. ##### Managed Private **Private isolation, run updates**. Set setup with client-side key control option. White-label ready. Run updates and tracking. ##### Self-Managed **Full systems control**. Deploy on your own systems. Client tracking, KMS/HSM link-up. Air-gapped option ready. Core Skills #### PII Detection & Anonymization ##### 320+ Entity Types Names, emails, phone numbers, credit cards, SSNs, IBANs, IP addresses, medical records, and more. NLP Engine for names and teams, Pattern Engine with checksum checks (Luhn, MOD 97) for set data. ##### 7 Anonymization Methods - **Replace** — Synthetic data substitution. - **Redact** — Full removal. - **Hash** — SHA-256 one-way. - **Encrypt** — AES-256-GCM reversible. - **Mask** — Partial obscuring. ##### Compliance Presets - **GDPR** — EU private data safety. - **HIPAA** — 18 PHI IDs. - **PCI-DSS** — Payment card data. ##### Image Anonymization Optional OCR-powered image processing. Tesseract OCR extracts text from JPEG, PNG, TIFF, BMP, WebP, GIF. 25+ item types detectable in images. Link-up Suite #### Platform Components ##### Web Application **Cloud-Based Processing** Full-featured web interface with Zero-Knowledge sign-in. No software installation needed. ##### Desktop App **Windows, macOS & Linux**. Local document processing with cloud-powered finding. Supports PDF, DOCX, XLSX, TXT, CSV, JSON, XML. Batch processing up to 100 files. ##### Air-Gapped Desktop **100% Offline** No internet connection needed. Local spaCy + regex models for 15+ languages. No account needed. Perpetual license, unlimited processing. ##### Office Add-in **Word, Excel & PowerPoint**. Inline PII highlighting and one-click PII strip directly in Microsoft Office. Policy-based processing. ##### MCP Server **Claude Desktop, Cursor, VS Code**. 7 focused tools: analyze_text, anonymize_text, analyze_document, anonymize_document, list_presets, list_entities, get_status. npm install rollout. ##### REST API **JWT Sign-in** RESTful endpoints for workflow auto-work and CI/CD link-up. 100 req/min (Professional), configurable limits (Firm-wide). Max 50MB per request. ##### Chrome Extension **AI Chat Safety**. Real-time PII interception for ChatGPT, Claude, Gemini, Perplexity, Copilot. Auto-anonymize on paste. Auto response de-PII strip. ##### Batch Processing **Multi-Document Upload** Process up to 100 docs per batch. CSV summary exports, JSON metadata, ZIP archive creation. Solution Templates #### 16 Pre-Built Solutions Ready-to-deploy solutions from 5-minute setup to firm-wide-grade rollouts. ##### Quick Start (5 min – 1 hour) - **Chrome Extension** — MDM or manual rollout. - **MCP Server** — npm install for AI tools. - **AI Application Dev** — API middle-tier for LLMs. - **Ticketing Systems** — HelloPSA, ConnectWise, Freshdesk. - **Event Platforms** — Eventbrite, Cvent, Hopin. ##### Standard (1 day – 1 week) - **Workflow Auto-work** — n8n, Make, Zapier + local AI. - **File Share Encoding** — SharePoint, Dropbox, network shares. - **Document Processing** — HR, legal, healthcare batch. - **Source Safety** — Journalism, investigations. - **White-Label** — MSP, legal tech, IT consultancy. ##### Enterprise (2+ weeks) - **Healthcare** — workflows matched to HIPAA PHI handling. - **Education** — designed for FERPA, COPPA, and IRB workflows. - **Legal** — e-Scan, M&A data rooms. - **Financial** — PCI-DSS, KYC/AML, info barriers. - **Insurance** — Claims, fraud finding, reinsurance. - **Government** — FOIA, inter-agency, multi-tenant. Industries & Applications #### Use Cases ##### Enterprise GDPR audit fit at scale. Centralized PII finding across departments with role-based access control, batch processing, and department-level encoding keys. ##### Healthcare HIPAA-matched preset covering 18 PHI IDs. Clinical research de-identification, telemedicine PII safety, healthcare AI workflow guardrails. ##### Legal e-Scan document live, privilege log auto-generation, M&A data room key control, per-matter encoding isolation. ##### Financial PCI-DSS-matched PAN/PII redaction, KYC/AML document processing, info barriers for trading/research, fraud pattern study with alias-swap. ##### Government FOIA request auto-work, inter-agency data sharing with barriers, field-level encoding control, epidemic surveillance alias-swap. ##### MSP & Resellers White-label platform for run service vendors. Multi-tenant control, per-client presets, PSA billing link-up, reseller partner program. Systems & Safety #### Zero-Knowledge Architecture ##### Zero-Knowledge Processing Text processed entirely in memory and immediately discarded. No disk storage, no AI model training, no third-party sharing, no data transfer outside EU. ##### Argon2id + XChaCha20-Poly1305 Memory-hard key derivation with modern authenticated encoding. AES-256-GCM vault encoding. 24-word BIP39 recovery phrase. 2FA/TOTP support. ##### Enterprise Authentication Zero-Knowledge Proof (Firm-wide tier), OAuth 2.0 (Google/Microsoft SSO), bcrypt (Professional), GeoIP session binding, 5-attempt lockout. ##### ISO 27001 & GDPR EU-based systems on Hetzner’s ISO 27001-certified data centers. ISO 27001-matched controls on Professional; client-funded ISMS cert path ready on Firm-wide. OWASP Top 10 hardened. TLS 1.3. Platform Comparison #### anonymize.solutions vs cloak.business vs anonym.legal Firm-wide rollout flexibility meets focused platform skills. All built on Microsoft Presidio with EU hosting. Feature anonymize.solutions cloak.biz anonym.legal **Focus** Firm-wide Umbrella Platform. Firm-wide & Developers. Legal & Privacy-First. **Item Types**. 260+ 320+ 260+ **Languages** 48 + RTL 48 48 + RTL **Rollout Models**. SaaS / Private / Self-Run. SaaS SaaS **Air-Gapped Desktop**. Yes (15+ langs, offline) No No **White-Label** Yes No No **Image Redaction**. Optional (OCR) Yes (38 OCR langs) No **MCP Server**. Yes (7 tools) Yes Yes **Zero-Knowledge Auth**. Yes (Firm-wide) Yes Yes **Desktop App**. Win/Mac/Linux Windows Win/Mac/Linux **Chrome Extension**. Yes No No **Audit fit Presets**. GDPR, HIPAA, PCI-DSS. GDPR GDPR **Pricing** Contact Sales. From €0/month. From €0/month. **Technology** Microsoft Presidio. Microsoft Presidio. Presidio-based [View cloak.biz details →](project-cloak-business.html)  | [View anonym.legal details →](project-anonym-legal.html) Access #### Explore anonymize.solutions Firm-wide rollout options for rule-bound industries. Contact us for a tailored assessment of your PII safety needs. [Open anonymize.solutions →](https://anonymize.solutions/) [View All Solutions](https://anonymize.solutions/solutions.html) [Link-ups](https://anonymize.solutions/integrations.html) **Related Platforms:** [cloak.biz](https://cloak.business/) — Firm-wide-grade PII finding with image redaction  |  [anonym.legal](https://anonym.legal/) — Zero-Knowledge PII PII strip with MCP Server  |  [anonymize.today](https://anonymize.today/) — Simple, transparent PII finding Fit & Limitations #### Best fit and known limitations ##### Best for Enterprises that need to choose between SaaS, Run Private, and Self-Run rollout, want pre-built solution templates, and need white-label or air-gapped operation alongside zero-knowledge design. ##### Not the right fit Quick proof-of-concept work ([anonymize.today](project-anonymize-today.html) is faster to start), single-developer use ([anonymize.dev](project-anonymize-dev.html) fits better), or workflows that do not need template-based industry packs. ##### Known limitations Self-Run and Run Private rollouts need set systems planning and longer onboarding; pricing is contact-sales rather than self-serve; white-label work is scoped per buy-in. #### Need enterprise-grade PII protection? Let's discuss how anonymize.solutions can support your audit fit needs with the right rollout model for your team. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonym.life — ZK Privacy Middleware | curta.solutions URL: https://curta.solutions/project-anonym-life.html > Zero-Knowledge PII platform for enterprise transactions. BYOK, MPC threshold custody, checksum validation, pseudonymization. GDPR compliant. Project • Firm-wide Platform • Privacy Middle-tier ### anonym.life — Privacy Middleware for Transaction Systems Zero Knowledge PII finding platform for firm-wide deal systems. 390+ item types, 317 regex matchers for auto private data finding. Policy-based alias-swap and narrow release. Client-run keys (BYOK), MPC threshold holding, checksum checks, and audit trail logging. Your keys, your data — we can't access it. Firm-wide Platform Zero Knowledge Privacy Middle-tier BYOK MPC Holding GDPR #### Platform Overview **anonym.life** is a privacy middle-tier (intelligent proxy) between data vendors (end users, patients, clients) and service vendors (labs, rollout services, e-commerce, processors). It detects touchy info in set and unstructured payloads, transforms data according to configurable presets, vaults ID mappings with firm-wide key control, distributes sanitized objects to downstream systems, and lets narrow release only when needed — with strong access rules, short-lived grants, and fixed audit proof. **Outcome:** Downstream systems store and process less toxic PII, reducing breach impact and simplifying audit fit and safety ops — without breaking biz workflows. 390+ Item Types 5 Pipeline Steps M-of-N Threshold Holding 4 Industry Presets Problem Statement #### Why This Exists Teams routinely move direct IDs (names, phones, addresses, IDs) through many systems and vendors. anonym.life reduces the exposure footprint by separating ID data from deal data. ##### Large Breach Blast Radius Too many databases and logs contain "toxic data". When every system has the same PII, **one breach becomes total breach**. ##### High Liability & Compliance Burden Data subject access, deletion, keep, processor controls — every link-up needs its own **privacy and safety hardening**. ##### Operational Friction Safety reviews, audits, incident response, and fix **scale with exposure footprint**. Every new vendor increases scope. ##### Hidden Costs Link-up depth, vendor onboarding delays, scattered PII handling across apps — **costs grow with every system that touches ID data**. Core Pipeline #### How anonym.life Works Five steps that separate ID from deals. Policy-based alias-swap between data vendors and service vendors. - **Detect** — Find candidate touchy items and classify them by category and risk level. PII finding in set and unstructured content with confidence scores per recognizer and support for custom matchers. - **Transform** — Apply transformations according to a chosen preset (policy package): redact, mask, generalize, tokenize, or encode-to-recipient. - **Vault** — Store "additional info" (mappings, IDs, keys) in a strongly protected domain. Encoded blobs, token mapping tables, policy receipts, and integrity hashes. - **Distribute** — Downstream service gets a sanitized object via API or gate. Most workflows full without raw IDs. - **Disclose** — Tight, time-limited re-identification when legally or operationally needed. Every reveal needs strong sign-in, purpose declaration, rate limiting, and fixed audit proof. // Inbound payload from data vendor "Deliver to Sarah Johnson, Hauptstraße 12, 66130 Saarbrücken, phone +49 681 12345" // Sanitized object to rollout service (after preset transformation) "Deliver to [TOKEN_7a3f], [ZONE_CENTRAL], relay [RELAY_CHANNEL_42]" // ID data vaulted separately (encoded, access-tight) "Vault: TOKEN_7a3f → [encoded blob] → KEK in client KMS" Key Skills #### Core Features ##### Zero Knowledge Architecture Your keys, your data — we can't access it. anonym.life never stores client KEKs in plaintext. Per-tenant and per-preset key encoding keys with standardized rotation schedules. ##### Pattern-Based PII Detection 390+ item types, 317 regex matchers for auto private data finding. Confidence scores per recognizer, support for custom matchers, and industry tuning for healthcare, finance, and logistics. ##### Customer-Managed Keys (BYOK) Wrap encoding with client-tight KMS/HSM. Each PII record encoded with a DEK, wrapped by a KEK stored in client-tight systems. Supports rotation, revocation, and separation of duties. ##### MPC Threshold Custody No single party can independently decrypt or grant re-identification. Threshold cryptography with M-of-N shares distributed across independent trust domains. Typical setups: 2-of-3 or 3-of-5. ##### Checksum Validation Built-in checks for set IDs using Luhn algorithm (credit cards) and IBAN checksum verification. Reduces false positives through mathematical checks of found items. ##### Audit Trail Logging Fixed audit log (append-only) with proof exports. Every release event records timestamp, requester ID, purpose declaration, attributes revealed, grant TTL, and integrity hash. Safety & Key Control #### Enterprise-Grade Key Management Your keys. Your control. Our enforcement. Multiple holding modes from firm-wide starting point to high-assurance threshold ops. ##### Baseline: Envelope Encryption **Client-Run KMS/HSM** Per-tenant and per-preset KEKs. Per-object DEKs. Standardized key rotation schedules. Break-glass flows with strict sign-offs and post-event review. Maps to procurement expectations for rule-bound clients. ##### High-Assurance: Threshold/MPC **M-of-N Shares Across Trust Domains**. Shares distributed across: (1) Client domain (KMS/HSM or TEE), (2) anonym.life domain (HSM-backed, cannot act alone), (3) Independent trustee or audit fit escrow. Strong safety against insider risk. ##### Selective Disclosure **Purpose-Bound, Time-Limited** Every reveal needs: strong sign-in & access rules, purpose declaration and policy match, time-bounded grants (JIT), rate limiting and anomaly finding, fixed audit proof. ##### Audit Anchoring **Optional Tamper-Evident Ledger**. Hashes of preset versions, policy decisions, release grants, and reveal receipts anchored to a permissioned ledger. No secrets on-chain — only hashes and timestamps for cross-team trust. Use Cases #### Industry Presets Pre-built presets for logistics, healthcare, e-commerce, and payments. Each preset defines finding thresholds, transformations, release rules, keep schedules, and audit needs. ##### Logistics & Delivery **Service vendor gets:** Order contents, rollout zone, drop-off token, relay contact channel. **Vault protects:** Name, phone, exact address. Driver uses token + relay. Exact address revealed only if operationally needed, time-limited, logged. ##### Healthcare & Diagnostics **Service vendor gets:** Sample token, test order metadata, study pipeline IDs. **Vault protects:** Patient ID, DOB, insurance IDs, special category fields. Referring physician re-identifies for clinical purpose, fully audited. ##### E-Commerce **Service vendor gets:** Order details, rollout tokens, anonymized client refs. **Vault protects:** Client profiles, payment details, browsing history. Downstream analytics and vendors operate on sanitized objects only. ##### Payment Processing **Service vendor gets:** Amount, deal token, merchant refs. **Vault protects:** Buyer ID and profile beyond what the processor needs. Strict tokens boundaries and purpose-limited sharing. Preset Engine #### Policy-Driven Transformation A **preset** is a policy package that defines finding thresholds, transformations, release rules, keep, and audit events. Each preset controls the full lifecycle of PII within a deal flow. ##### Preset Template - Name, industry pack, law area, risk tier. - Item label set + transformation rules per type. - Confidence thresholds and fallbacks. - Allowed takers and purposes. - Release rules: who, what, max duration, sign-offs. - Keep and deletion schedule. - Audit events + proof exports format. - Exception handling and manual review paths. ##### Transformation Methods - **Redact** — Full removal of found items. - **Mask** — Partial obscuring with visible structure. - **Generalize** — Reduce precision (city rather of address) - **Tokenize** — Replace with non-reversible tokens. - **Encrypt-to-Recipient** — Targeted encoding for authorized parties. ##### Operational Guardrails - "Deny by default" release posture. - Fine-grained scopes: attribute-level and object-level. - Audit-first: fixed logs + proof exports. - Backpressure on uncertainty: low-confidence triggers minimize/block. - Fail-safe behavior: mask/minimize rather than pass-through. Biz Value #### Measurable Impact Reduce breach impact. Simplify audit fit. Keep workflows running. ##### Reduced Breach Impact Fewer systems with direct IDs. Attackers obtain less actionable ID data. Measurable reduction of plaintext IDs across downstream systems. ##### Control Consolidation Replaces scattered, inconsistent PII handling across apps and vendors. Fewer systems "in scope" for touchy IDs. Reduced link-up depth. ##### Compliance Acceleration Presets encode minimization, keep, and release policies. Proof exports aid audits and DPIAs. Better purpose limitation and data minimization enforcement. ##### Faster Integration Standardized presets shorten safety reviews and link-up cycles. Reduced vendor onboarding time. Workflows remain functional via tokens, relay channels, and JIT grants. Pricing #### Simple, Transparent Pricing Pay for what you protect. Scale as you grow. ##### Starter €499/month 100,000 deals per month. - 390+ item types, 317 regex matchers. - Preset engine with policy DSL. - Vault with wrap encoding. - Client KMS link-up. - Fixed audit log. - API gate + SDKs. ##### Professional Recommended €1,999/month 1,000,000 deals per month. - All Starter features. - Key rotation & revocation workflows. - Break-glass + sign-offs. - Anomaly finding for release abuse. - Multi-region reliability. - Priority support. ##### Enterprise