The control layer between your information and AI

Use the right AI for the task. Keep your original documents in VaultLM.

VaultLM is the control layer between confidential information and approved AI models. Your original files stay in VaultLM. Before a model is called, permissions are checked, identifying data is masked or pseudonymised where required, and only the permitted context needed for the task is sent. You can change approved model routes without moving your source files or rebuilding access controls.

Built for legal, HR, finance, advisory and leadership teams working with confidential information.

Original files stay in VaultLMIdentifying data is protected before external model useAI receives only permitted contextApproved model routes can change without moving sourcesResults keep sources and audit evidence
Product

Your information layer stays. Model routes can change.

Treat AI models as processing routes, not as the home of your organisational knowledge. VaultLM keeps source files, permissions, identity mappings, retention rules and audit evidence inside the vault, then prepares only the protected context required for the selected workflow and approved model route.

Your information layer

Original documents, vaults, roles, permissions and retention stay under your control.

VaultLM control layer

Checks access, protects identities, minimises context and selects an approved model route.

The AI route

The selected model receives only the prepared, permitted context for the task. The result returns to VaultLM with sources and route evidence.

What stays where
Inside VaultLMOriginal files, identity mappings, permissions, retention rules and audit evidence.
Outside the vault boundaryOnly protected excerpts or derived context required by the selected workflow and approved model route.
Three governed modes

Use source-grounded answers, document workflows or approved model knowledge deliberately.

The workspace keeps the chosen mode visible so a user does not accidentally turn a document task into an unrestricted general-AI request.

Source-grounded Q&A

Ask questions answered from permitted vault sources and linked back to the exact passages used.

Governed document jobs

Run summaries, comparisons or extraction across complete documents through the controlled pipeline; a raw dossier is not simply pasted into a chat.

Approved model knowledge

Allow broader model knowledge only when the workspace policy and the user intentionally select that route.

Why VaultLM

Keep your information layer independent from the AI provider.

Models will change. Your documents, permissions, identity mappings, policies and evidence should not have to move with them.

Use the right model for the task

Route work to approved AI models without moving the original source files or rebuilding the information layer.

Reduce what leaves the vault

Protect identifying data and send only the permitted context the chosen task requires.

Keep control after the answer

Retain sources, route details and audit evidence so teams can review how the result was produced.

How it works

Control what reaches the model, every time.

VaultLM sits before the model. Every request checks source permissions, applies the protection policy, selects only the permitted context needed for the task and records the route and evidence for review.

01

Place documents in a vault

A user or invited contributor adds documents to a vault with defined access, ownership and retention.

02

Apply the protection policy

VaultLM masks or pseudonymises identifying data before preparing any context for an external model route.

03

Prepare the permitted context

Only sources the user may access and the context needed for the chosen task are included. The original source library stays in VaultLM.

04

Use an approved model route

The selected model receives the prepared context. The answer returns with source passages, route information and an audit event for human review.

AI access cannot expand source permissions, and changing model routes does not require moving the source library.
Who it is for

Built for teams whose most useful information is also their most sensitive.

The strongest fit is a European knowledge-intensive organisation that wants to use one or more AI models with confidential information without making any single model platform the home of its documents and controls.

Professional services

Consultancies, legal and accounting firms, recruiters and corporate-finance teams working with confidential client files.

Confidential business functions

HR, legal, finance, compliance and board teams working with employee, contract and management information.

PE-backed and regulated SMEs

Organisations that need stronger governance than consumer AI, with faster deployment than a bespoke enterprise programme.

Employees already use different AI tools. VaultLM gives confidential work one controlled information layer and approved routes to AI, instead of private accounts, copied files and manual redaction.
Security

Make the data route explainable before asking people to trust it.

VaultLM links every request to permissions, a protection policy, an approved route and reviewable evidence.

Access follows source permissions

A user cannot retrieve more through AI than they may open in the underlying vault and source set.

Required masking fails closed

If a required protection step is unavailable, the external model request stops instead of bypassing it.

Context is minimised per workflow

The selected route receives protected context needed for the task, not an unrestricted raw dossier by default.

