Skip to content
Faylo
How it works

Four steps between your prompt and a private answer.

Faylo sits between your team and the model as a refraction layer. Identifiable client data is split out and pseudonymised on the way in, and resolved again on the way out — so the provider does the reasoning while you keep the identities.

Capture · Refract · Reason · Restore

The pipeline, step by step. Your team notices nothing — the privacy lives in the layer beneath.

On your deviceContains identifiers

Our contact Van Dijk Diensten B.V. (KvK 61234567) shared a record about M. de Vries (BSN 999995649). Payments and correspondence run through IBAN NL44 RABO 0123 4567 89.

Can you summarise this record and flag the main points to follow up?

AI providerNo identifiable data

The provider never receives a name, number or account it could re-identify.

[[ENTITY]]Pseudonymised identifier
  1. 01

    Step 01 · Capture — your prompt, in the clear

    Your team writes exactly as they always would: full names, BSNs, KvK and BTW numbers, IBANs. Faylo works inside your existing tools and detects Dutch entities — person, organisation, BSN, KvK, BTW and IBAN.

  2. 02

    Step 02 · Refract — identifiers split & pseudonymised

    Each identifier is detected and replaced with a stable, opaque token, for example [[ORG_4f9c2a]] or [[BSN_5c0a]]. The value-to-token mapping is written to a vault that never leaves your tenant. Deterministic: the same value always gets the same token within a session.

  3. 03

    Step 03 · Reason — the model sees only tokens

    The pseudonymised prompt is sent to the model. Because tokens are consistent, the model reasons about relationships and context at full quality — without any value it could re-identify. No name, number or account ever reaches the provider.

  4. 04

    Step 04 · Restore — tokens resolved in your answer

    The model’s response comes back still tokenised. Faylo resolves every token against the local vault, so your team reads a clean, fully restored answer about the real client. Resolution happens locally and users never see a token.

What the provider never sees

Identifying details are replaced with tokens before egress. Non-identifying figures — revenue, salary, balances — pass through unchanged, exactly what the reasoning needs.

Person names

Personal names and roles are detected and tokenised before they leave the environment.

Organisations, KvK & BTW

Company names, KvK and BTW numbers become stable tokens while their mutual relationships are preserved.

BSN & identifiers

Citizen service numbers (BSN) and other direct identifiers never reach the provider.

IBAN & accounts

Account numbers and IBANs are tokenised; the figures around them stay usable for analysis.

What organisations ask before a pilot

Does pseudonymisation hurt the quality of the answer?

No. Because tokens are deterministic, the model still sees that “the same company” and “the same person” recur throughout the prompt, so relationships and context are preserved. Non-identifying figures — revenue, salary, balances — pass through unchanged, which is exactly what the reasoning needs.

What counts as an identifier?

Person names, organisation names, BSN, KvK and BTW numbers, IBANs, addresses and other direct identifiers. The set is configurable per organisation, and detection is tuned for Dutch entities and document formats.

Where are the value-to-token mappings stored?

In a vault inside your own tenant or on-premises environment. Faylo never holds the mapping or the keys, which means no one outside your organisation — including us — can reverse a token back to a real value.

Which models can we use?

Faylo is model-agnostic and works with leading ChatGPT-class models. Because the provider only ever receives tokenised text, you can choose the model that fits your needs without changing the privacy guarantees.

Ready to see the pipeline on your own files?

We set up a short pilot in your environment and walk the architecture and audit logs with your DPO.