Custom Contact Sales Unlimited deals - All Professional features. - Threshold/MPC holding mode. - Optional ledger anchoring. - Industry-specific presets. - Set support & SLA. - Audit fit readiness program. Rival Positioning #### anonym.life vs Alternatives Unlike old-style tokens vendors or encoding-only solutions, anonym.life provides policy-driven alias-swap with firm-wide key control, fixed audit proof, and purpose-bound narrow release. Rival Their Focus. anonym.life Edge. **VGS** Card data tokens. Handles all PII types with policy-driven presets, not just payments. **Skyflow** Data privacy vault. Middle-tier, not storage — integrates without design overhaul. **Evervault** Encoding systems. Alias-swap + narrow release, not just encoding. **Basis Theory**. Developer tokens. Firm-wide rules with audit proof and audit fit tooling. **Build In-House**. Custom solutions. Battle-tested presets, faster time-to-audit fit, ongoing evolution. Positioning #### How anonym.life Differs from Our PII Detection Platforms **anonym.life** is **firm-wide middle-tier** — a privacy proxy that sits between data vendors and service vendors, separating ID from deal data at the systems level. It is in core other from our user-facing PII finding and PII strip platforms. Our other platforms ([anonymize.solutions](project-anonymize-solutions.html), [anonym.legal](project-anonym-legal.html), [cloak.biz](project-cloak-business.html), [anonym.today](project-anonym-today.html), etc.) are **tools for users** who paste text, upload docs, or use browser extensions to detect and anonymize PII. anonym.life, by contrast, is **systems for teams** that need to control PII flow across their entire link-up landscape — with vaulting, tokens, policy presets, firm-wide key control, and audit-fit narrow release. Access #### Get Started with anonym.life See anonym.life in action with your data. Request a demo to explore how policy-driven alias-swap can reduce your team's PII exposure footprint. [Open anonym.life →](https://anonym.life/) [Request Demo](contact.html) **Related Platforms:** [anonymize.solutions](project-anonymize-solutions.html) — Firm-wide PII finding & PII strip  |  [anonym.legal](project-anonym-legal.html) — Zero-Knowledge PII PII strip with MCP Server Fit & Limitations #### Best fit and known limitations ##### Best for Enterprises with deal-system data flows — B2B platforms, healthcare/fintech alias-swap pipelines, logistics and e-commerce processors — that need policy-based alias-swap and narrow release between data vendors and service vendors, with BYOK and MPC threshold holding so the platform itself cannot read protected fields. ##### Not the right fit Single-user desktop workflows (use [anonym.plus](project-anonym-plus.html)), bulk image redaction with OCR (use [cloak.biz](project-cloak-business.html)), or teams looking for a self-hosted on-premises rollout — anonym.life ships as run middle-tier. ##### Known limitations SaaS-only rollout today; link-up needs API work on each downstream service; BYOK + MPC holding add ops depth versus single-key vaults; the €499/month Starter tier sets a meaningful minimum spend versus consumer tools. #### Need privacy middleware for your transaction systems? Let's discuss how anonym.life can reduce breach impact, simplify audit fit, and keep your workflows running. [Book a Call](contact.html) [← All Projects](projects.html) --- ## anonym.plus — Offline PII Anonymization | curta.solutions URL: https://curta.solutions/project-anonym-plus.html > 100% offline PII anonymization. 340+ entities, 48 UI / 44 NLP languages, OCR. Presidio + spaCy. AES-256-GCM vault. No uploads, no cloud. Project • Desktop App • Offline PII Detection ### anonym.plus — Your Documents Never Leave Your Computer Detect and anonymize PII in documents and images entirely on your machine. No uploads, no cloud processing, no internet needed. Bundled Presidio + spaCy NLP engine with 340+ entity types, 48 UI languages (44 NLP detection languages), 7 document formats plus images with OCR. Encrypted local vault with AES-256-GCM. Built on Microsoft Presidio. Desktop App 100% Offline 340+ Entity Types 48 UI / 44 NLP Languages Encrypted Vault MCP Server #### Platform Overview **anonym.plus** is a 100% offline desktop application for PII detection and anonymization. The entire PII detection and anonymization pipeline runs locally. A bundled Presidio NLP engine handles entity recognition. Rust-native operators handle anonymization. No data ever touches an external server. No account needed for basic use. No internet required. **Dual-engine architecture:** Python-based NLP for detection. Rust-native operators for anonymization. Both bundled in a single installer. 340+ Entity Types 48 / 44 UI / NLP Languages 7+ Document Formats 5 Anonymization Methods Offline Architecture #### Complete Offline Processing Every step runs 100% on your machine. No data sent to any server at any point in this process. ##### No Uploads Files stay on your disk. The complete PII detection and anonymization pipeline runs on your machine. No internet connection needed. No data sent to any external server. ##### No Internet Works without Wi-Fi. English NLP model is pre-installed. No Python, no setup, no dependencies. Just install and go. 20+ additional language models available for download. ##### Local NLP Engine A full Presidio + spaCy NLP engine ships with the app. No external API calls for PII detection. The NLP engine runs as a local sidecar process on localhost only. ##### Encrypted Vault AES-256-GCM local storage. Processing history, settings, and keys stored in an encrypted vault. Secured by a 24-word BIP39 recovery phrase. PIN quick-unlock for daily use. Processing Pipeline #### How anonym.plus Works Four steps, all running locally on your machine. No data sent to any server at any point. - **Extract** — Text pulled from PDF, DOCX, XLSX, CSV, JSON, XML, TXT, or images (OCR). All parsing runs locally - **Detect** — Presidio + spaCy analyze text for 340+ PII entities with confidence scores. Local NLP engine, no API calls - **Review** — You see every detected entity and toggle each one. Full control over what gets anonymized - **Anonymize** — Rust-native operators apply your chosen method (Replace, Redact, Mask, Hash, or reversible AES-CBC Encrypt for Presidio compatibility; the local vault itself uses AES-256-GCM). Document rebuilt in original format on your disk // Original document content "Contract for John Smith, email john@mail.com, card 4111-1111-1111-1111" // After local NLP detection + Rust anonymization "Contract for , email ███████, card XXXX-XXXX-XXXX-1111" // Processed entirely on your machine — zero network traffic Core Features #### Production-Grade Anonymization Without the Cloud Everything runs on your machine. No accounts needed for basic use. No internet required. ##### Bundled NLP Engine A full Presidio + spaCy NLP engine ships with the app. English is pre-installed. No Python, no setup, no dependencies. Just install and go. ##### 340+ PII Entity Types Detect names, emails, phones, credit cards, SSNs, IBANs, passports, tax IDs, medical records, and 190+ more across all global regions. ##### 7 Document Formats + Images PDF, DOCX, XLSX, TXT, CSV, JSON, XML plus images (PNG, JPG, BMP, TIFF) with OCR text extraction in 38 languages. ##### Reversible Encryption Encrypt PII with AES-256-GCM instead of removing it. Deanonymize later with your key. Manage multiple encryption keys for different use cases. ##### Encrypted Local Vault Processing history, settings, and keys stored in an AES-256-GCM encrypted vault. Secured by a 24-word BIP39 recovery phrase. PIN quick-unlock for daily use. ##### Batch Processing Process multiple files at once. Customizable filename patterns, summary exports (JSON/CSV), and per-entity anonymization rules. ##### 48 UI / 44 NLP Languages Full UI in 48 languages with RTL support. PII detection in 44 languages (23 spaCy + 21 transformer models). English bundled, additional NLP models download on-demand. ##### AI Privacy (MCP Server) Connect Cursor, Claude Desktop, or other AI tools via MCP. Automatically anonymize PII before sending to AI, restore in responses. ##### Image Redaction OCR-based text extraction from images with visual bounding-box redaction. Customizable fill colors. Automatic EXIF orientation handling. Anonymization Methods #### Five Operators, All Running Locally in Rust Mix and match methods per entity type within a single document. ##### Replace **Substitute with placeholder** John Smith → ##### Redact **Remove completely** john@mail.com → ███████ ##### Mask **Partially hide** 4111-1111-1111 → XXXX-XXXX-1111 ##### Hash **One-way SHA-256** Max Muster → a3f2b8c1... ##### Encrypt **Reversible AES-256-GCM** secret → eyJhbGci... Document Support #### Supported Formats Process any document type — all locally. Files read and reconstructed on your machine. Never uploaded anywhere. ##### Documents - **PDF** — up to 50 MB - **DOCX** — up to 30 MB - **XLSX** — up to 100k rows - **TXT** — up to 30 MB ##### Data Formats - **CSV** — up to 30 MB - **JSON** — up to 30 MB - **XML** — up to 30 MB ##### Images (OCR) - **PNG, JPG, BMP, TIFF** - Image OCR via bundled Tesseract - Visual bounding-box redaction - Automatic EXIF orientation Global Coverage #### 340+ PII Entity Types, Detected Offline Country-specific entities for regulatory compliance. All detection runs on the local NLP engine. ##### Universal Entities - Person, Email, Phone - Location, Date, URL - IP Address ##### Financial - Credit Card, IBAN - SWIFT/BIC - Bitcoin, Ethereum ##### United States - SSN, ITIN, DEA - Driver License, Passport - Bank Number ##### Europe (DACH) - Tax ID, ID Card - Passport, Social Insurance - Driver License ##### Healthcare - Medical License, ICD Code - NDC Code, Medicare - Health Card ##### Asia Pacific - My Number (JP), Resident ID (CN) - RRN (KR), Aadhaar (IN) - NRIC (SG) Detection Presets #### Pre-Configured for Compliance Standards Start with a built-in preset or create custom ones with your own entity selection and confidence thresholds. ##### General PII Detection Names, emails, phones, addresses, dates and more. 10 entity types • 0.85 threshold ##### GDPR Compliance EU data protection: all GDPR-relevant personal data. 10 entity types • 0.90 threshold ##### HIPAA Medical Patient data, medical records, protected health info. 9 entity types • 0.90 threshold ##### Financial Services Credit cards, IBANs, tax IDs, account numbers. 10 entity types • 0.95 threshold ##### Multi-Language European Entity types across EU member states and regional IDs. 9 entity types • 0.85 threshold ##### Custom Presets Any combination of 340+ entity types with custom thresholds. Unlimited • Configurable Security & Privacy #### Offline-First. Encrypted at Rest. Zero-Knowledge. Your data never leaves your control. We can't access your vault — even if we wanted to. ##### Offline First **No Cloud Dependencies** The complete PII detection and anonymization pipeline runs on your machine. No internet connection needed. No data sent to any external server. Documents stay on your disk. ##### Vault Encryption **AES-256-GCM + Argon2id** Local vault encrypted with AES-256-GCM. Keys derived from your 24-word BIP39 recovery phrase using Argon2id (64 MB memory, 3 iterations). Keys zeroed from memory when locked. ##### Zero-Knowledge **Password Never Leaves Device** With ZK authentication, passwords derive cryptographic keys locally. Only proofs go to the server. We never see, store, or transmit your password. ##### Local Processing **Bundled NLP Engine** Presidio + spaCy ship inside the installer. No external API calls for PII detection. The NLP engine runs as a local sidecar process on localhost only. ##### Recovery **24-Word BIP39 Phrase** 256 bits of entropy via standard BIP39 mnemonic. Recover your vault on any device. Optional PIN (4-8 digits) for daily quick unlock. ##### Deterministic **Regex-Based, Not AI** PII detection uses regex pattern matching via Microsoft Presidio. Same input, same output, every time. Fully auditable for regulatory compliance. Positioning #### How anonym.plus Differs from Our SaaS Platforms **anonym.plus** is the **only fully offline desktop application** in the curta.solutions project ecosystem. While our SaaS platforms ([anonymize.solutions](project-anonymize-solutions.html), [anonym.legal](project-anonym-legal.html), [cloak.business](project-cloak-business.html), [anonym.today](project-anonym-today.html), etc.) process data via cloud infrastructure on ISO 27001-certified German servers, anonym.plus runs the **entire pipeline locally** — bundled NLP engine, Rust-native anonymization operators, and encrypted vault — with zero network traffic. This makes anonym.plus ideal for **air-gapped environments**, **classified document handling**, and organizations where data must never leave the local machine under any circumstances. Access #### Download anonym.plus No account needed. No internet required. English NLP model included. Your documents never leave your computer. [Download for Windows →](https://anonym.plus/) [Visit anonym.plus](https://anonym.plus/) Windows, macOS, and Linux builds shipping today (see desktop_app CHANGELOG). Built on Microsoft Presidio. **Related Platforms:** [anonymize.solutions](project-anonymize-solutions.html) — Enterprise SaaS platform  |  [anonym.today](project-anonym-today.html) — Consumer web app  |  [anonymize.dev](project-anonymize-dev.html) — Developer privacy tools Fit & Limitations #### Best fit and known limitations ##### Best for Teams that must process documents 100% offline — defence, healthcare, classified projects — and want a single-machine appliance with no cloud round-trip and no admin server. ##### Not the right fit Centralised multi-user workflows or API-driven pipelines (use [cloak.business](project-cloak-business.html) or [anonym.life](project-anonym-life.html)); browsers, mobile, or anything that has to run inside a SaaS context. ##### Known limitations Per-machine licensing means there is no central audit trail across endpoints; OCR throughput is bounded by the host CPU/GPU; the Presidio-compatible Encrypt operator uses AES-CBC (the local vault separately uses AES-256-GCM). #### Need offline PII protection for your organization? Let's discuss how anonym.plus can provide air-gapped document anonymization without any cloud dependencies. [Book a Consultation](contact.html) [← All Projects](projects.html) --- ## anonymize.education — Protect Student Data | curta.solutions URL: https://curta.solutions/project-anonymize-education.html > PII anonymization for schools. 320+ entity types, 48 languages, 5 methods. Desktop, Office add-in, MCP Server. GDPR, FERPA aligned. Free to start. Project • Education Platform • Student Data Safety ### anonymize.education — Protect Student Data. Keep Education Safe. The simple way for schools and universities to anonymize private info. 320+ item types, 48 languages, 5 PII strip methods. Desktop app, Office add-in, OpenOffice add-in, and MCP Server for AI tools. No technical skills needed. Designed for GDPR, FERPA-matched, hosted on ISO 27001-matched systems (Hetzner). SOC 2 Type II in progress (Q2 2026 target). Free to start. Education Platform Student Privacy 320+ Item Types 48 Languages GDPR & FERPA ISO 27001 #### Platform Overview **anonymize.education** is the education-focused portal for data PII strip tools. It helps schools, universities, and educational institutions protect student data, research data, and administrative records while maintaining GDPR and FERPA audit fit. Designed for educators with no technical skills needed — upload or paste a document, click anonymize, share safely. **Parent Platform:** Built on the [anonym.legal](project-anonym-legal.html) engine. Finding uses Microsoft Presidio with deterministic regex-based pattern matching — no AI/ML, same input produces same output every time, fully audit-fit for rule-set audit fit. 320+ Item Types 48 Languages ISO 27001 Matched Systems The Problem #### Schools Handle Sensitive Data Every Day Student names, grades, health records, contact info — touchy data lives across schools, registrars and research teams. The platform anonymises it before it leaves the institution. ##### Student Information Names, email addresses, phone numbers, dates of birth, student IDs, home addresses — auto found and protected. ##### Staff Records Employee names, tax IDs, bank account numbers (IBAN), social safety numbers — keep personnel data private. ##### Academic Documents Anonymize transcripts, evaluations, and reports before sharing with outside parties or using with AI tools. ##### International Schools 48 languages supported including Arabic, Chinese, and Hebrew. Works with any student population. How It Works #### Three Simple Steps Three simple steps to protect private info. No training needed. - **Upload or Paste** — Open a document (PDF, Word, Excel) or paste text directly. Drag and drop works too. - **Click Anonymize** — The system finds all private data auto. Choose how to protect it: replace, hide, or encode. - **Share Safely** — Download the protected document or copy the text. Ready to share without privacy worries. // First student record "Emma Wilson, Grade 10, DOB 2010-03-15, parent email wilson@family.com" // After PII strip (Replace method) "[STUDENT_1], Grade 10, DOB [DATE_1], parent email [EMAIL_1]" // Academic data preserved, private data protected Products #### Choose Your Tool Other ways to protect data — pick what works best for your school. All tools use the same powerful PII strip engine. ##### Desktop App FREE **Works on your computer. No internet needed.