Faheem فهيم

Faheem Shield

Private data is never seen by cloud AI.

A local gateway in front of the public models your teams already want. Names, IDs and account numbers are swapped for tokens before a prompt leaves, put back on the answer, and the send is refused when unsure.

Works with Claude, GPT, Gemini, DeepSeek, Qwen, Llama and more, configured at deployment.

Big models, with the gate in your building.

Shield is for work that wants the best public models but cannot send personal data to an outside company. It is honest about the trade: requests do leave, but only after the gate has taken out what must not.

  • A local gateway sits in front of any external model. Nothing goes around it.
  • Your documents never make the trip: they are indexed and searched on your own servers, and only the masked prompt leaves.
  • Names, national IDs, account numbers, cards and phone numbers are swapped for placeholders before anything goes out, in Arabic and English.
  • Answers come back with the real values restored, exactly, on your side of the line.
  • Every send shows a person the masked version first, and each person and each provider has a weekly spending limit.
  • Every send is written to the black box, with a count of what was masked.

Built like security software, not a plugin.

Fixed rules where they are possible, and a gate that closes when it is not sure.

  • Identifiers, Caught Cold

    Emails, phone numbers (Gulf formats included), IBANs, national IDs, payment cards and amounts are caught by fixed rules, not guesswork.

  • Arabic-Aware

    Checks run on your servers in Arabic and English, in text and in scanned pages. Arabic numerals and hidden characters are handled, so nothing slips past in disguise.

  • Stops When Unsure

    If a check fails, or a second look at the masked text still finds something, the request is not sent. Being unsure means not sending.

  • A Human Can Hold the Gate

    Every send can wait for a person, who sees the masked version and the week's spending so far. Approving never shows them the real data.

  • Placeholders That Come Back

    Each name or number becomes a placeholder like [PERSON_1] or [IBAN_1]. The real values stay in a vault on your side and go back into the answer when it returns.

  • A Record of What Left

    Every send lands in the black box with a count of what was masked, and spending on outside models is tracked. You can always answer: what left, when, and with what taken out.

Everything else in the platform

For teams that want big models without exposure.

The work teams put through Shield from day one, with a regulator who will ask what left.

  • Drafting and review of board papers and letters, with names and accounts masked
  • Help with code, with prompts checked for passwords and keys before they leave
  • Analysis over customer records, with identities masked on the way out and restored on return
  • Public model answers for teams not yet on a full sovereign deployment
  • Any organisation already using ChatGPT or Claude that must stop personal data leaving
  • Teams that need a provable record of every prompt that crossed the line

Honest boundaries, stated plainly.

Masking reduces exposure. It does not make outside AI sovereign, and we will never tell you it does. What Shield guarantees is the gate: personal data is taken out before a request leaves, or the request does not leave.

Your documents stay home
Indexed and searched on your own servers, never uploaded; only masked prompts leave.
Checks on your servers
Fixed rules plus a local AI model. No outside service is involved in the checking.
Placeholders
The real values wait in a vault on your side and go back in exactly. The list never leaves.
A gate that stops when unsure
A second check runs before anything is released. Unsure means not sent.
Rules and approvals
Rules for each kind of data, and a person can be asked before every send.
Confidentiality levels
Every document gets a level on arrival. It can only be raised, and Restricted never crosses.
Sending documents, optional
Text is masked and scanned pages are blacked out before a document can cross. Your choice at installation.
A record of every send
Every send in the black box, with weekly spending limits per person and per provider.
The public model, your choice
The leading public models, chosen at installation.
Tested by attackers
A set of tests keeps trying to smuggle personal data past the gate.

The same Faheem. Two other places to draw the line.

Shield is the practical one: public AI with a masking layer in front. When the work must never leave at all, the other two keep everything home.

Faheem Sovereign

Data never leaves your building.

On servers you own, inside your walls. You hold every key. For ministries, banks and anyone whose data must never leave.

Faheem Private Cloud

Data never leaves the country.

Dedicated servers in your country, managed by Netveva. Same platform, no hardware to run. For organisations without a server room, including smaller companies.

Back to the Faheem overview

Faheem Shield, in plain terms.

What counts as personal data, and how is it detected?

Emails, phone numbers, IBANs, national IDs, payment card numbers and amounts are caught by fixed rules that check the number itself. Names, organisations, roles and the like are found by an AI model running on your own servers. A set of tests keeps trying to smuggle identifiers past the gate. No outside service is involved.

Does it handle Arabic personal data?

Yes. Checks run in Arabic and English, Arabic numerals are handled so digits cannot be disguised, and hidden characters are removed before checking. Restored answers keep the original text exactly.

Is the masking really reversible?

Yes. Each name or number is swapped for a placeholder, and the real values wait in a vault on your side for that session. When the answer comes back, the placeholders are swapped back for the real values, exactly. The list never leaves your servers.

What happens if detection is uncertain?

The request is not sent. If any check fails, a required check does not run, or a second look at the masked text still finds something, the send stops and can go to a person, who sees only the masked version. Being unsure never means sending.

Do our documents get uploaded to the external models?

Not by default, and never without your say-so. Your documents live on your own servers: indexing, search and citations all happen there, and the outside model only ever sees the masked text of a prompt. If you choose to let the outside model read a document, that is an option with its own gate: the text is masked like any prompt, scanned pages are blacked out before they cross, and a document marked Restricted is refused for the cloud and sent to the local model instead.

What is recorded?

Every send is written to the same tamper-evident black box used across Faheem, with a count of what was masked in each category, and spending on outside models is tracked against weekly limits set per person and per provider. You get a provable record of exactly what left and what was taken out first.

Does Shield make external AI sovereign?

No, and we will not claim it does. Requests do leave your building; that is the point. Shield reduces exposure by making sure personal data is taken out before anything goes, and by recording everything that went. For work that must never leave at all, use Faheem Sovereign or Private Cloud.

Public models, with the gate in your building.

Book a demo and watch the gateway strip a document of every identifier, send it, and restore the answer, with the black box recording each step.

Or send us a message