Skip to content

Work Freely. Disclose Nothing.

Keepiit is the privacy workspace for the AI era, built for the professions where a client’s details can never leave the room.

The basics

What is PII?

Personally Identifiable Information, or PII, is any information that can identify a real person.

Some of it identifies someone outright: a full name, an ID number, an email address, a case or patient number.

Most of it doesn’t. A birth date on its own tells you nothing. Neither does a postal code, a job title, or the date of a hearing. Put three of them in the same paragraph and you usually have one person. This is what makes PII hard to remove. It isn’t a list of sensitive words. It’s whatever combination lets someone work out who the document is about.

Privacy laws treat it the same way. GDPR and HIPAA hold the holder of the document responsible for all of it, not just for the obvious fields.

Professional work runs on documents like this. In law, medicine, finance, insurance and more, PII is in almost every one of them. A referral letter can hold a name, a diagnosis and an insurance number in one sentence. A due diligence file can lay out a client’s entire financial history.

Patient John Miller, born 12 Mar 1984, was seen at St. Mary’s Clinic in Vienna and asked that the invoice go to j.miller@mail.com.

  • John MillerPerson
  • 12 Mar 1984Date
  • St. Mary’s ClinicOrganization
  • ViennaLocation
  • j.miller@mail.comEmail

Where the industry stands

AI is already part of the work

AI use has grown to the point where it’s no longer separate from the job. It reviews the contract, weighs the diagnosis, checks the numbers, and hands back an answer a professional signs off on.

0%

of doctors use AI in their practice. In 2023 it was 38%.

AMA, 2026 Physician Survey on Augmented Intelligence

0%

of legal professionals use generative AI at work, more than double the year before.

8am, 2026 Legal Industry Report

0%

of tax professionals who use generative AI use it at least weekly. A third of them, several times a day.

Thomson Reuters Institute, 2026 AI in Professional Services Report

This is not a trial run anymore. It’s how the work gets done.

The catch

Sensitive data goes with it

An AI tool can’t review a document it hasn’t been given. To get the file summarised, the file has to be uploaded. To get the answer, the document has to be sent.

And it is sent to a company. The AI provider is a third party, and it relies on third parties of its own, so the confidentiality of the document now rests on their data security rather than on the firm’s own.

That is a disclosure. For a lawyer it’s privileged material, and privilege depends on who has seen it. For a doctor it’s protected health information, which cannot go to an outside company without an agreement in place. For an accountant it’s client information covered by a rule they’re personally bound to. The obligation doesn’t change because the recipient is a model instead of a person.

Nothing here requires a breach, a hacker or bad intent. The tool works exactly as intended. The document just ends up in the hands of a company the client never agreed to, kept for a length of time nobody chose, read by whoever has access on the other side.

77%

of employees paste company data into AI tools. 82% of them do it from a personal account.

LayerX, Enterprise AI and SaaS Data Security Report 2025

43%

of firms have no AI policy at all.

8am, 2026 Legal Industry Report

What firms do about it

The two usual answers

Faced with that, most organisations land on one of two policies.

Ban the use of AI.

No client files in AI, full stop. The confidentiality problem disappears, and so does the pace. Competitors are not waiting. They are turning the first draft around in an afternoon and pricing accordingly. A ban also rarely holds. Individual use already runs well ahead of official policy, so the result is usually not zero use. It is use nobody can see, on a personal laptop, with no record of what was sent.

Firms using AI
Firms with a ban

Allow it, under rules.

AI is permitted, on the condition that identifying details come out of the document before it goes anywhere. On paper this works. In practice it puts the whole obligation on whoever happens to be holding the file, and there is no realistic way to supervise it. AI is not a system anyone logs into. It is a browser tab, a phone, a personal laptop at home on a Sunday, and it sits in every tool people already use. Nobody sees the document at the moment it is pasted. And the rule quietly assumes someone will read every line and catch every identifier, perfectly, every time. That holds on a two-page letter. It does not hold on a sixty-page agreement, a folder of forty scans, or a Tuesday afternoon before a deadline. The step is manual and unbillable, which makes it the first thing to go when time is short.

Even one lazy workaround can cost the whole team its compliance.

Keepiit

There is a better, third option

Keepiit is a private workspace for confidential work. Redact, draft, ask any leading model, and more, without the sensitive data ever leaving the machine. Detection runs locally, on a lightweight engine built and specifically trained for the job. Nothing is uploaded for processing, and no server holds a copy, because there is no server in the path. That is not a policy about how data is handled. It is a description of where the software runs.

More tools on the way

Redaction Studio

Detects and removes PII across full documents, and takes custom instructions for a single matter: a specific term to always remove, or a whole category to look for, described in a word. Runs offline, at the length of documents the work actually involves, and produces a record of what was removed.

referral_letter.pdf

Patient Anna Keller[PERSON:0001], born 03 Jun 1979[DATE:0001], reached at +43 660 231 8744[PHONE:0001], insurance no. K-2214[ID:0001], treated in Vienna[LOCATION:0001].

5 identifiers replaced · record saved

Let’s start keepiing your data private

A private walkthrough of Keepiit, on real documents, with the team.

Prefer email?

support [at] keepiit [dot] com

Windows will flag the installer. Here’s how to get past it in 3 steps.

  1. Open the downloadedKeepiit-Setup.exe.
  2. When SmartScreen appears, click More info.
  3. Then click Run anyway at the bottom.

Why this happens: SmartScreen warns about installers it hasn’t seen many times before. We’re working on getting the Windows build signed; once that lands, this warning goes away.

Questions, feedback, demo bookings, or enterprise inquiries?
Write to support [at] keepiit [dot] com or use the form below.

0/1000