** Drag-and-drop document processing. Batch processing for multiple files. Local encoded vault. Perfect for teachers who need quick safety. Windows (macOS and Linux coming soon). ##### Office Add-in **Word, Excel & PowerPoint**. Works inside Microsoft Office. Select text and click anonymize. Perfect for grading and administrative work. Works offline. ##### OpenOffice Add-in **LibreOffice & OpenOffice** For schools using free LibreOffice or OpenOffice. Same powerful safety, zero cost software. Works offline. ##### MCP Server Pro+ **Claude, Cursor & VS Code**. Use AI tools like Claude without sending student data. Auto safety before AI sees text. Needs Pro or Biz tier. Feature Desktop App. Office Add-in. OpenOffice Add-in. MCP Server. **Price** FREE Included Included Pro+ tiers. **Works Offline**. Yes Yes Yes No **Best For**. Quick PII strip. MS Office users. Free software users. AI tool safety. **Platforms** Windows (Mac/Linux soon) Word, Excel, PowerPoint. LibreOffice, OpenOffice. Claude, Cursor, VS Code. What We Detect #### 320+ Entity Types 320+ types of private info auto found in your docs. No manual marking needed. ##### Personal Identifiers Full names, email addresses, phone numbers, dates of birth, age, gender, nationality. ##### Financial Information Credit card numbers, IBAN, BIC/SWIFT codes, bank accounts, tax IDs, VAT numbers. ##### Government IDs Social Safety numbers, national IDs, passports, driver's licenses, health insurance IDs. ##### Location Data Street addresses, cities, postal codes, countries, GPS coordinates. ##### Digital Identifiers IP addresses, URLs, usernames, device IDs, MAC addresses. ##### Education-Specific Student IDs, enrollment numbers, institutional IDs, academic records metadata. PII strip Methods #### 5 Protection Methods Choose how to protect each type of private data. Mix and match methods within a single document. ##### Replace Substitute with placeholder labels like [STUDENT] or [EMAIL]. Keeps document readable while removing IDs. ##### Redact Full removal of found items. The info is gone entirely. ##### Hash (SHA-256) One-way cryptographic hash. Track patterns across docs without knowing real identities. ##### Encrypt (AES-256-GCM) Reversible encoding. Deanonymize later with your key when needed. ##### Mask Partially hide info. Show enough structure to be useful while protecting the actual data. Use Cases #### Real Education Scenarios ##### Sharing Student Records **Problem:** You need to share student files with outside evaluators or contractors. **Solution:** Replace real names with fake ones. Keep academic data readable. ##### Using AI for Grading Help **Problem:** You want to use ChatGPT or Claude but cannot share student names with AI companies. **Solution:** MCP Server removes all names before AI sees the text. Get AI help safely. ##### Publishing Research **Problem:** Research involves student data that cannot be published with real identities. **Solution:** Hash IDs for tracking patterns without knowing real names. ##### Student Data Protection Anonymize student records for sharing with third parties. Protect personally identifiable info in reports. FERPA and GDPR audit fit. ##### Research Data Anonymize survey responses and interview transcripts. Protect participant data in published research. IRB audit fit support. ##### Administrative Records Anonymize employee and staff data. Protect financial records. Secure document sharing with outside parties. Safety & Audit fit #### Trusted by Educational Institutions ##### GDPR Compliant Full audit fit with EU data safety rules. Designed for European educational institutions handling student private data. ##### FERPA Aligned Matched with the Family Educational Rights and Privacy Act. Protects student education records and personally identifiable info. ##### ISO 27001-Aligned Hosted on Hetzner data centers in Germany (ISO 27001-certified systems). 100% EU-based. Uptime targets logged on the status page; no contractual SLA. ##### Zero-Knowledge Architecture Zero-knowledge sign-in with Argon2id. 24-word BIP39 recovery phrase. AES-256-GCM encoding. TLS 1.3 in transit. We never see actual data. Pricing #### Simple Pricing for Schools Free Desktop App included with every plan. Educational discounts ready for institutions. ##### Free €0/month 200 tokens per month. - Desktop App included. - 48 languages - TXT files (web) - Perfect for individual teachers. ##### Basic €3/month 1,000 tokens per month. - All Free features. - All file types. - Office & OpenOffice add-ins. - Perfect for regular use. ##### Pro Best Value €15/month 4,000 tokens per month. - Everything in Basic. - MCP Server access. - All file types. - Perfect for active schools. ##### Business Enterprise €29/month 10,000 tokens per month. - Everything in Pro. - 50-text batch processing. - Priority support. - Perfect for universities. Positioning #### How anonymize.education Differs **anonymize.education** is the **education-specific portal** built on the [anonym.legal](project-anonym-legal.html) platform. While our other platforms serve developers, enterprises, and broad consumers, anonymize.education is designed namely for **schools, universities, and research institutions**. Key differences: simplified language for non-technical educators, education-specific use cases (student records, grading, research), **FERPA fit** alongside GDPR audit fit, **OpenOffice/LibreOffice add-in** for schools using free software, and educational institution pricing. The underlying finding engine and safety design are shared with anonym.legal. Access #### Start Protecting Student Privacy Today Download the free Desktop App or create a free account. No credit card needed. [Open anonymize.education →](https://anonymize.education/) [Parent Platform: anonym.legal](https://anonym.legal/) **Related Platforms:** [anonym.legal](project-anonym-legal.html) — Zero-Knowledge PII PII strip  |  [anonym.plus](project-anonym-plus.html) — Offline desktop app  |  [anonym.today](project-anonym-today.html) — Consumer privacy tool Fit & Limitations #### Best fit and known limitations ##### Best for Schools, universities, and EdTech vendors that need GDPR-audit-fit, FERPA-matched PII strip for student records, research datasets, and comms across 48 languages with 320+ item types. ##### Not the right fit Broad-purpose firm-wide PII pipelines outside the education vertical (use [anonym.legal](project-anonym-legal.html) or [cloak.biz](project-cloak-business.html)); single-user consumer scrubbing (use [anonymize.today](project-anonymize-today.html)). ##### Known limitations Built on anonym.legal so feature parity tracks the parent product; FERPA fit is a setup profile, not a third-party audit cert; OpenOffice add-in coverage lags the Microsoft Office add-in by one minor version. #### Need data protection for your school or university? Let's discuss how anonymize.education can help protect student privacy across your institution. [Book a Call](contact.html) [← All Projects](projects.html) --- ## piisafe.eu — Free Website PII Scanner | curta.solutions URL: https://curta.solutions/project-piisafe-eu.html > Free website PII scanner. 131+ entity types via cloak.business, 41 languages, results under 60 s. Designed for GDPR / HIPAA / PCI-DSS. Zero storage. Project • Free Tool • Data Safety. ### piisafe.eu — Free Website PII Scanner Instantly scan any website for exposed private data. Regex-based finding across 131+ item types (via the cloak.biz API) and 41 languages — no listing, no data storage, results typically under 60 seconds. Free Tool. PII Finding. Website Scanner. GDPR. HIPAA. PCI-DSS. Zero Data Storage. #### Platform Overview **piisafe.eu** is a free website PII scanner that detects exposed private data across 131+ item types (shipped via the cloak.biz API) and 41 languages. The free tier uses regex pattern matching; the upstream cloak.biz engine adds ML augmentation. Scan results are computed in-memory and never stored. No account, no credit card, no listing needed. The scanner crawls up to 10 pages per scan. It delivers an A-F risk grade with a detailed breakdown of every found PII category. Examples include email addresses, phone numbers, IBANs, government IDs, and medical record numbers. Results export as HTML, JSON, or CSV for audit fit docs. 131+ Item Types (via cloak.biz) 41 Languages <60s Typical Scan Time What It Detects. #### PII Categories Covered ##### Personal Identifiers Names, email addresses, home addresses, phone numbers, dates of birth, and national ID numbers. Coverage spans 30+ country-specific formats including German Steuer-ID, EU national IDs, and SSNs. ##### Financial Data Credit card numbers (Visa, Mastercard, AMEX, and more), IBANs, bank account numbers, and payment refs. Found with checksum checks to eliminate false positives. ##### Medical Records Medical record numbers, health insurance IDs, prescription refs, and other healthcare-specific PII. Covered by HIPAA and EU health data rules. ##### Digital Identifiers IP addresses, MAC addresses, device IDs, cookies, session tokens, and API keys. These constitute private data under GDPR and similar frameworks. ##### Location Data Postal codes, geographic coordinates, regional IDs, and location-specific patterns. These may constitute private data when combined with other IDs. ##### Organization Data Company listing numbers, VAT IDs, trade registry entries, and biz IDs. These may expose client or partner data in violation of B2B data agreements. Risk Assessment. #### A-F Risk Grading Every scan produces a risk grade from A (no PII found) to F (critical exposure). The report includes a full breakdown by item category and page location. ##### Deterministic Detection Regex-based pattern matching delivers deterministic, reproducible results. The same input on the same ruleset version always produces the same output. Audit-ready and verifiable by your audit fit team. ##### In-Memory Processing Scan results are computed and returned without any data storage. No PII from your website is stored on our servers — processing is ephemeral by design. ##### Detailed Reports Export scan results as HTML dashboard, JSON for pipeline link-up, or CSV for spreadsheet study. Each report includes item type, page URL, and exact match location. ##### Multi-Language 41 languages supported for global websites. PII patterns are locale-aware — German IBANs, French social safety numbers, and Japanese phone formats are all found correctly. How It Works. #### Scan Process - **Enter URL** — Provide any website URL. No account or listing needed. - **Crawl** — The scanner crawls up to 10 pages of the target site, following in-house links. - **Pattern Matching** — 131+ regex patterns (shipped via the cloak.biz API) scan every page. Coverage extends across 41 language profiles. - **Risk Grading** — Found PII is categorized and weighted to produce an A-F risk score per page and overall. - **Report Generation** — Results are compiled with item types, locations, and risk breakdown — computed in memory, never stored. - **Export** — Download your report as HTML, JSON, or CSV for audit fit docs or fix tracking. [Try the free scanner now →](https://piisafe.eu/) Audit fit Coverage. #### Regulatory Frameworks ##### GDPR Identifies private data exposure on your website that may constitute a GDPR violation. Covers all categories of private data under Article 4, including special category data. ##### HIPAA Detects Protected Health Info (PHI) exposed on web pages, supporting HIPAA audit fit for healthcare teams and their biz associates. ##### PCI-DSS Identifies cardholder data (credit card numbers, CVVs, expiry dates) exposed on web pages. Critical for merchants and payment processors under PCI-DSS scope. ##### CCPA Covers private info categories defined under the California Consumer Privacy Act, supporting US-based teams with CCPA audit fit obligations. ##### ISO 27001 Supports Annex A control A.8.2 (Info labeling) and A.5.34 (Privacy and safety of private data). It identifies uncontrolled PII exposure on web surfaces. ##### Made in Germany Hosted in Germany under EU law area. All processing happens inside the EU; no cross-border data transfers. Pricing. #### Free Scanning. Unlimited with Upgrade. piisafe.eu is free with generous limits. For unlimited scanning, image OCR, and full PII strip, upgrade via the related platforms. ##### Free €0 20 scans per hour, up to 10 pages per scan. - 131+ item types (via cloak.biz) - 41 language profiles. - A-F risk grading. - HTML, JSON, CSV export. - No account needed. - Zero data storage. ##### Unlimited via cloak.business Full Power €49/month Unlimited scans, image OCR, API access, and full PII PII strip. - Unlimited website scans. - Image redaction with OCR. - 317 regex pattern matchers. - Full PII PII strip platform. - API access for auto-work. - Priority support. ##### Personal via anonym.legal €3/month Chrome Extension, 285+ items, batch processing. - Chrome Extension included. - 285+ item types. - 48 languages + RTL. - Zero-Knowledge sign-in. - MCP Server for AI tools. - Batch processing. Use Cases. #### Who Scans with piisafe.eu ##### Compliance Teams Verify that client-facing websites do not expose private data in HTML source, embedded scripts, or linked docs. Run before GDPR or ISO 27001 audits. ##### Web Developers Run pre-rollout PII scans to catch accidental exposure of test data, debug logs, or API responses containing private info. ##### Security Auditors Include website PII exposure in safety assessments and penetration test reports. Export JSON results for link-up into vulnerability control platforms. ##### Legal Teams Document the absence of PII exposure as proof of data safety audit fit. Useful for clients, regulators, or legal proceedings requiring proof of due diligence. ##### Healthcare Organizations Verify that patient portals, appointment booking pages, and informational websites do not inadvertently expose Protected Health Info (PHI). ##### E-Commerce Merchants Confirm that order confirmation pages, account areas, and product listings do not expose cardholder data. Also checks for client contact info in page source. Access. #### Scan Your Website Now Free, no listing needed. Enter your website URL and get results in 60 seconds. [Start Free Scan →](https://piisafe.eu/) [cloak.biz — Full Platform](project-cloak-business.html) [anonym.legal — Private Plan](project-anonym-legal.html) **Related Platforms:** [cloak.biz](project-cloak-business.html) — firm-wide PII PII strip with image OCR and unlimited scanning. [anonym.legal](project-anonym-legal.html) — Zero-Knowledge PII platform with MCP Server and Chrome Extension. Fit & Limitations. #### Best fit and known limitations ##### Best for Marketing, legal, and audit fit teams that need a quick public-page PII risk grade across an entire site without signup — useful before audits, RFPs, or rule-set reviews. ##### Not the right fit Authenticated areas, intranets, or dynamic content behind login (the scanner crawls public surfaces only); ongoing tracking (one-shot scan only); image redaction (use [cloak.biz](project-cloak-business.html)). ##### Known limitations Public-page scope only with a single scan per request; deterministic regex finding without ML name resolution; report depth depends on how much HTML is rendered server-side rather than after JavaScript hydration. #### Need continuous PII monitoring for your website? Let's discuss auto-run scanning, fix workflows, and audit fit reporting for your team. [Book a Call](contact.html) [← All Projects](projects.html) --- ## gtools.pro — Zero-Knowledge M365 Tools | curta.solutions URL: https://curta.solutions/project-gtools-pro.html > Free M365 administration suite. Local PowerShell collectors plus a self-hosted Teams chat exporter. ISO 27001-aligned audit reports. Project • Free Tool • M365 Administration. ### gtools.pro — Local-First M365 Administration Suite Free Microsoft 365 administration tools. Local PowerShell collectors export Intune, Entra ID, and Safety setups; a self-hosted Teams chat exporter handles Teams 1:1, group, and channel conversations. Audit reports map to ISO 27001 Annex A controls. Free Tool. M365 Administration. Local-First. PowerShell Audit. Teams Chat Export. ISO 27001 Mapping. #### Platform Overview **gtools.pro** is a local-first administration suite for Microsoft 365 IT teams. The audit toolchain runs as PowerShell collectors on the operator’s own machine, authenticating directly against Microsoft Graph. The Teams chat exporter ships as a self-hosted React frontend + FastAPI backend that runs inside the operator’s perimeter; tenant credentials are used by that local service only and never touch any curta-hosted SaaS. What ships today: 18 PowerShell audit collectors covering ID, safety, and setup; 11 pre-built audit reports mapped to ISO 27001 Annex A controls; a self-hosted Teams chat exporter (1:1, group, and channel conversations); Intune device-policy export; Entra ID ID-setup export. Free for all users. 