SECURITY

Practical safeguards for reversible anonymization.

The application combines deterministic detection, carefully filtered language analysis, memory-only PDF uploads, protected premium access and reversible restoration.

Local detection

Pattern matching and offline English and Italian language models run inside the application. No external AI provider receives the source text for detection.

Precision-first language analysis

Language models propose candidates, but context and confidence checks decide whether a natural-language entity is anonymized automatically.

Controlled restoration

Text restoration replaces exact placeholders from the private map; its text fingerprint is advisory. PDF restoration is position-based and intentionally uses no PDF hash or source-file fingerprint.

Memory-only PDF uploads

Multipart file streams use RAM rather than Werkzeug spooled temporary files, with a hard request-size cap. Export permanently removes selected source text before writing placeholders.

Protected paid access

Paid limits and subscriptions are validated by the server. Access-code replacement does not reset quota or create a second entitlement.

Durable migrations

Versioned backups preserve premium entitlements and usage during normal updates without including submitted text or restore maps.

Administrator protection

Repeated failed administrator sign-ins trigger a temporary lockout, and the dashboard exposes aggregate operational data rather than submitted content.

Read how the anonymization flow works, the privacy model, or the FAQ.