On-Site AI Privacy Guard

Use smart AI.
Keep private info private.

Cordon lets your team use powerful AI helpers without letting private information ever leave your building. It sits on your own computers, right in the middle of every AI request, and trades every real name or number for a fake tag before anything goes out.

The problem

Smart AI helpers live on the internet, run by other companies.

When your team types in a patient's name or an account number, that information leaves your building. For a hospital or a bank, that's a real risk: it can break the law and lose people's trust.

What Cordon does

The outside AI only ever sees fake tags.

Before anything goes out to the AI, Cordon hides the private parts. It trades each real name or number for a fake tag. When the answer comes back, Cordon puts the real information back in, but only inside your building.

1

Ask

Your team asks the AI a question. It may have private info in it.

2

Hide & send

Cordon hides the private parts. It sends only safe, fake tags to the AI.

3

Bring it back

The answer returns. Cordon fills the real info back in, just for your team.

Architecture

Sensitive data never becomes a dependency.

Cordon's sealed core runs entirely on-premise. Contractors and partner tools only ever touch a narrow, PHI-free control plane. The parts that actually matter are unreachable by construction, not by trust.

🏥 On your premises — on-prem appliance Raw private data exists only here, only transiently
LiteLLM-style AI proxy Policy enforcement Redaction engine Fingerprint / tokenizer Signed metering ledger
☁ Approved external models — egress-gated
Claude / GPT / Copilot APIs Local models (fully air-gapped option)

Only sanitized, tokenized payloads for approved models are allowed out. Anything unapproved is blocked and logged, never guessed at.

🔧 Partner & dashboard tools — narrow control-plane access only
Policy management UI Audit-trail explorer Spend & violation dashboards

Reads only PHI-free, tokenized records through scoped access, with no path to raw data or the sealed core.

⬛ Never exposed, not a dependency
Core agent runtime & routing logic Answer assembly & scoring engine Patent-pending IP portfolio
Why you can trust it

Proof, not promises.

🏢 On your computers

Nothing private leaves the building. Cordon runs on commodity NVIDIA hardware inside your own walls.

🔏 Signed records

Every action gets a locked, tokenized record, proof of every call you can show an auditor later.

🚫 Blocks the unsafe

Risky requests are stopped outright, not guessed at. If it can't be made safe, it doesn't go out.

👥 Granular attribution

Every request is logged to the person, the individual agent, and the specific policy line involved.

See Cordon on your own data.

Built for hospitals, banks, and any team that handles private information under strict compliance rules. Don't attend a compliance audit without it.

Talk to our team
Tell us a bit about your organization and we'll follow up to set up a live demo or answer your questions directly.