18 PowerShell Audit Collectors 11 Audit Reports 1 Framework Mapped (ISO 27001) Free Now Pricing Local-First Design. #### Security by Design ##### Local-Only Credential Handling PowerShell collectors authenticate directly to Microsoft Graph from the operator’s own machine. The Teams chat exporter runs as a self-hosted service inside the operator’s perimeter; tenant credentials are used by that local service only. No curta-hosted SaaS gets, stores, or proxies your credentials. ##### Direct Graph API Exports All data exports are made via direct calls from your browser to Microsoft Graph API. Exported files download directly to your machine without transiting or being stored on any third-party server. ##### WebAssembly Encryption Cryptographic ops use AES-256-GCM and ChaCha20-Poly1305 set up in WebAssembly for high-speed, browser-native encoding without JavaScript library dependencies. ##### Microsoft OAuth Only Sign-in is handled entirely through Microsoft's OAuth 2.0 flow. Supports both delegated user permissions and application permissions via service principal / app listing. Content Backup. #### Backup What Matters Three backup centers cover all major M365 content workloads, with both private and team-wide scope options. ##### Communication Backup **Teams chats, channels, email, calendar, contacts**. Export Teams conversations and channel history, Exchange mailbox content, calendar entries, and contact lists. Supports delta sync for incremental backups. Output includes JSON and PST formats. ##### Files Backup **OneDrive and SharePoint docs**. Back up OneDrive private drives and SharePoint site libraries. Delta sync support exports only files changed since the last backup. Live log viewer shows real-time progress for large tenants. ##### Productivity Backup **Planner, Bookings, To Do tasks**. Export Microsoft Planner boards with tasks, buckets, and assignments. Back up Bookings calendars and appointment history. Export private and shared To Do task lists to JSON. Setup Export. #### 8 Configuration Export Tools Document your M365 tenant setup before moves, policy changes, or audits. All exports download directly to your machine. ##### Entra ID Advanced Export Full Entra ID (Azure AD) setup including Privileged ID Control (PIM), MFA policies, Conditional Access rules, B2B settings, custom safety attributes, and team branding. ##### Exchange Online Deep Export 13 export categories covering mailbox policies, transport rules, connectors, anti-spam and anti-malware settings, keep policies, and audit fit setups. ##### Intune Configuration Export 26 setup categories: device audit fit policies, setup profiles, app safety policies, enrollment restrictions, Windows Autopilot profiles, and update rings. ##### M365DSC Export Make Microsoft365DSC PowerShell scripts from your live tenant setup for systems-as-code docs, drift finding, and setup replication. ##### Power Platform Inventory Export Power Apps, Power Auto-run flows, Power BI workspaces, and Dataverse setups across your tenant. Find shadow IT and ungoverned auto-work assets. ##### Security & Compliance Export 13 parts: DLP policies, trust level labels, keep labels, comms audit fit policies, eDiscovery cases, insider risk control settings, and audit log setups. ##### SharePoint Permissions Export Document site collection permissions, unique permission inheritance breaks, outside sharing settings, and guest access at scale across all SharePoint sites and libraries. ##### Teams Voice Configuration Export Teams Phone System setup: dial plans, call queues, auto attendants, emergency locations, voice routing policies, and Direct Routing trunk settings. Audit & Audit fit. #### Audit and Compliance Reports Eleven pre-built reports covering safety posture, access rules, sharing risks, Teams rules, and ISO 27001 fit. ##### Security Posture - M365 Tenant Audit (ISO 27001 Annex A mapping) - Safety Risk Dashboard. - Privileged Access Report. - Copilot Readiness Assessment. - Permission Change Audit. ##### Access Governance - Access Review Report. - Outside Teamwork Report. - Orphaned Users Report. - Oversharing Finding. - Unique Permissions Audit. ##### SharePoint Security - SharePoint Safety Center. - SharePoint Permissions Report. - Sharing Links & Invitations Report. - Broken Inheritance Report. - Group Membership Report. ##### Teams & Lifecycle - Teams Rules Report. - Teams Safety Center. - Teams Storage Report. - Site Lifecycle Report. - Stale Content Report. Audit fit Framework. #### ISO 27001 Audit Coverage The M365 Tenant Audit runs 18 collectors across safety settings, ID setup, and audit fit controls, mapped to ISO 27001 Annex A. Mappings for other frameworks (SOC 2, GDPR, HIPAA, NIS2) are on the roadmap but not yet set up. ##### ISO 27001 18 audit collectors mapped to ISO 27001 Annex A controls. Covers ID safety (MFA, PIM, Conditional Access), data safety policies, audit logging, and safety setup starting points. ##### GDPR — informational Setup checks covering data minimization, access controls, keep policies, and audit logging surface proof relevant to GDPR reviews. No GDPR-specific control mapping ships yet. ##### Other frameworks — roadmap SOC 2 Trust Service Criteria, HIPAA technical safeguards and NIS2 risk-control controls are planned mappings. Not set up today; do not rely on this tool for those audits yet. Export Formats. #### Flexible Output for Every Use Case ##### Machine-Readable **JSON, CSV** Set data exports for pipeline link-up, vulnerability control platforms, SIEM ingestion, and custom reporting workflows. ##### Human-Readable **HTML Dashboard, Excel, PDF**. Visual dashboards for audit fit reviews, control reporting, and audit presentations. Excel exports for data study and pivot table reporting. ##### Infrastructure as Code **PowerShell (.ps1)** M365DSC PowerShell scripts made from live tenant setup for docs, drift finding, and setup replication across tenants. ##### Backup Archives **ZIP, PST** Packaged backups of Teams content, Exchange mailboxes (PST format), and document libraries shipped as ZIP archives directly to your local machine. Use Cases. #### When IT Teams Reach for gtools.pro ##### Pre-Migration Documentation Document source tenant setup before M365 tenant moves or major policy changes. Export all 8 setup categories to create a starting point snapshot for comparison and rollback reference. ##### Employee Offboarding Back up departing user's Teams chats, OneDrive content, To Do tasks, and calendar data before account deactivation. Ensure no biz-critical content is lost when accounts are disabled. ##### Copilot Readiness Run the Copilot Readiness Assessment and Oversharing Finding reports before M365 Copilot rollout to find permission risks and touchy content that could be exposed through AI-assisted queries. ##### Compliance Audits Make ISO 27001 audit proof in a single session. 18 audit collectors produce set findings with high/medium/low/info severity ratings and ISO 27001 Annex A coverage percentages. Mapping to other frameworks (SOC 2, GDPR, HIPAA, NIS2) is on the roadmap. ##### External Access Review Audit all guest accounts, outside user sharing, and B2B teamwork settings across your tenant. Find overprovisioned outside access before safety reviews or partner relationship changes. ##### Storage & Lifecycle Find stale content, dormant Teams, inactive sites, and storage growth patterns. Prioritize archival or deletion decisions with activity-level categorization across all M365 workloads. Pricing. #### Free for Now gtools.pro is now free for all M365 IT administrators. All tools and reports are accessible without subscription. Needs Microsoft 365 E3 or E5 licenses for the M365 tenant features being administered. Advanced audit features (1-year keep, unified audit log) need M365 E5. **Access Needs:** Microsoft 365 tenant with right administrator role. Supported roles include Global Administrator, Audit fit Administrator, Teams Administrator, Exchange Administrator, and Power Platform Administrator depending on the tools used. App listing in Azure AD needed for application permission flows. [Open gtools.pro →](https://gtools.pro/) Fit & Limitations. #### Best fit and known limitations ##### Best for Microsoft 365 administrators preparing for an ISO 27001 audit who want local-first PowerShell collectors and a self-hosted Teams export service rather than handing tenant data to a third-party SaaS. Mapping to SOC 2, GDPR, HIPAA and NIS2 is on the roadmap. ##### Not the right fit Non-Microsoft estates; runtime tracking (use a SIEM); setups that ban any local processing of admin data, even client-side encoded. ##### Known limitations Browser-bound — very large tenant exports are constrained by browser memory; read-only by design (does not modify tenant setup); coverage focuses on the most-used M365 surfaces, not every Microsoft Graph endpoint. #### Need M365 governance, migration, or compliance support? Let's discuss how gtools.pro fits into your M365 administration, audit, and audit fit workflows. [Book a Call](contact.html) [← All Projects](projects.html) --- ## PropsHub — Film & TV Props Management | curta.solutions URL: https://curta.solutions/project-propshub-online.html > Professional props management platform for film and TV production. Script breakdown, inventory tracking, barcode scanning, zero-knowledge security. Project • Custom Software • Film Live ### PropsHub — The Operating System for Props Departments Professional platform for film and TV props control. Script-aware planning meets physical asset tracking with zero-knowledge safety design. Custom Software Film Live Stock Control Zero-Knowledge React 19 TypeScript PostgreSQL #### Platform Overview **PropsHub** bridges film-native flows and physical asset control. The platform pairs script breakdown and revision tracking with serial stock control, barcode/QR scans, and chain-of-holding docs. All within a zero-knowledge design. Encoded data sits on the server. Decryption runs only on the client. Built for prop masters. For assistant prop masters. For on-set leads. For prop buyers. For live control teams. They need script-aware planning, buying tracks, budget control, and continuity docs in one linked system. 2 Core Workflows United Barcode Asset Scanning Script Breakdown Link-up Zero Server-Side Plaintext Core Skills #### Film-Native Meets Warehouse-Grade ##### Script Breakdown Scene-linked props control with script revision tracking. Break down scripts, tag props by scene and character, track script changes across revisions, and maintain continuity refs throughout live. ##### Inventory Tracking Serialized asset control with barcode and QR code scanning. Check-in/check-out workflows, transport chain-of-holding docs, and real-time location tracking across warehouse and on-set setups. ##### Procurement & Budgets Purchase tracking linked with stock and scene needs. Budget allocation by department, vendor control, invoice tracking, and real-time spend view against approved budgets. ##### On-Set Mobile Capture Mobile-optimized interface for on-set coordinators. Capture continuity photos, log prop usage by take, update asset status in real-time, and sync offline changes when connectivity returns. Zero-Knowledge Design #### Security by Design Client-side encoding ensures that server-stored data remains encoded. Only authorized users with the correct encoding keys can decrypt touchy live info. ##### XChaCha20-Poly1305 Encryption All touchy live data is encoded client-side using XChaCha20-Poly1305 authenticated encoding before transmission to the server. The platform stores only encoded blobs — plaintext data never reaches the server. ##### Argon2id Key Derivation User passwords are processed with Argon2id key derivation to make encoding keys. Keys are derived client-side and never transmitted. The server cannot decrypt user data even with database access. ##### Production Data Isolation Each live operates in a cryptographic isolation boundary. Live keys are independent, ensuring that access to one live's data does not compromise others on the same platform instance. ##### Audit Trail Logging Full access logging and change history tracking. All data access, modifications, and user actions are logged with timestamps and user attribution for audit fit and safety auditing. Target Audience #### Built for Production Teams ##### Prop Masters & Assistants Full view into script needs, stock uptime, procurement status, and on-set asset tracking. Manage continuity docs and link with multiple departments from a single platform. ##### On-Set Coordinators Mobile-optimized workflows for real-time asset check-out, continuity photo capture, and scene completion logging. Offline-capable for remote locations with auto sync when connectivity returns. ##### Prop Buyers & Procurement Purchase request tracking linked with scene needs and approved budgets. Vendor control, invoice matching, and spend view by live, department, and budget category. ##### Production Management Budget oversight, department team-up, and live-wide view into props status. Role-based access control ensures each team member sees only relevant info for their duties. Technology Stack #### Modern Architecture for High Performance ##### React 19 Frontend **React 19, Vite 6, TypeScript, Tailwind CSS 4**. Modern React design with TypeScript for type safety. Vite for fast dev work and optimized live builds. Tailwind CSS 4 for responsive design and mobile-first layouts. ##### Fastify 5 Backend **Fastify 5, Node.js, TypeScript** High-speed HTTP server with TypeScript throughout. Schema-based checks, request/response serialization, and plugin design for modular API design. ##### PostgreSQL + Prisma **PostgreSQL 16, Prisma ORM**. Relational database with full ACID audit fit. Prisma ORM for type-safe database access, auto-run moves, and developer-friendly query interface. ##### State & Forms **TanStack Query, React Hook Form**. TanStack Query for server state control with caching, optimistic updates, and background syncing. React Hook Form for performant form handling with built-in checks. Internationalization #### German & English Support PropsHub includes full internationalization support via react-i18next with German and English language support. UI labels, checks messages, and system notifications adapt to user language preference. Live teams can operate in their preferred language while maintaining consistent data structures. Use Cases #### Where PropsHub Adds Value ##### Multi-Location Productions Track props across warehouse, studio sets, and remote locations. Chain-of-holding docs ensures checks when assets move between locations and departments. ##### Script Revision Management Handle script changes during pre-live and active shooting. Auto find which props are affected by script revisions and update scene breakdowns as needed. ##### Budget-Conscious Productions Real-time view into procurement spend against approved budgets. Prevent overspending with approval workflows and purchase request tracking linked with budget allocations. ##### High-Volume Inventory Manage productions with hundreds or thousands of serialized props. Barcode scanning accelerates check-in/check-out workflows and reduces manual data entry errors. ##### Continuity Documentation Link continuity photos and notes directly to scenes and takes. Maintain searchable continuity archives for tough productions with multiple units shooting at once. ##### Post-Wrap Accounting Make live-end reports for asset disposition, final budget reconciliation, and vendor invoice matching. Export data for accounting systems and archive docs. Fit & Limitations #### Best fit and known limitations ##### Best for Film and TV live departments handling script breakdowns, physical asset tracking, barcode/QR scanning, procurement, and continuity in one client-side encoded platform. ##### Not the right fit Broad warehouse or retail stock control outside live; teams that do not need script-aware planning; lightweight private asset tracking. ##### Known limitations Tuned for live timelines and continuity, not for never-ending rental fleets. Pulling in legacy spreadsheets needs hand-mapping. Mobile capture today is limited to barcode/QR scan via phone camera. #### Need custom production management software? Let's discuss how tailored software solutions can streamline your live workflows while maintaining safety and data isolation. [Book a Call](contact.html) [Visit PropsHub →](https://propshub.online/) --- ## localLLM — Sovereign AI Platform | curta.solutions URL: https://curta.solutions/project-localllm.html > Sovereign AI inside the client perimeter. Project-aware RAG, OpenAI gateway, 38 MCP tools, 54-family catalog, 30 task types. Air-gapped or hybrid. Project • Custom AI Engagement • In Implementation. ### localLLM — Sovereign AI inside the client perimeter Project-aware RAG, OpenAI-compatible gateway, MCP-first agent surface. The project-intelligence backend behind a hybrid AI engagement — project memory, retrieval, and orchestration stay on-premises; reasoning is supplied by either local LLMs (air-gapped) or the customer's existing cloud account routed through LiteLLM. Custom AI Solution. Sovereign Local AI. Self-Improving RAG. Agentic Orchestration. MCP Server. In Implementation. #### Platform Overview **localLLM** is a turnkey platform that scans the client’s codebases and documents, builds a self-improving per-project knowledge base, and serves a project-aware assistant through any tool that speaks the OpenAI API. A FastAPI gateway fronts a benchmarked catalog of 54 model families and routes 30 task types to the right brain on demand. A 24-tool plan-then-execute orchestrator with grammar-constrained outputs runs alongside an MCP server exposing 38 tools to external IDE agents (Cline, Aider, Goose, OpenHands, Continue). Deploys air-gapped or hybrid — the perimeter is the customer’s, not ours. 54 Model Families 30 Routed Task Types 38 MCP Tools Architecture. #### Verified Architecture Six layers, top-down: inputs → ingestion → per-project knowledge base → FastAPI gateway → agent & integration surfaces → external IDE agents. Verified against the running codebase on 2026-04-29. * localLLM — verified architecture, 2026-04-29. [Mermaid source](localllm-architecture.mermaid). Layer 1 · Ingestion. #### Ingestion Five input streams feed the per-project knowledge base. Every artifact carries provenance back to its origin so retrieval results stay auditable. ##### Codebase Scanner Detects skills, frameworks, and languages