CamoText
Compliance

Compliance and confidentiality
starts on your device.

CamoText masks content on your own machine, before anything reaches an external service. This page maps some specific obligations, by regulation and profession, to how our architecture mitigates them.

On your device
Re: Margaret Ellison v. Harding Freight Ltd
Matter 2024-0417 · DOB 14/03/1968
NHS 485 777 3456
The only version that leaves
Re: <PERSON_a41f2c9d> v. <ORGANIZATION_9c02e1b4>
Matter <ACCOUNT_5518f0aa> · DOB <DATE_71ba9c3d>
NHS <ID_0c3d77e2>

01.There Is No Second Party

Nearly every privacy obligation on this page is triggered by a disclosure of data moving from you to someone else. Cloud redaction tools, AI platforms, and transcription services all trigger it, then spend their own compliance pages explaining how they mitigate it: contractual terms, encryption in transit, retention windows, sub-processor lists which may periodically change.

CamoText never receives your data. Not encrypted, not transiently, not in logs. The masking happens inside a single local process, in memory, on hardware you already control. For the masked content, the obligations below aren't just mitigated; many are never engaged at all.

No Processor

We don't process personal data on your behalf. No data processing agreement to negotiate, no sub-processor register to monitor, no vendor to add to your Article 30 record for this product.

No Transfer

Nothing crosses a border, because nothing leaves the device. International transfer rules aren't engaged by CamoText itself.

No Breach Surface

We hold no copy of your documents. A compromise of our systems cannot expose your client data, because your client data was never there.

Comparison of a cloud redaction workflow and the CamoText workflow In a cloud workflow, unmasked client data crosses the trust boundary twice: once to the redaction vendor and once to the AI provider. With CamoText, only masked text crosses the boundary, and it crosses once. TYPICAL CLOUD REDACTION WORKFLOW trust boundary Your deviceunmasked file client data leaves Redaction SaaSprocessor · DPA · logs AI providerprocessor · retention Two disclosures. Two contracts. Two retention policies. Two breach surfaces. WITH CAMOTEXT trust boundary Your device — CamoText (in-memory, single process) detect → mask → review → key held locally AI providersees pseudonyms
No processor between you and the AI service.

02.GDPR: Pseudonymisation as a Named Article 32 Measure

The GDPR requires a lawful basis, a security posture proportionate to the risk, and control over onward disclosure for the use of AI on personal data.

Masking before the prompt helps address all three, and is the one measure the Regulation names in the text of the security article itself.

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Security of processingArt. 32(1)(a) Measures appropriate to the risk, expressly including pseudonymisation and encryption. Pseudonymisation is the product. Consistent tokens replace direct and indirect identifiers before any external system is involved.
Pseudonymisation, properly doneArt. 4(5) The "additional information" that would allow re-identification must be kept separately and protected. The mapping key is written only to a local path you choose, or discarded entirely. It's not bundled with the output and not transmitted (separation contemplated by Art. 4(5)).
Data minimisationArt. 5(1)(c) Only data adequate and limited to what's necessary for the purpose. Analytical purposes rarely require identity. The human-in-the-loop review process ensures identifiers avoid exposure to the AI service.
Processor obligationsArt. 28(3) A written contract with anyone processing personal data on your behalf. Not engaged. CamoText LLC is not a processor of your data: we have no access to it at any point. No DPA is required, and none is offered, because there's nothing to govern.
International transfersCh. V, Art. 44–49 A valid transfer mechanism before personal data leaves the EEA. Not engaged by CamoText. Where you subsequently use a US-hosted AI service, the material you transfer contains pseudonyms rather than identifiers, materially changing the transfer risk assessment.
DPIAArt. 35 An assessment where processing is likely to result in high risk. Masking is a mitigating measure to record under Art. 35(7)(d). Because the tool performs no transmission and retains nothing, its own risk profile is short to document.
Record of processingArt. 30 Categories of recipients, transfers, and safeguards. CamoText adds no recipient and no transfer to your register.
Breach notificationArts. 33–34 Notification of breaches affecting personal data, with severity assessed by reference to the data exposed. Where exposed material was masked and the key held separately, the severity assessment changes accordingly. We never receive your data.
CLARIFICATION

Pseudonymised, not anonymous. We describe CamoText's output as pseudonymised in GDPR context. Pseudonymised data remains personal data under Recital 26. Whether a given output is genuinely anonymous depends on the residual re-identification risk in that specific document; free text can identify a person without naming them. That judgment is yours, which is why every output is presented for human review before it goes anywhere. Anyone selling "GDPR-compliant anonymisation" as a guaranteed output state is overstating what any software can determine.