and emits a structure graph for every git-tracked source tree. Output lands in skills.json and vectors.db alongside the per-project manifest. ##### Document Loaders Ingests PDF, DOCX, CSV, XLSX, Markdown, JSON, and TXT via **pymupdf**, **python-docx**, and **pandas** — deterministic extractors with provenance tracking. ##### Web Researcher SSE-streamed, per-skill web research via **httpx** + **trafilatura** + LLM summarisation. Fills knowledge gaps without operator hand-holding; results cached. ##### URL Ingestion Single-page fetch into KB entries for ad-hoc references — documentation, RFCs, blog posts, vendor advisories. ##### Signed Webhooks HMAC-signed inbound triggers drive ingestion from existing CI. Six lifecycle actions: scan, learn, improve, project_chat, agent_run, pipeline. Layer 2 · Knowledge. #### Per-Project Knowledge Base Each project gets its own knowledge base with hybrid retrieval and five persistent memory layers that survive across sessions. ##### Hybrid Retrieval **SQLite FTS5** keyword search plus sqlite-backed cosine vector embeddings plus **FlashRank** cross-encoder reranking, fused via **RRF**, diversified via **MMR**, and expanded one hop across entry-citation graphs. Citations carry entry IDs end-to-end. ##### Five Memory Layers - **Hermes** — long-term agent memory - **ReasoningBank** — distilled successful trajectories - **__global__** — cross-project skills KB - **USER.md** — per-user profile memory - **Skill rules** — per-skill rule extraction ##### Per-Project Layout Each project ships as a self-contained set of files: manifest.json, entries.json, graph.json, vectors.db, hermes_memory.json, reasoning_bank.json. Portable and inspectable. ##### Single-Flight Context Cache Mtime-keyed cache for the assembled context bundle — concurrent requests for the same project state collapse into one retrieval pass. Layer 3 · Gateway. #### FastAPI Gateway A single FastAPI service exposes an OpenAI-compatible /v1/chat/completions endpoint. Every external tool that speaks the OpenAI API gets project intelligence through a single header. ##### 3-Layer RAG Injection An X-Project-ID header triggers automatic injection of (1) project overview, (2) KB entries, and (3) Hermes memories before the LLM call. The caller never assembles a prompt manually. ##### 30 Task Types → Right Brain Routes via TASK_MODEL_MAP across the active model families with size + memory + health guards. The right brain is matched to each task on demand — from code_review* to *iso_standards* to *function_calling*. ##### LiteLLM Provider One provider abstraction over Ollama (default), llama.cpp, vLLM, OpenAI, Anthropic, and Gemini. Typed-fallback dispatch keeps the surface stable when an upstream is unhealthy. ##### Adaptive Health & Watchdog Adaptive health checks (30 s when unhealthy, 120 s when all healthy). An SSE disconnect watchdog releases upstream model resources within ~200 ms of client drop — no orphaned VRAM. Layer 4 · Integration Surfaces. #### Agent & Integration Surfaces Four peer surfaces ride the gateway: an agentic orchestrator, an MCP server, a VS Code extension, and a Pipelines DSL with eval and predictions tooling. ##### Agentic Orchestrator **24 tools** · plan-then-execute with grammar-constrained emit_plan (Ollama 0.5+ JSON-schema decoding) and a ReAct fallback path. Every destructive action goes through an audited approval gate with full audit log. ##### MCP Server **38 tools** over stdio — 19 foundational query verbs plus 19 lifecycle verbs (scan, learn, improve, evaluate, plan, …). Every tool call is audited. Drives Cline, Aider, Goose, OpenHands, and Continue. ##### VS Code Extension Bundled extension adds **Ask About File**, **Explain Selection**, and inline edit suggestions — project-scoped per workspace. ##### Pipelines & Peers Pipelines DSL (sequential + fanout steps with verbatim and verify_build modes), signed webhooks, Compare and Predictions surfaces, and an evaluation harness for regression-grading project runs. Layer 5 · External IDE Agents. #### External IDE Agents Any OpenAI-compatible client — Cline, Aider, Goose, OpenHands, Continue, Flowise — reaches the gateway via /v1 + the X-Project-ID header, calls MCP tools over stdio, and uses cloud Claude or GPT for reasoning under tool constraints when the engagement runs in hybrid mode. **localLLM stays the project-intelligence backend; the IDE agent is the brain.** The gateway is OpenAI-compatible HTTP — there is no agent-detection logic and no rejection list. Any client that can hit a custom base URL and add a header gets the full RAG-injected experience. Operation Modes. #### Air-Gapped or Hybrid A single project KB — two doors. The architecture is identical; only the brain changes. ##### Air-Gapped **100% local LLMs · zero network egress** Local recall, local memory, local reasoning. No data leaves the client perimeter. Runs on commodity hardware (M-series Mac, RTX desktop, on-prem GPU server). The Pipelines DSL, MCP server, and orchestrator behave identically — only the model backend changes. ##### Hybrid (Stance B) **Local recall + cloud LLM reasoning** Local 8B–30B models do **recall** well (KB, memory, structure, rules); cloud Claude or GPT do **reasoning under tool constraints** reliably. Hybrid splits the work to the right brain. The cloud LLM only sees the RAG-injected payload of each call and individual MCP tool responses — never the raw archive. ##### Local Drawer (Direct Mode) Project Q&A in **~3 s warm**, 100% on-prem. Bypasses the agent layer entirely — pure retrieval + completion against the active model family. ##### External Agent + Cloud LLM Code edits via Cline; localLLM provides project context via MCP tools and RAG injection. The cloud account is the customer’s — we don’t broker tokens. Verified Numbers. #### Verified Against Current Code Every number on this page is grounded in the running source tree, verified on 2026-04-29. Surface. Count. Source. **Model families (catalog)**. 54 config/catalog.yaml. **Enabled models on M-series**. 8 models across 7 distinct families. config/models.macos.yaml. **Routed task types**. 30 skills/project_orchestrator.py · TASK_MODEL_MAP. **Agentic orchestrator tools**. 24. tools/registry.py. **MCP tools (foundational + lifecycle)**. 38 (19 + 19) mcp_server.py · mcp_server_lifecycle.py. **Memory layers**. 5. skills/knowledge_base.py. **Webhook lifecycle actions**. 6. webhooks/router.py. Fit & Limitations. #### Best fit and known limitations ##### Best for Regulated organisations that must keep prompts, code, and context inside the perimeter, want a project-aware RAG knowledge base, and prefer an OpenAI-compatible gateway so existing IDE assistants and pipelines work unchanged. ##### Not the right fit Teams happy with cloud LLMs and short-lived prompts; lightweight chatbot use without code or document context; environments that cannot host the modest GPU/CPU footprint required for local inference. ##### Known limitations Answer quality is bounded by the local model family chosen for each task type; ingestion of very large monorepos requires tuning and storage planning; first-time setup includes infrastructure decisions (GPU, storage, VS Code rollout). #### Discuss a similar engagement Air-gapped sovereign AI, hybrid RAG-injected gateway, or a custom agent surface for an existing tool stack — we deliver the project-intelligence backend; you keep the perimeter. [Book a Consultation](contact.html) [← All Projects](projects.html) --- ## LocalBrain — FRCP-Aligned E-Discovery | curta.solutions URL: https://curta.solutions/project-localbrain.html > A fully-local knowledge graph + FRCP-aligned e-discovery workbench. Email + document archives, matter scoping, Bates, privilege workflow, redaction. v6.2. Project • Custom AI Engagement • In Active Development • v6.2. ### LocalBrain — a living knowledge graph and FRCP-aligned e-discovery workbench Years of corporate email and document history become a navigable, provenance-stamped knowledge graph — with an e-discovery surface designed against FRCP 26 sitting on top. Everything runs inside the client perimeter. The team that uses it is the team that owns the data. Custom AI Solution. Knowledge Graph. E-Discovery Workflow. Matter Scoping. Local-Only Operation. In Active Development. #### What it is, in one paragraph **LocalBrain** reads the mail archives and document folders an organisation already has — PST, MBOX, EML, MSG plus PDF, DOCX, XLSX, PPTX, TXT, CSV and image OCR — and turns them into a queryable knowledge graph that lives on the operator’s own hardware. Investigators can navigate the graph as a force-directed WebGL canvas, ask natural-language questions through a chat-first console, run named saved queries with temporal as-of snapshots, and receive alerts when a stakeholder is silently dropped from a thread. On top of that knowledge layer sits a full e-discovery workbench — matter scoping, a custodian roster, an append-only chain-of-custody ledger, a five-state privilege workflow, Bates numbering, audit-tracked redaction overlays, a privilege log aligned to FRCP 26(b)(5)(A), and a production-set CSV export. The architecture is opinionated: *nothing leaves the perimeter*. Parsing, language-model reasoning, embedding, retrieval and audit all run locally. 3 Provenance Classes per Edge 5 Privilege Workflow States 11 Supported Source Formats Architecture · Diagram 1 of 3. #### Data flow — from a folder of files to a defensible record Top-down: heterogeneous inputs are normalised, language-processed and extracted; relationships persist in a dual store; analysis surfaces communities, anomalies, hybrid search and forensic queries; the e-discovery layer wraps the lot; presentation surfaces serve investigators and downstream tools. Ingest → Graph → E-Discovery → Surface PST · MBOX · EML · MSG PDF · DOCX · XLSX · PPTX TXT · CSV · Image OCR IMAP · Local Folder Watch ↓ Ingestion, NLP & ExtractionRFC 5322 threading · Quote stripping · Coreference · Entity-pair relation extraction with provenance ↓ ##### Graph + Vector Store People · Threads · Topics · Organisations Semantic similarity · neighbourhood traversal ##### Analytics + Full-Text Store Canonical facts · BM25 index · Bi-temporal audit Source of truth for the knowledge graph ↓ Leiden Communities Who works with whom Gap Anomalies Silent exclusions Hybrid Search BM25 + vector · RRF Forensic Queries Temporal as-of ↓ E-Discovery LayerMatter scope · Custodian · Chain-of-custody · Privilege workflow · Bates · Redaction · Production CSV ↓ Force-Directed WebGL Graph Chat Console · Slash + STT + Matter Switch Per-Matter Obsidian Vault · git MCP + REST Tool Surface Layer 1 · Ingest. #### From a folder of files to a clean canonical record Ingestion does the unglamorous work that everything else depends on. The pipeline parses files, reconstructs threads from RFC 5322 headers, skips duplicates, and routes every body through quote stripping, forward-boundary detection and coreference resolution — so “he agreed” becomes “Alice agreed” before any language model sees it. ##### Mail archives The parser folds PST, MBOX, EML and MSG into a single canonical mail model with RFC 5322 threading and attachment metadata. A local SQLite ledger checkpoints deduplication so re-runs stay idempotent. ##### Document corpora The extractor handles PDF, DOCX, XLSX, PPTX, TXT and CSV deterministically; scanned images go through OCR fallback. Every artefact carries provenance back to its source path. ##### Live sources An IMAP connector pulls from on-premise mail servers; a 30-second folder watcher re-scans on disk change. A folder-to-matter template can auto-tag inbound files to the right matter without manual triage. ##### Coreference before extraction The resolver maps pronouns to the speaker and named-entity context in each thread **before** any LLM call. This is a hard rule: “rule-first, LLM-second” — the language model never sees ambiguous text it would have to guess about. Layer 2 · Knowledge Graph. #### A graph where every edge tells you how it got there The knowledge graph is not a bag of inferred relationships. Every single edge belongs to exactly one of three provenance tiers, and every single edge carries six mandatory fields so a reviewer can always answer the question: *why does the system claim this?* Provenance Taxonomy · 3 Tiers · 6 Mandatory Fields per Edge ##### Deterministic Derived from RFC 5322 headers and structural facts. Sent-to · CC · Replied-to · Thread-of **Confidence 1.0** · no manual review ##### Rule-Derived Inferred from deterministic rules over headers and body patterns. Forwards · Org-of · Communicates-with **High confidence** · spot review ##### LLM-Extracted Semantic relations from a local LLM with embedding-based grounding. Requests-action · Reports-to · Discusses **Probabilistic** · mandatory human review Every edge, every tier: source · confidence · evidence excerpt · timestamp · model version · review status. ##### Dual store, on purpose The knowledge graph lives in a graph + vector store optimised for traversal and semantic similarity; the canonical facts and a BM25 full-text index live in an analytics store with bi-temporal columns. The analytics store is the source of truth — the graph store is a queryable projection. If a better graph engine ships tomorrow, the projection can be rebuilt without losing anything. ##### Continuous human review LLM-extracted edges go into a keyboard-driven review queue: J/K to step, Y to confirm, N to reject. Decisions persist alongside the edge, and a reviewer can always trace a confirmed relationship back to the exact body excerpt and the exact model version that produced it. Layer 3 · Analysis. #### Communities, anomalies and answers that cite the evidence Once the graph is built, the analyst gets four working surfaces — all driven from the same underlying graph, all answering the kinds of questions an investigation actually needs. ##### Communities (Leiden) The Leiden algorithm clusters the communicates-with graph to surface who actually works with whom — not who is on the org chart. Each community gets a short, locally-generated description so the analyst can scan the landscape fast. ##### Participant-gap alerts A deterministic delta over the thread DAG flags candidates: people who appeared in two or more earlier messages but vanished from a later one. A second pass classifies each candidate — oversight, restriction, deliberate exclusion — and writes an anomaly node with the reason recorded. ##### Hybrid search with RRF fusion BM25 lexical search and vector similarity search both return ranked results; Reciprocal Rank Fusion combines them without requiring score normalisation. The output is a single ranked list where every hit cites the underlying message. ##### Forensic queries with temporal as-of Bi-temporal storage means the graph can answer “what did this look like on date X?” even after later edits, retractions or re-classifications. Operators pin named saved queries to a matter and re-run them as the matter evolves. ##### Chat-first console A slash-command launcher, voice input, matter switcher and a streaming agent loop sit on top of everything else. The analyst can ask in plain English and the answer comes back with citations to the messages that grounded it. ##### Force-directed WebGL graph People, threads, organisations, topics, communities and anomalies render as a navigable graph. Clicking a node shows its neighbourhood, its detail panel and the edges that touch it — with the provenance class colour-coded on the line. Layer 4 · E-Discovery. #### The workflow a litigator actually runs The e-discovery layer is not a search dashboard with a privilege checkbox. It is a matter-scoped workbench with first-class primitives for the steps an investigation produces — from intake through production — designed against FRCP 26 and built so every step leaves a defensible trail. Matter → Privilege Workflow → Production Matter Intake → Custodian + Chain-of-Custody → Document Review → Privilege Workflow unreviewed → asserted → produced → clawed-back · FRCP 26(b)(5)(B)-style → released ↓ Bates Numbering Designed monotonic · concurrency-safe Redaction Overlay Audit-tracked · non-destructive Privilege Log Aligned to FRCP 26(b)(5)(A) Production-Set CSV Per-matter export Every mutating endpoint honours a dry-run preflight. Audit payloads carry SHA-256 hashes — never the protected content. ##### Matter as a primitive Every artefact in the system is bound to a named matter. The same email parsed twice under two different custodians produces two defensible records, not a collision. Matter scoping flows through retrieval, the agent loop, and the export surfaces. ##### Custodian + chain-of-custody Each matter has its own custodian roster and an append-only chain-of-custody ledger. The ledger captures every ingest, every promotion, every export as an event with a hash and a timestamp. ##### Five-state privilege workflow Documents move through *unreviewed → asserted → produced → clawed-back → released*. The clawback transition mirrors FRCP 26(b)(5)(B) so a post-production assertion of privilege has a defined path back, with an audited reason field. ##### Bates numbering, designed correct Bates assignment is monotonic and concurrency-safe by construction. Two reviewers stamping at the same time cannot duplicate or skip a number — the assignment runs under an async lock that serialises the sequence even under load. ##### Redaction as audit-tracked overlay Redactions are never destructive. They are overlays stored against the original, with the reviewer, the reason, the timestamp and the revision history attached — so a successful challenge can always produce the unredacted original. ##### Privilege log and production-set CSV A privilege log aligned to FRCP 26(b)(5)(A) and a production-set CSV are first-class exports. Manifests, Bates ranges, custodian and privilege state ship together so the production package is reviewable end-to-end before it leaves the system. Layer 5 · Defence in Depth. #### Security is the architecture, not a feature Because nothing should leave the perimeter, every layer has to respect the perimeter — not just an outer firewall rule. The same applies to user-driven mistakes: an internal bug should never become a denial of service for the analyst. ##### No external API for data processing Parsing, language-model reasoning, embedding, retrieval and audit all run on local hardware. The only sanctioned outbound channels are user-authorised ingestion from IMAP and on-premise file shares, and optional SMTP delivery of scheduled digest reports. ##### Layered egress controls on agent output The agent loop runs behind an input-validation layer that defends against prompt injection on untrusted ingest text, and an output-side filter at the egress chokepoint that catches data trying to leave through generated answers. ##### Hardened outbound connector boundary Outbound connector calls pass a master kill-switch, a per-account host pin and a resolved-IP filter against SSRF. Credentials live in the OS keyring and are never written to logs or audit payloads. ##### PII on the data-security surface A dual-engine PII detection pipeline scans the corpus with span-level provenance labels so the analyst can see exactly which spans triggered, where, and by which detector. GDPR delete flagging is built into the data-security page. ##### Audit by hash, not by content Audit payloads carry SHA-256 hashes of protected content — never the content itself. Forensic admissibility lives in the data model rather than in a paper trail bolted on at the end. ##### Hard resource guards A preflight check guards every long-running operation: free-disk floor on the data volume, bounded streaming captures, a free-RAM warning before inference, log-directory rotation thresholds. An internal bug cannot become a denial of service. Operation Modes. #### One stack, two postures Same architecture, same code path — what changes is the visibility of cloud-connector UI and which channels may ingest. Operators choose the posture at install time. ##### Local-only mode **Air-gappable. Zero cloud-OAuth surface visible.** All cloud-connector UI is hidden. Only the local-folder ingest and IMAP are visible to operators. Useful for genuinely air-gapped deployments where the cloud surfaces would only be a distraction or a compliance concern. ##### Default mode **Cloud-connector UI visible, none active by default.** The same code path with the cloud-connector surfaces left visible so operators can see what later integration will connect. Active ingest stays restricted to local folders and IMAP until the customer explicitly authorises an additional provider. ##### Supported hosts Windows 11 with Git Bash or WSL2, and macOS Apple Silicon (tested on a Mac mini M4 / 16 GB). One idempotent startup script handles dependency checks and starts the four cooperating services in the only order that works. ##### Single-host today The current deployment target is a single workstation or a single operator’s box inside the customer perimeter. There is no cloud control plane, no staging environment, no managed-service component to depend on. A Day in the Life. #### What an analyst actually does with it The architecture is the means; the analyst’s working hour is the end. Four scenarios that hit the main surfaces of the system. ##### Open a matter, drop a PST The analyst creates a matter, names a custodian, drops a PST file into the folder watcher. Within minutes the pipeline parses, threads, deduplicates, language-processes and indexes the file — writing every artefact into the chain-of-custody ledger for that custodian. ##### Find the silent exclusion The graph view lights up a red anomaly node on a thread where the General Counsel was always CC’d — until a particular date. The analyst clicks through, sees the reason classification, the confidence score, and the exact message that triggered the alert. ##### Save a question, re-run it “Every communication with opposing counsel between two dates” goes in as a named saved query. The analyst pins it to the matter and runs it again every Monday morning. Hybrid retrieval handles the lexical and the semantic side; RRF fuses the rankings; every hit cites its source. ##### Produce a defensible package Documents move through the privilege workflow. The reviewer stamps Bates numbers monotonically. Redactions go on as overlays with reviewer, reason and timestamp. The privilege log and the production-set CSV export side by side — ready for review before the package leaves the system. Eight Principles. #### The rules the system holds itself to LocalBrain enforces eight architectural principles as project-wide invariants. They are not aspirational — a pull request that violates one is rejected by the same review queue the code reviews use. ##### P1 · Rule-first, LLM-second Header fields, RFC threading and participant lists are deterministic facts. The language model is used only for semantic enrichment, never for facts that can be derived from structure. ##### P2 · Store-once, project-many Raw mail is stored once. All derived layers — vector, graph, Obsidian vault, exports — are projections. No uncontrolled duplication of source data. ##### P3 · Three-class edge taxonomy Every relation has exactly one class: deterministic, rule-derived, or LLM-extracted. Classes are never mixed; downstream consumers can always filter by tier. ##### P4 · Provenance on every edge Six mandatory fields: source, confidence, evidence, timestamp, model version, review status. No edge enters the graph without all six. ##### P5 · Coreference before LLM Pronouns are resolved before any language-model call. “He agreed” is meaningless without knowing who “He” is — the model never has to guess. ##### P6 · Guided entity-pair extraction Relations are extracted by asking constrained questions about pre-computed entity pairs — not by asking the model to free-form discover relations. Avoids the NA-imbalance problem that wrecks unconstrained extraction. ##### P7 · Obsidian as projection The per-matter Obsidian vault is a display layer for analyst notes, not a primary database. Truth lives in the graph and analytics stores; the vault stays in lockstep. ##### P8 · No cloud egress All models, all databases, and every processing step run locally. Zero external API calls for data processing — an invariant, not a configuration flag. Stack at a glance. #### What runs the engagement A short table of generic capability categories — specific vendor choices are deliberate and can be substituted without changing the architecture. Layer. Capability category. Why this layer. **Storage (graph)**. Embedded graph + vector store. Neighbourhood traversal and semantic similarity in one engine, with named query support. **Storage (analytics)**. Columnar analytics store with BM25 full-text index. Canonical fact store and bi-temporal audit; full-text search co-located with the analytics columns. **Inference**. Local language-model runtime + local embedding model. All reasoning and embedding stays on the host; no cloud LLM is called for data processing. **NLP**. Local coreference resolver + NER pipeline. Pronouns and entities are resolved before any LLM call so the model never sees ambiguous text. **Clustering**. Leiden algorithm over the communicates-with graph. Surfaces communities that reflect actual communication patterns, not org-chart structure. **Retrieval**. Hybrid BM25 + vector search fused via Reciprocal Rank Fusion. Lexical precision and semantic recall combined without requiring score normalisation. **API**. FastAPI REST surface + Model Context Protocol server. One surface for internal UI, one surface for compatible AI clients; same tool catalogue underneath. **Frontend**. React + TypeScript + force-directed WebGL canvas. Multi-page SPA with a graph as a first-class navigation surface, not a static visualisation. **Hosts**. Windows 11 (Git Bash / WSL2) and macOS Apple Silicon. One idempotent startup script covers both. The same code path runs in both environments. Fit & Limitations. #### Best fit and known limitations ##### Best for Regulated organisations with internal investigations, legal hold, litigation response or compliance audits — where the data cannot leave the perimeter and every relation needs to be defensible back to a source. Particularly strong fit for teams whose discovery workflow already references FRCP 26 vocabulary. ##### Not the right fit Teams that want a turnkey cloud SaaS, a fully managed e-discovery service, or a generic search box over mail. LocalBrain is a custom on-premises engagement; it expects an operator who values control over convenience. ##### Known limitations Answer quality is bounded by the local model family chosen for each task. The current scope is single-host on one workstation per matter; horizontal scale-out is on the roadmap but not in scope today. Cloud-source connectors exist in code but are deferred — current sanctioned ingest is local folders and IMAP. #### Discuss a similar engagement If you have a regulated investigation, an internal review, or a litigation workflow that needs to stay inside your perimeter — with a defensible record at every step — we can build the system around your matter, not around our SaaS. [Book a Consultation](contact.html) [← All Projects](projects.html) --- ## SuperLocalBrain — Team Knowledge Brain | curta.solutions URL: https://curta.solutions/project-slb.html > A private, local-first knowledge brain for a 6-10 person professional-services team. Cited answers over your own pile of emails and documents. v6.5. Project • Custom AI Engagement • In Active Development • v6.5. ### SuperLocalBrain — a private knowledge brain for your team’s accumulated files A 6–10 person professional-services team or family office holds fifteen years of mixed personal and company files. Three storage generations. Two languages, sometimes more. The question that costs them the most time, every week, is the simple one. *Where is the thing I half-remember, and what does it actually say?* SuperLocalBrain is built around that question: cited answers, locally, with proof on every claim. Custom AI Solution. Knowledge Brain. Knowledge Graph. Local-Only Operation. Cited Answers. In Active Development. #### What it is, in one paragraph **SuperLocalBrain** (SLB) is the knowledge-brain sibling to LocalBrain. Where LocalBrain holds the forensic and FRCP-aligned e-discovery line, SLB stays out of forensic chain and concentrates on the everyday question of finding the thing in the pile. It ingests the team’s emails (PST, MBOX, EML, MSG) and documents (PDF, Word, Excel, PowerPoint, plain text, scans). It rebuilds scattered threads. It resolves pronouns to real people before any language-model call. Then it extracts typed relationships under a three-class provenance taxonomy, and stores them in a dual layout: a graph store for who-relates-to-whom, and a bi-temporal fact ledger that keeps superseded values instead of overwriting them. The team queries it in plain language through a chat-first console. Every answer carries a credibility contract: claims, byte-spans, trust tier, verification status, reasoning trail. Every citation jumps to the source file. The whole system runs on a single Apple-Silicon workstation inside the team’s perimeter. An egress guard physically blocks outbound traffic. cloak.business handles PII at first-party. 9 Unbreakable Architectural Rules 4 Memory Tiers (L0–L3) 5 Autonomous Improvement Loops Architecture · Diagram 1 of 3. #### Data flow — from a folder of files to a cited answer Top-down: inputs are normalised, language-processed and extracted; relationships persist in a dual store with a bi-temporal fact ledger; analysis surfaces communities, anomalies and patterns; the assistant answers with a credibility contract; everything is wrapped by a defence-in-depth perimeter. Ingest → Knowledge Graph → Assistant → Answer with Proof PST · MBOX · EML · MSG PDF · DOCX · XLSX · PPTX TXT · CSV · Scans · OCR IMAP · Folder Watch ↓ Assembly LineQuote strip · Thread rebuild · Language detect · Coreference · PII via cloak.business · Entity-pair extraction ↓ Knowledge Graph + Bi-Temporal Fact Ledger3-class provenance (GOLD · SILVER · BRONZE) · 6 mandatory fields per edge · superseded values kept, never deleted ↓ Communities Who works with whom Anomalies Missing recipients, gaps, drift Hybrid Search Keyword + meaning + rerank, RRF-fused Schema Induction Recurring document patterns ↓ Chat-First AssistantPlan · retrieve · self-critique · ask-back on ambiguity · credibility contract on every answer ↓ Cited Answer + Reasoning Trail Downloadable Artefact Obsidian-Style Notes Vault Tool Surface over MCP Layer 1 · Ingest. #### From a folder of files to a clean canonical record Ingestion is the unglamorous floor everything else stands on. Files are parsed, threads are rebuilt from headers, duplicates are skipped, and every body is run through quote stripping, language detection and coreference resolution — so “he agreed” becomes “Anna agreed” before any language model sees it. PII is anonymised in flight by cloak.business before any text crosses an internal boundary. ##### Mail archives PST, MBOX, EML and MSG are parsed into a single canonical mail model with thread reconstruction. Quoted-reply text is stripped so the same sentence isn’t counted ten times. Deduplication is checkpointed so re-runs are idempotent. ##### Document corpora PDF, DOCX, XLSX, PPTX, TXT and CSV are extracted deterministically; scanned images go through OCR. Every artefact carries provenance back to its source path, sha256 and byte ranges. ##### Live sources A watched-folder connector picks up new files automatically; an IMAP connector pulls from on-premise mail. No cloud-storage connectors are in scope at MVP — sources stay on the operator’s own network. ##### Coreference before extraction Pronouns are resolved against the speaker and named-entity context in each thread **before** any LLM call. The model never has to guess who “he” is — that work is done deterministically up-stream. ##### PII at first-party [cloak.business](project-cloak-business.html) sweeps personal data before any chunk is embedded, indexed, or shown to the language model. As curta.solutions’ own product, it sits behind the first-party exemption in the egress rules. ##### Multi-language by default German and English ship from day one; Romance languages (French, Italian, Romanian, Spanish) land progressively as deferred per-language scripts in V1 and V2. Layer 2 · Knowledge Graph · Diagram 2 of 3. #### Four memory tiers, like a brain that remembers honestly SuperLocalBrain stores knowledge on four levels — what the assistant is thinking about right now, what the team has accumulated over years, what means what semantically, and what a human wants to browse directly. Nothing is silently overwritten; nothing is duplicated by accident. Memory Tiers · L0 Working · L1 Fact Ledger · L2 Meaning · L3 Mirror ##### L0 · Working What the assistant is thinking about *right now*, during one task. Per-task scratch **Lifetime:** single task ##### L1 · Fact Ledger Bi-temporal: every claim is time-stamped. Old values get an expiry date, not a delete. “What did we know on March 1?” **Lifetime:** permanent, append-only ##### L2 · Meaning Stores the meaning of text; finds “cash flow” from a question about “money problems”. Semantic recall **Lifetime:** derived, rebuildable ##### L3 · Mirror A human-readable Obsidian projection that stays in sync with the graph. The wiki is interpretation; raw is truth. Analyst’s working vault **Lifetime:** projection, regeneratable Every edge across every tier carries: source · confidence · evidence excerpt · timestamp · model version · review status. ##### Three-class provenance Every relationship in the graph belongs to exactly one tier — **GOLD** (deterministic from headers), **SILVER** (rule-derived), or **BRONZE** (LLM-inferred, human-confirmable). The tiers are never mixed; downstream tools can always filter on confidence class. ##### Wiki + Schema layer On top of the raw ledger sits a self-writing wiki: the system drafts canonical interpretation pages from the corpus, and a named human gardener gates promotions. Schema induction quietly learns the recurring shapes of documents (the invoice email, the renewal notice, the engagement letter). Layer 3 · Assistant. #### An assistant that asks back, cites, and refuses to guess The team interacts with SLB through a chat-first console. The agent plans, retrieves, runs a mandatory self-critique pass, and answers with a structured credibility contract on every response. When a question is ambiguous, it asks back with buttons — instead of guessing — and explicitly says “I don’t know” when the sources don’t support an answer. ##### Credibility contract Every answer comes back as a typed JSON envelope: claims with byte-spans, trust tier, verification status, reasoning trail, and citations clickable to the source file. ##### Self-critique at temperature zero Before delivery, a second pass compares every claim against the source byte-spans. Unsupported claims get demoted or fail. Correctness beats speed — there is no latency SLA. ##### Ask-back on ambiguity “Did you mean Matter A or Matter B?” with buttons to pick. The agent never guesses when the question splits across scopes. ##### Workbench mode Natural-language instructions become a reviewable script that a