AI Act

Regulation (EU) 2024/1689 imposes obligations on deployers as well as providers, phasing in through 2027. Masking inputs doesn't itself satisfy any AI Act obligation, but it reduces the personal-data footprint of deployment and supports the AI-literacy and governance measures firms are being asked to evidence via a demonstrable, defensible process. The EDPB's Opinion 28/2024 on personal data in AI models is the useful companion reading for how supervisory authorities are framing model inputs.


03.UK GDPR, the ICO, and SRA Confidentiality

The UK GDPR and Data Protection Act 2018 track the EU analysis above. Two additions matter for UK firms.

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
ConfidentialitySRA Code of Conduct, para. 6.3 Client information kept confidential unless disclosure is required or permitted by law, or the client consents. Uploading an unredacted matter file to a third-party AI service is a disclosure. Properly masking first can mean no identifiable information is disclosed, so material-specific consents may not be required.
Competence and supervisionSRA Principles; Code paras. 3.2–3.5 Services delivered competently, with effective supervision of the work. Human-in-the-loop review is mandatory in the workflow, as CamoText cannot automatically communicate output to an external service. Every detection is presented for confirmation, reversal, or extension before output.
ICO anonymisation guidance A risk-based, documented assessment of re-identification, including the "motivated intruder" test. CamoText produces the pseudonymised output and a reviewable record of what was replaced. The re-identification assessment remains a human judgment, supported by a visible list of every substitution made.
Legal professional privilege Preservation of privilege, which can be compromised by disclosure to third parties. No third party receives the material until the output is reviewed and confirmed as not containing identifiable privileged information.
NOTE

Buying from the UK? CamoText Pro is the right product for English-language practice. International adds recognition models for Spanish, French, German, and Italian document content: choose it only if your matters involve those languages, not because you're outside the US.



05.HIPAA: Safe Harbor Identifiers, and Why We're Not a Business Associate

The de-identification standard at 45 CFR § 164.514(b)(2) lists eighteen identifier categories. Adequately mask and remove all eighteen, with no actual knowledge that the remainder could identify the individual, and the information is no longer protected health information.

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Safe Harbor de-identification45 CFR § 164.514(b)(2) Removal of eighteen enumerated identifier categories. CamoText detects pertinent data across the categories, including names, geographic subdivisions, contact details, account and record numbers, device identifiers, URLs, IP addresses, and biometric-adjacent references, and has an intuitive highlight-to-anonymize user feature for the subjective category details.
Re-identification key§ 164.514(c) Any code permitting re-identification must not be derived from or related to the individual, and must not be disclosed. Tokens are randomly generated. The key is stored locally at your election, or discarded.
Business associate§ 164.502(e); § 164.308(b) A BAA with anyone creating, receiving, maintaining, or transmitting PHI on your behalf. Not engaged. We don't create, receive, maintain, or transmit PHI. Licensed desktop software that never contacts the vendor doesn't make the vendor a business associate. No BAA is required from us.
Minimum necessary§ 164.502(b) Limiting use and disclosure to the minimum necessary. Masking is the operational form of this rule when the recipient is an analytical tool that has no need to know identity.
Psychotherapy notes§ 164.508(a)(2) Authorisation for most uses and disclosures, with narrow exceptions. Process notes can be worked with locally, and if AI assistance is used, only de-identified narrative leaves the machine. Try CamoVoice for a HIPAA-compliant transcription service.
CAVEAT

Read this before relying on Safe Harbor. Automated detection does not equal certified de-identification. Free-text clinical narrative can identify a patient without containing a single listed identifier, such as a rare diagnosis, a described incident, or an employer. Safe Harbor also requires the absence of actual knowledge of residual identifiability, a human determination no software can make for you. CamoText is built to make that review fast and complete, not to remove it. If you need a formal § 164.514(b)(1) expert determination, engage a qualified statistician.


06.§ 203 StGB, BRAO, and the DSK Position on AI

Germany is the jurisdiction where the case for local masking is strongest, because breach of professional secrecy can be a criminal offence.

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Criminal secrecy§ 203 StGB Unauthorised disclosure of a secret entrusted to a lawyer, doctor, or psychotherapist is a criminal offence. § 203(3) permits involvement of assisting persons, subject to obligations and care in selection. The cleanest position is not to rely on the assisting-person route at all. A vendor who never receives the secret is not an assisting person, and no disclosure occurs.
Professional duty§ 43a(2) BRAO Verschwiegenheitspflicht extending to everything learned in the course of the mandate. Removing identifying content before any external service is used; the mandate details stay on the Kanzlei's own hardware.
Supervisory guidanceDSK orientation on AI; BDSG German authorities have emphasised input minimisation and caution about entering personal data into AI systems. Input minimisation is precisely the function performed, with a bundled model trained on German-language names and organisations in CamoText International.
Works council§ 87(1) Nr. 6 BetrVG Co-determination for technical systems suited to monitoring employee conduct or performance. CamoText produces no telemetry, no usage logs, no central console, and no administrator visibility into employee activity. There's nothing for the system to monitor with, which materially shortens the Betriebsrat conversation.