human approves before it runs. The script then executes in a sealed sandbox (time-limited, no network, fully audited) and the result comes back as a downloadable artefact. ##### Artefact pipeline Excel, PDF, CSV, JSON, Word, zip — on demand. Ask for “an Excel of every invoice over €10k from Q3” and a real file lands in the inbox, not a transcript to copy by hand. ##### Hybrid retrieval, RRF-fused BM25 keyword search, dense vector retrieval, and a cross-encoder reranker all return ranked results; Reciprocal Rank Fusion combines them without requiring score normalisation. Faceted filters and saved searches are first-class. Layer 4 · Defence in Depth · Diagram 3 of 3. #### Three explicit defence layers around the assistant A knowledge brain that reads untrusted email has to assume some of that email is hostile. SuperLocalBrain is built with three explicit defence layers around the assistant, plus an egress guard that physically enforces the local-only invariant. Critical-Actions Firewall · Watchdog Supervisor · Content-Blind Status · Egress Guard ##### Critical-Actions Firewall A sidecar enforcer mints short-lived capability tokens for every effector that can change state. Planner and executor are split; untrusted ingest text is datamarked before it reaches reasoning; layered prompt-injection detectors gate any escalation; a set of kill switches fail closed. A two-chain append-only audit log records every decision. ##### Watchdog Supervisor A supervisor process runs every service under a four-level heartbeat protocol with exponential back-off. Named never-auto-restart conditions block thrash loops on certain failure modes. Bulkheads draw isolation domains so a fault in one cannot cascade. An off-volume audit anchor functions as a meta-audit floor. ##### Content-Blind Status Surface A small menubar indicator turns watchdog signals into a six-mood operator status. It is content-blind by design — it sees counters, never answers. Screen-share auto-hides; a panic-hide hotkey is available; speech events are hard-capped to at most one per ten minutes; a 90-day Presentation Mode is mandatory. ↓ Egress GuardOutbound traffic physically blocked at the OS network layer · first-party PII engine exempt · opt-in allowlist required for any external call Signed AUTONOMY_HALT file pauses every autonomous loop at once. Authentication uses PASETO bearer tokens with audience binding and refresh-token reuse detection. Operation. #### A single workstation, two phases SLB is designed to live on one machine inside the team’s perimeter. There is no cloud control plane, no managed service, no SaaS dependency. The roadmap distinguishes between the architecture build and the production hardware that the final faithfulness target depends on. ##### Architecture-MVP **Today’s hardware.** Every layer is wired up; the credibility contract works end-to-end; the assembly line ingests; the firewall logs; the assistant answers with citations. This phase proves the system works. ##### Faithfulness-MVP **Production hardware.** Re-bench on a production-tier Apple-Silicon workstation (~64 GB unified memory, Thunderbolt-attached NVMe). The faithfulness target (≥97% on a sealed acceptance set) is applied here, after the upgrade. ##### Supported host Apple Silicon — Mac mini today, Mac Studio at production tier. One idempotent startup orchestrates the local LLM runtime, the storage layer, and the assistant. ##### Roles A named human gardener owns the wiki promotion path, runs the runbook drills, and gates GDPR Article 17 erasure requests. Vacation mode hands the role off to a delegate with explicit scope. A Day in the Life. #### What a small team actually does with it Four scenarios that hit the main surfaces of the system. ##### Find the half-remembered thing An advisor asks: “Where is the contract draft Maria sent me last spring?” The assistant retrieves with hybrid search, cites the source email, and surfaces three related threads the advisor didn’t remember. ##### Time travel through the ledger A principal asks: “What did we know about the Omega deal on 1 March?” The bi-temporal fact ledger returns the graph as it stood that day — superseded values intact, never overwritten by later edits. ##### Ask for a deliverable, not a transcript An executive assistant types: “Excel of every invoice from supplier X over €5k since 2022.” The workbench drafts a reviewable script, runs it sandboxed, and returns a real downloadable file. ##### Catch the silent gap The Monday dashboard shows last week’s anomalies: a stakeholder who was always on the renewal thread but wasn’t this time. The advisor clicks through to the triggering message and decides whether to follow up. Nine Rules. #### The rules the system holds itself to SuperLocalBrain enforces nine unbreakable rules as project-wide invariants, plus a stack of amendment rules covering compression discipline, the critical-actions firewall, the watchdog, and the status surface. ##### R1 · Facts before guesses Use the language model only where real intelligence is needed; never to invent something a header already states. ##### R2 · Store each thing once Everything else is just a view of it. Markdown is canonical truth; databases are derived indexes. ##### R3 · Trust tier per claim GOLD, SILVER, or BRONZE — never mixed. Every consumer can filter by class. ##### R4 · Proof per claim Source, confidence, evidence, timestamp, model version, review status. Six fields, no exceptions. ##### R5 · Coreference before thinking “He agreed” is worthless until you know who “He” is. Pronouns are resolved up-stream. ##### R6 · Guided relation extraction Relations are extracted by asking constrained questions about pre-computed entity pairs, not by asking the model to free-form discover relations. ##### R7 · Wiki is interpretation, raw is truth The self-writing wiki is canonical interpretation; the raw inbox is canonical truth. A human gardener gates promotions. ##### R8 · Local at rest, networked at change Data sits locally. Network access is reserved for sanctioned change channels (IMAP ingest and the first-party PII engine). ##### R9 · Auto-tune read, human-gate write Read-side improvement loops can run autonomously. Write-side promotions (to the wiki, to the schema) always need a named human signoff. Stack at a glance. #### What runs the engagement A short table of generic capability categories. Specific vendor choices are deliberate and can be substituted without changing the architecture. Layer. Capability category. Why this layer. **Storage (graph)**. Embedded graph + vector store. Neighbourhood traversal and semantic similarity in one engine. **Storage (ledger)**. Bi-temporal fact ledger with append-only history. Time-travel queries: “what did we know on date X?”. **Search**. Lexical (BM25) + dense vector + cross-encoder rerank, RRF-fused. Lexical precision and semantic recall in one ranked list. **Inference**. Local language-model runtime, Apple-Silicon envelope. Reasoning stays on the host; nothing leaves the perimeter. **NLP**. Local coreference resolver + multilingual NER. Pronouns and entities resolved before any LLM call. **PII**. [cloak.business](project-cloak-business.html) at first-party. PII detection runs inside the perimeter under a first-party exemption. **API**. Model Context Protocol server with ~60 tools. Any MCP-capable client can drive the system — chat UI, IDE, custom integration. **Auth**. PASETO bearer tokens with audience binding. Capability-bound sessions; refresh-token reuse-detection on every renewal. **Status surface**. SwiftUI menubar indicator, content-blind. Operator visibility without ever showing answer content on-screen. **Audit + integrity**. Two-chain append-only audit log + off-volume anchor. Tamper-evident receipt for every state-changing action; meta-audit floor on a separate device. Fit & Limitations. #### Best fit and known limitations ##### Best for A 6–10 person professional-services firm or family office sitting on 15+ years of mixed personal and company files across multiple storage generations. Mixed-language corpora (German + English minimum). Teams that want cited answers and a defensible trail without sending anything to a cloud LLM. ##### Not the right fit Teams above 10 active users (RBAC for >10 users is V3+ deferred). Workflows that need full forensic chain — that’s LocalBrain’s territory. Teams happy with a cloud LLM and short-lived prompts; SLB is a custom on-premises engagement, not a SaaS subscription. ##### Known limitations Voice input, 3D graph visualisation, autonomous skill generation and full bi-temporal forensic chain are explicitly deferred to V3+. The faithfulness target re-benches after the production hardware upgrade. The wiki layer requires a named gardener role — a small but real operational commitment. #### Discuss a similar engagement If your team has fifteen years of files spread across three storage generations — and the right person on your team spends thirty minutes every day looking for the thing they half-remember — we can build the knowledge brain that ends that workflow, inside your perimeter. [Book a Consultation](contact.html) [← All Projects](projects.html) --- ## EU IT Migration Master GPT | curta.solutions URL: https://curta.solutions/project-eu-migration-master.html > Custom GPT for EU-focused IT and M365 migrations. Migration coaching with governance, risk management, and privacy-first implementation. Project • Custom GPT • Move. ### EU IT Migration Master Custom GPT for EU-focused IT and Microsoft 365 cutovers — a set coach that translates tough projects into clear, repeatable work packages with focus on rules, risk control, and privacy-conscious rollout. Custom GPT in ChatGPT. Move. Rules. Safety-by-Design. #### Project Description EU IT Move Master is a Custom GPT within ChatGPT, designed as a set coach for EU-oriented IT and Microsoft 365 projects. The GPT helps teams translate tough cutovers into clear, repeatable work packages — with focus on rules, risk control, docs, and privacy-conscious rollout. *GPTs are customizable versions of ChatGPT that can be tailored to specific purposes through instructions, knowledge, and skills.* #### Use Cases - **Set Move Scan** — Now state assessment, dependencies, and risk identification. - **Target Design & Move Roadmap** — Phase-based, prioritized, and traceable planning. - **Cutover & Rollback Planning** — Ops readiness for go-live. - **Docs & Handover Packages** — For IT ops and service control. - **Stakeholder Comms** — Control summaries, decision templates. Outputs. #### Typical Outputs ##### Assessment Checklists Set checklists covering ID, Devices, Data, Safety, and Applications for full scan. ##### Risk Register + Action Plan Logged risks with mitigation measures, owners, and timelines for ahead-of-time risk control. ##### Cutover Runbook Step-by-step cutover steps and stabilization steps for ops readiness. ##### Governance Building Blocks Roles, RACI matrices, control points, and approval workflows for set rollout. ##### Communication Templates Standardized comms building blocks for rollout and adoption messaging. ##### Handover Documentation Full docs packages for IT ops and service control teams. Rules & Audit fit. #### Built for EU Requirements The GPT is designed for set, docs-strong rollout and backs incorporating EU-relevant needs such as **data safety** and **auditability** into the process. **Note:** This tool does not replace legal advice. Final sign-offs should be provided by Safety, Audit fit, and Legal teams. ##### GDPR Awareness Built-in consideration for data safety needs in planning and execution. ##### Audit-Ready Outputs Docs standards that support auditability and audit fit verification. ##### Security-by-Design Safety considerations linked into planning from the start. ##### Structured Methodology Repeatable approach ensuring consistent quality and audit fit across projects. Access. #### Try the GPT EU IT Move Master is ready as a Custom GPT in ChatGPT. Use it to structure your next cutover project with rules-first approach. [Open EU IT Move Master in ChatGPT →](https://chatgpt.com/g/g-67c6d0462c8881919c19a30d820c26ae-eu-it-migration-master) May need a ChatGPT paid subscription — check now ChatGPT plans for access details. Built by curta.solutions. Fit & Limitations. #### Best fit and known limitations ##### Best for EU-based organisations migrating off US-hosted SaaS to sovereign-cloud alternatives (Nextcloud, Seafile, OnlyOffice, Mailcow) under DSGVO, Schrems-II, or sector-specific data-residency mandates. ##### Not the right fit Greenfield projects without a legacy US-SaaS estate; teams that have already done sovereign move and need ongoing ops rather than cutover (consider [solutions / rollout](solutions-deployment.html)). ##### Known limitations Move timelines depend heavily on user-data load and licenses-cycle fit; some legacy link-ups need bespoke connectors before cutover; the cost-equation can shift if the source SaaS vendor opens an EU-resident tier mid-project. #### Need migration support? The GPT is a starting point. For full cutover rollout, let's discuss your specific needs. [Book a Call](contact.html) [← All Projects](projects.html) --- ## Approach — How We Deliver | curta.solutions URL: https://curta.solutions/approach.html > Our delivery methodology aligned with ITILv4: Assess, Design, Implement, Operationalize, Improve. Security-by-design, governance-first, audit-ready. How We Deliver ### Our Approach A set rollout methodology matched with ITILv4 Service Value Chain — ensuring rules, measurability, and steady gains at every phase. Guiding Principles #### How We Work ##### Security-by-Design Safety controls and audit fit needs are built into solutions from the start, not added as an afterthought. ##### Governance + Controlling Cost clear view, speed measurement, and SLA-based controlling ensure lasting, accountable ops. ##### Auditability Full policies, logging, and traceability by default. Every solution is ready for in-house and outside audits. Rollout Phases #### Mapped to ITILv4 01 ##### Assess Systems study, risk assessment, audit fit posture review, and biz goal fit. We understand your now state before proposing changes. ITILv4 Mapping PLAN 02 ##### Design Design design, safety controls definition, and target operating model. Clear docs of the solution before rollout begins. ITILv4 Mapping DESIGN & TRANSITION 03 ##### Implement Phased rollout with tight switches, link-up testing, and auto-work rollout. Rules controls active from the start. ITILv4 Mapping OBTAIN / BUILD 04 ##### Operationalize Tracking setup, KPI dashboards, user training, and full docs. Your team can operate the solution independently. ITILv4 Mapping DELIVER & SUPPORT + ENGAGE 05 ##### Improve Steady gains cycle based on ops data, feedback, and evolving needs. Regular reviews and tuning. ITILv4 Mapping IMPROVE (Ongoing) What This Means #### ITILv4 Alignment Ensures ##### Governance at Every Phase Clear duties, logged decisions, and audit trails throughout the project lifecycle. ##### Measurable Outcomes KPIs, SLAs, and speed metrics defined upfront and tracked throughout ops. ##### Clear Handover Points Logged switches between phases with acceptance criteria and rollback plans. ##### Sustainable Operations Your team can operate, maintain, and improve the solution after project completion. #### Ready to start a project? Book a call to discuss your needs and how we can help. [Book a Call](contact.html) [View Our Experience](experience.html) --- ## Industries — Regulated Mid-Market | curta.solutions URL: https://curta.solutions/industries.html > IT solutions for regulated industries, multi-country organizations, and data-intensive environments requiring GDPR, ISO 27001, and NIS2 compliance. Industries ### Who We Help We focus on regulated, data-sensitive settings where audit pressure meets the need for modern tech and automation. Primary Focus #### Regulated Mid-Market Mid-market firms face a tough mix. They carry the same rules as big firms. But they run lean teams on tight budgets. We help them roll out enterprise-grade tools at low cost. ##### Common characteristics - **Audit pressure** — GDPR, ISO 27001, NIS2, sector-specific rules - **Lean IT teams** — Need for automation and lean ops - **Cost control** — Clear budgets and ROI - **Audit needs** — Routine in-house and outside audits ##### Finance & Banking GDPR, regulator reports, records-room control, API links to ledgers and bank tools. GDPR Audit API ##### Legal & Professional Services Virtual data rooms, doc handling, client privacy, safe shared workspaces. VDR Confidentiality DLP ##### Manufacturing & Engineering ERP link-up, smart upkeep, process automation, supply chain data safety. ERP ML Automation ##### Healthcare & Research Patient record safety, study data control, safe team work, audit docs. GDPR Research Privacy Geographic Scope #### Multi-Country Organizations Firms that work in many countries need IT patterns that scale. The patterns must work worldwide. They must also fit local needs. ##### What we deliver - **Set safety baselines** — Same rules at every site - **One identity hub** — Azure AD / Entra ID with local fit - **Global endpoint control** — Intune rules at scale - **Local rules in view** — GDPR, local data home needs 26 Locations Supported Global sites 700+ Endpoints Managed Global rollout 5,000 Accounts Governed User life cycle ITILv4 Framework Service work Data Requirements #### Data-Intensive Environments Firms that work with lots of touchy data need strong rules, access checks, and audit trails. ##### Key requirements - **Sharing rules** — Tight checks on outside sharing - **Data room control** — Safe space for due diligence, M&A, and