07.Secret Professionnel and CNIL Expectations

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Secret professionnelArt. 226-13 Code pénal; RIN Art. 2 Absolute and unlimited professional secrecy for avocats, breach of which is criminally sanctioned. Masking before transmission means no covered information is revealed to a third party. The obligation being général, absolu et illimité, removing the disclosure entirely is the only fully reliable posture.
CNIL AI guidanceLoi Informatique et Libertés; CNIL recommendations Minimisation of personal data in AI development and use; documented security measures. Local pseudonymisation is a documented, demonstrable measure that produces a reviewable substitution record.
Souveraineté des données Practical concern about client data reaching non-EU providers. Data never reaches us. There's no hosting location to assess because there's no hosting outside of your own hardware.

08.Garante Enforcement and the Codice Deontologico

The Garante has been an active EU authority on generative AI specifically, including its 2023 temporary limitation on ChatGPT and subsequent enforcement action. Italian professionals are correspondingly cautious about what enters a prompt.

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Segreto professionaleArt. 13, Codice deontologico forense; Art. 622 c.p. Strict duty of confidentiality and secrecy over client affairs. Identifying content never leaves the studio's hardware.
Codice PrivacyD.Lgs. 196/2003, as amended; GDPR Security measures appropriate to risk; pseudonymisation expressly contemplated. See the GDPR mapping above; the Italian-language model in CamoText International recognises Italian names, organisations, and codice fiscale patterns.

09.LOPDGDD, AEPD Anonymisation Guidance, and the Estatuto

Duty → mechanism
ObligationWhat It RequiresHow CamoText Discharges It
Secreto profesionalEstatuto General de la Abogacía Española; Art. 199 CP Duty of secrecy over facts learned through the professional relationship. No third party receives identifiable client information.
AEPD anonymisation guidanceLOPDGDD 3/2018 The AEPD has published detailed guidance distinguishing anonymisation from pseudonymisation and stressing residual risk assessment. We describe the output as pseudonymised and surface every substitution for review, rather than asserting anonymity the software cannot guarantee. Spanish DNI, NIE, and NIF patterns are recognised.

10.FISMA, NIST, and Procurement Review

For US federal and state agencies, the relevant question in an ATO or security review is usually the system boundary. CamoText's boundary is a single user-space process on an endpoint you already accredit.

ReferenceRelevancePosition
NIST SP 800-53 Rev. 5Control baseline for federal systems.SC-7, SI-7, SA-8(33), SA-8(6), AU-2, and SC-28 are mapped in the Security & Privacy section of the product page.
NIST SP 800-188De-identifying government datasets.The design follows its emphasis on documented, reviewable transformation and retained governance over re-identification keys.
FedRAMPCloud service authorisation.Not applicable. FedRAMP governs cloud services; CamoText isn't one. There's no service to authorise.
SOC 2 / ISO 27001Third-party attestation of vendor controls.Not held. Those attestations assure you about a vendor's handling of your data. We handle none, and offer direct verification instead.
VERIFY, DON'T TRUST

Disable every network interface, run CamoText, and confirm full functionality. Run a packet capture and confirm zero connections. Inspect the filesystem for artefacts outside your chosen output path. Inspect the process tree for children. Four tests, one afternoon, no reliance on anything we've told you.

Including at install. Start the capture before installation, not after. Licence activation is validated entirely on the machine — there's no first-launch check-in and no periodic re-validation, so the product installs and activates on hardware that has never touched a network. Most software marketed as offline can't pass this test; it's the one worth running first.


11.What This Page Does Not Say

Compliance is a property of your practice, not of a binary. Four things we will not claim:

We do not claimBecause
That CamoText makes you compliantIt's one technical measure. Lawful basis, retention, subject rights, training, and supervision remain yours.
That output is anonymous dataPseudonymised data is still personal data. Residual identifiability in free text is a human judgment.
That detection is completeModels running on laptop hardware can miss terms and flag false positives. Review is mandatory, and the interface is built around that fact.
That we have audited certificationsWe don't hold SOC 2 or ISO 27001. We think observable behaviour is better evidence for this architecture, and we'd rather say so plainly than imply otherwise.

CamoText was built by the founding attorney of Varia Law. This page maps published obligations to product behaviour, not advice on your circumstances.

Send this to whoever has to approve it.

Every claim on this page is testable in an afternoon: disable the network, run CamoText, and watch nothing happen on the wire. The full control mapping, data-flow diagram, and verification steps live in the Security & Privacy section of the product page, or email us and we'll walk your security or compliance team through it directly.