legal work - **Access logs** — Full audit trails for all data use - **Keep rules** — Auto life-cycle steps - **Private cloud** — Self-hosted setup when public cloud won't fit ##### Private Cloud Case Study See how we shipped a self-hosted file sync & share tool with Seafile for a client who needed full data control. [View Seafile Case Study →](experience-seafile.html) #### Working in a regulated industry? Book a call to talk about your audit and tech needs. [Book a Consultation](contact.html) [View Our Experience](experience.html) --- ## Healthcare PII Anonymization — HIPAA + GDPR | curta.solutions URL: https://curta.solutions/industries-healthcare.html > Healthcare PII anonymisation aligned to HIPAA + GDPR. anonym.life middleware, anonymize.solutions enterprise tier, ML on protected data with proper controls. Industries ### Healthcare PII Anonymization — HIPAA-Aligned, GDPR-Compliant By [George Curta](about.html) · Founder, curta.solutions · Updated May 24, 2026 Healthcare data carries the highest trust level under GDPR Article 9. It is also the entire scope of HIPAA in the US. The curta.solutions product family covers three distinct healthcare patterns. Privacy middle-tier sits between clinical systems. Firm-wide PII PII strip ships with healthcare presets. ML on protected data uses reversible alias-swap. This page lays out which tool fits which pattern. PHI Finding #### What HIPAA PHI identifiers does anonymize.solutions detect? anonymize.solutions ships a HIPAA-matched preset covering the 18 PHI IDs defined under HIPAA Safe Harbor (45 CFR 164.514). The list includes names, geographic subdivisions below state, all dates except year, phone numbers, fax numbers, email addresses, and SSN. It also covers medical record numbers, health plan beneficiary numbers, account numbers, certificate/license numbers, vehicle IDs, device IDs, web URLs, and IP addresses. The final categories are biometric IDs, full-face photographs, and any other unique finding number. The Safe Harbor list is the deterministic floor. If all 18 identifier categories are removed or transformed and the covered item has no actual knowledge of residual re-identification risk, the data is considered de-found for HIPAA purposes. anonymize.solutions implements each category as a named recognizer that can be lets, disabled, or tuned per workflow. The Expert Determination pathway (45 CFR 164.514(b)(1)) is the alternative HIPAA route. A qualified statistician certifies that the risk of re-identification is very small. anonymize.solutions outputs a per-document risk metric (k-anonymity bucket size, distinct-value counts on quasi-IDs). This feeds directly into Expert Determination proof packs. For GDPR Article 9 special category data, the same matchers run with EU-specific extensions. These include German Krankenversichertennummer, French numero de securite sociale, and Italian codice fiscale. ICD-10 and ATC pharmaceutical codes also act as indirect health IDs under Recital 35. The tool backs HIPAA workflows; the covered item remains the accountable party for the determination, docs, and the residual-knowledge attestation. Middle-tier Pattern #### How does anonym.life keep clinical data flowing between systems without exposing patients? anonym.life sits between data vendors (hospitals, labs, payers) and downstream service vendors (analytics, billing, e-prescription, telemedicine) as a privacy middle-tier. Touchy IDs are replaced with reversible tokens at the boundary. Downstream systems only see pseudonyms. Narrow release releases the first values only to authorised endpoints holding the matching skill. The technical pattern is straightforward. A HL7 FHIR or HL7 v2 message enters the middle-tier. The middle-tier tokenises identifier fields (patient.name, patient.identifier, address, telecom) with format-preserving encoding. It forwards the message to the downstream system. On the return path, it de-tokenises the response — if it contains pseudonyms — only if the requesting role holds the matching skill. Key holding is the load-bearing design choice. anonym.life uses Bring-Your-Own-Key with MPC threshold holding. The re-identification key is split across multiple trustees (e.g. clinical director, DPO, hosting vendor). Re-identification needs a quorum of trustees to assemble the key. No single party — including curta.solutions — can unilaterally reverse the alias-swap. The audit trail captures every tokenisation and re-identification event. Each record includes the requesting role, the legal basis cited, and the timestamp. The log is append-only and signed, suitable for proof in DPIA reviews and supervisory body audits. ML on Protected Data #### Can I train ML models on patient data without breaking GDPR Article 9? Yes. GDPR Article 9(2)(j) permits processing of health data for scientific research where data is pseudonymised and the controller applies right safeguards. Pair anonym.life or anonymize.solutions for the alias-swap layer with a logged DPIA and the technical-organisational measures listed in your processing record. The Article 9(2)(j) gate is narrow. It needs Union or Member State law as the legal basis, proportionality to the aim pursued, respect for the essence of the right to data safety, and specific suitable measures to safeguard fundamental rights. In Germany, the relevant national law is BDSG §27, which expands the basis for scientific research. The real training pipeline runs in stages. The alias-swap layer transforms clinical data at the source-system boundary. The pseudonymised dataset moves to the training setup. Model training happens on pseudonyms only. The team evaluates model outputs for memorisation (extraction attacks against the final weights). The model ships without the re-identification key reaching the inference setup. Differential privacy is the additional layer where the model itself could leak training-set membership. For deep models on small cohorts (less than ~10,000 patients) the recommendation is DP-SGD with a logged epsilon budget. For classical ML on larger cohorts, k-anonymity buckets on quasi-IDs are usually sufficient. The DPIA docs the data flow, the alias-swap mechanism, the key holding arrangement, the re-identification rules, and the residual risk assessment. It is the controller's duty. It is also the supervisory body's reference document during an audit. Rollout Fit #### What deployment models does a German Krankenhaus or Praxis need? A German Krankenhaus typically needs Self-Run (on-premises, no cloud egress). A Praxis or MVZ can use Run Private (single-tenant SaaS in EU). Both need EU data residency and ISO 27001-matched hosting (Hetzner). The choice is either anonym.life's BYOK + MPC threshold holding (Krankenhaus scale) or anonymize.solutions' Firm-wide tier with Zero-Knowledge auth (Praxis scale). The Krankenhaus rationale has three parts. Hospital info systems (HIS) are typically segmented from the public internet by policy. The §75c SGB V requirement for state-of-the-art IT safety in hospitals over 30,000 cases per year drives explicit on-premises rollout. The link-up surface (KIS, RIS, PACS, LIS) is large enough to justify set systems. The Praxis or MVZ rationale is other. The ops footprint is smaller. Most practices already run the PVS (Praxisverwaltungssystem) in the cloud. The cost of running on-premises systems is disproportionate to throughput. The gematik TI (Telematikinfrastruktur) connector handles the rule-bound transport layer. Hosting choice matters for both. Hetzner data centres in Germany are the typical answer for EU data residency with ISO 27001:2022 cert. AWS Frankfurt and Azure Germany West Central are acceptable where the client accepts US CLOUD Act exposure with right SCC and TIA docs. Buy-in #### How does curta.solutions support healthcare engagements? curta.solutions runs healthcare engagements as scoped Rollout engagements. The scope covers scan of in-scope systems, DPIA support, PII strip layer design and rollout, link-up with HIS/EHR/PVS, and audit-ready handover docs. The localBrain buy-in is ready where forensic-grade proof chains are needed (e.g. complaints handling, fraud investigations). A typical Krankenhaus buy-in runs 8 to 16 weeks. The first phase is 2 weeks of scan (system stock, data-flow mapping, DPIA scoping). The second phase is 4 to 8 weeks of design and rollout (PII strip middle-tier, key holding, link-up with KIS/LIS/RIS). The third phase is 2 to 4 weeks of handover (runbooks, on-call steps, audit packs). A Praxis or MVZ buy-in is shorter (4 to 8 weeks). Tasks include tenant provisioning on Run Private and recogniser tuning for the practice's specific PVS. The buy-in also covers PII strip policy setup, staff training on Article 4 AI literacy where AI tools are in use, and the DPIA docs pack. The localBrain pattern is for cases where every re-identification event needs to be proof-grade. Outputs include a forensic chain-of-holding log, signed timestamps, and a clear separation between investigators (who request re-identification) and trustees (who approve and execute it). This is typical for complaints handling, fraud investigations, and litigation scan. curta.solutions does not provide medical, legal, or audit fit opinions. Those remain with the covered item, its DPO, and its legal counsel. The outputs support the covered item's HIPAA and GDPR obligations. They do not transfer checks. Trade-offs #### Best fit and known limitations ##### Best fit Krankenhäuser, MVZs, Arztpraxen, payers, and clinical research organisations. These need to move set PHI between systems with reversible alias-swap and audit-ready proof. ##### Less suitable Pure unstructured free-text without any set identifier fields. The toolkit works best where HL7, FHIR, DICOM, or set CSV is the transport. ##### Known limitations Designed for HIPAA workflows; does not certify covered items as HIPAA-audit-fit. Statutory interpretation of HIPAA, GDPR Article 9, BDSG §27, and §75c SGB V remains with the covered item and its counsel. Related Solutions #### Adjacent Engagements [ ##### anonym.life — Clinical Middleware Privacy middle-tier with BYOK + MPC threshold holding. Built for hospital-grade alias-swap between clinical systems. Learn more → ](project-anonym-life.html) [ ##### anonymize.solutions — Enterprise Tier Firm-wide PII PII strip with HIPAA Safe Harbor presets and Zero-Knowledge auth. Three rollout models, including air-gapped. Learn more → ](project-anonymize-solutions.html) [ ##### ML on Protected Data — Case Study Reference buy-in for training ML models on pseudonymised ops data with logged proof chain. Learn more → ](case-study-predictive-maintenance.html) #### Scoping a healthcare engagement? Book a call to walk through your in-scope systems, PHI stock, rollout fit, and a fixed-price scan sprint. [Book a Call](contact.html) [All Industries](industries.html) --- ## About — Since 1998 | curta.solutions URL: https://curta.solutions/about.html > IT consulting since 1998: secure system integration, AI enablement, process automation, and compliance-first delivery. curta.solutions. Since 1998. ### About curta.solutions IT services for over 27 years. Today the focus is on modern roll-outs. Plus safe link-ups, AI use, and auto-work. Audit fit built in. #### Our Focus curta.solutions builds firm-grade IT plans for rule-bound, data-touchy setups. We help teams upgrade their tools. We set up AI safely. We auto-run ops. All with full GDPR, ISO 27001, and ITILv4 fit. ##### What makes us different - **Docs-first rollout** — Every project includes full runbooks, design docs, and handover packages. - **Rules-first approach** — Audit fit is built in from day one, not added as an afterthought. - **Safety-by-design** — Zero-Trust principles and audit-ready controls in every buy-in. - **ITILv4-set services** — Proven service control framework for measurable, lasting outcomes. #### Credibility Worked as IT Solutions Architect and Head of IT in global setups. Led teams. Drove strategy. Shipped cross-team roll-outs with strong biz-IT fit. ##### Key achievements - Global ops control: **700+ endpoints across 26 global locations**. - Built and led IT teams (up to **12 members**) and safety teams (up to **4 members**) - Designed and set up **Zero-Trust safety** and ISO 27001-matched IT service control. - Built **SharePoint Virtual Data Rooms** at scale (up to 80 data rooms and 5,000 accounts) Audit fit & Trust. #### Our Commitment ##### GDPR Alignment All work built with data safety by default. Privacy-shield patterns for AI roll-outs. Clear data-use agreements. ##### ISO 27001 Practices Safety checks. Risk scoring. Info safety control matched to ISO 27001 needs. ##### ITILv4 Service Management Services set around the ITILv4 Service Value Chain. Built for rules, metrics, and steady gains. ##### Audit-Ready by Default Full logging. Traceability. Docs in every solution. Ready for in-house and outside audits. Partner Network. #### MacXpress IT Consulting ##### Strategic IT Consulting & Secure System Management MacXpress IT Consulting offers added services. IT controlling. Safety and audit fit. Ops control. Microsoft 365 work. [Visit macxpress.net →](https://macxpress.net) #### Let's work together Book a call to discuss your IT strategy, safety, or auto-work needs. [Contact Us](contact.html) [View Our Experience](experience.html) --- ## Insights — Resources & Blog | curta.solutions URL: https://curta.solutions/insights.html > Resources on AI governance, GDPR compliance, Microsoft 365 security, Power Platform automation, and IT best practices. Insights ### Resources & Knowledge Real guidance on AI rules, safety, audit fit, and auto-work for rule-bound teams. Pillar Topics #### Key Focus Areas AI Rules ##### GDPR-Compliant AI Prompting Templates, policies, and audit checklists for safe AI usage in rule-bound setups. How to prevent data leakage while letting AI productivity. GDPR AI Policy Privacy Engineering ##### AI Privacy Shield Architectures Reversible PII strip patterns for AI link-ups. How to use AI without exposing private data to the model. Privacy PII strip Design Microsoft 365 ##### Microsoft Purview for DLP & Audit What actually works in firm-wide Purview rollouts. Real guidance on DLP, trust level labels, and audit logging. Purview DLP Audit fit Copilot ##### Copilot Governance Firm-wide adoption without data leakage. Rules frameworks, user policies, and tracking for Microsoft Copilot rollouts. Copilot Rules M365 ERP Link-up ##### Business Central Integration Patterns Finance auto-work and traceability with Dynamics 365 Biz Central. API link-up patterns with DATEV, banking, and other systems. Biz Central API Finance Safety ##### Zero-Trust in Microsoft 365 Pragmatic rollout plan for Zero-Trust design. ID, device, data, and network controls with Microsoft safety stack. Zero-Trust Safety M365 Lead Magnets #### Downloadable Resources Real tools and checklists for IT leaders in rule-bound teams. ##### AI Governance Starter Kit Policy templates, risk assessment framework, and rollout checklist for GDPR and ISO 27001 matched AI rules. [Request Access →](contact.html) ##### M365 Security Baseline Checklist Full checklist for Microsoft 365 safety setup. ID, devices, data safety, and tracking controls. [Request Access →](contact.html) ##### Automation ROI Calculator Spreadsheet tool for estimating ROI on Power Platform auto-work projects. Process selection criteria and biz case template. [Request Access →](contact.html) #### Want personalized guidance? Book a call to discuss your specific challenges and needs. [Book a Call](contact.html) [Explore Solutions](solutions.html) --- ## Contact — Book a Consultation | curta.solutions URL: https://curta.solutions/contact.html > Contact curta.solutions for AI readiness sessions, integration assessments, and IT consulting for regulated organizations. Contact ### Let's discuss your requirements Book a readiness session, request a connection assessment, or ask for a proposal. We respond within one biz day. Get in Touch #### Contact Form Name * Email * Company Role Main Interest * Select an area... AI Rollout & Rules System Link-up IT Safety & Audit fit Process Auto-work Cloud & M365 Services Other / Broad Inquiry Audit fit Constraints Select if applicable... GDPR ISO 27001 NIS2 Multiple frameworks Not sure / Need guidance Message * I consent to the processing of my data for responding to my inquiry. [Privacy Policy](privacy.html) * I would like to receive occasional insights on AI rules and safety topics. (Optional) Send Message This site is protected by reCAPTCHA and the Google [Privacy Policy](https://policies.google.com/privacy) and [Terms of Service](https://policies.google.com/terms) apply. ##### Thank you for your message! We'll get back to you within one biz day. What to Expect #### Consultation Options ##### AI & Security Readiness Session Assess your AI, safety, and audit fit posture. Find gaps and chances with a set review. AI Rules Safety Audit fit ##### Integration Assessment Review your now systems and find link-up chances with Microsoft 365, Azure, ERP, and APIs. M365 Azure ERP ##### Fixed-Scope Workshop Focused scan session on a specific topic: AI readiness, M365 rules, or link-up design. Workshop Scan ##### Project Proposal Request a scoped proposal for system link-up, AI rollout, safety assessment, or process auto-work. Each proposal targets rule-bound setups with explicit GDPR, ISO 27001, and ITILv4 constraints. All engagements start with a scan session to validate needs and confirm scope before any commitment. ##### Compliance & Trust We handle all consultations and comms in audit fit with GDPR. We process your data only to respond to your inquiry. GDPR Audit-fit ISO 27001 ---