Managed routes keep EU data residency

Managed routes are configured for EU data residency. Customer-controlled keys follow the configuration and terms of that provider route.

Evidence is attached to the answer

Source passages, route details and relevant audit events make later review possible.

Pseudonymisation still needs judgement

Reversible masking remains pseudonymisation; sensitive or high-impact conclusions still require human review.

Review the architecture, not just the marketing claim.

The public security page explains the architecture, data flow and operational controls. The downloadable one-page overview is suitable for an initial internal or procurement review.

Public security details · downloadable one-page data flow
VaultLM vs an AI platform

The AI platform supplies intelligence. VaultLM controls what reaches it.

Enterprise AI platforms can have strong security. VaultLM solves a different problem: it keeps your information layer separate from the model provider and controls the data passed into each approved route.

ControlAI platform aloneWith VaultLM
DocumentsDocuments or retrieved context are processed inside the AI platform's environmentOriginal sources stay in VaultLM; the selected route receives prepared context
Identifying dataThe platform can process the identifying data supplied to the taskMasking or pseudonymisation is applied before protected external processing where required
Model contextThe platform receives the document or context made available to itThe route receives only selected, permitted and protected context needed for the task
Model choiceKnowledge, permissions and workflows can become tied to one platformKeep the information layer in VaultLM and choose approved model routes per workflow
EvidenceDepends on the platform, configuration and user behaviourSource passages, route details and relevant audit events stay with the result
OrganisationControls are split across AI platforms, accounts or copied chatsVaults, roles and policies create one reusable organisational workflow
Pricing

Start with one professional. Keep the same control layer as the organisation grows.

Each plan includes the secure information layer and managed AI capacity. Team and Organisation add shared vaults, permissions, policies and central controls.

Professional

For one adviser or specialist working with confidential documents.

16
per user / monthBilled annually
  • 1 user
  • Private vaults and persistent chats
  • Data masking, citations and audit trail
  • 10 GB storage
  • Managed AI usage included
Request access

Organisation

For multiple teams with central governance.

33
per user / monthBilled annually
  • 11–100 users
  • Organisation-wide policies and model routes
  • Advanced audit, retention and usage controls
  • Priority onboarding and support
  • Higher workspace limits
Request access

Enterprise

For custom security, deployment, contracts or volume.

Contact us
 
  • Custom users and capacity
  • Security and architecture review
  • Custom DPA, SLA and procurement support
  • Dedicated or customer-controlled routes
  • Contracted usage and support
Contact us

A seat covers the secure workspace. AI capacity covers model use.

You do not need to count tokens yourself. VaultLM translates model usage into a workspace budget, warns administrators at 80% and does not create uncontrolled overage by default.

Prices exclude VAT. Annual plans are billed yearly. Managed AI usage is subject to fair-use and workspace limits; administrators receive a warning before additional capacity is used.

During the final test phase, access requests are reviewed and new workspaces are opened selectively.

AI Act

AI governance is becoming part of everyday operations.

The AI Act is risk-based. Which duties apply depends on your organisation’s role, intended use and the system’s risk category. VaultLM helps put practical controls around confidential document use without claiming automatic compliance.

VaultLM supports operational controls. It is not a compliance certificate.

VaultLM supports access control, data minimisation, logging, source traceability and human review. Legal classification, risk assessment and the duties that follow still require an organisation-specific assessment.

Q&A

Questions security, legal and business teams ask before a pilot.

Clear answers about the data boundary, model independence, whole-document workflows and AI Act positioning.

What does VaultLM do?

VaultLM is the control layer between confidential information and AI models. It keeps the source library, permissions, identity mappings and audit evidence under your control, prepares the permitted protected context for an approved model route and returns the result with sources and route evidence.

Why use VaultLM instead of an AI platform directly?

An enterprise AI platform can be well secured. VaultLM is useful when you want your information layer to remain separate from the model provider. Original files, permissions, identity mappings and audit evidence stay in VaultLM, while an approved AI route receives only the permitted protected context needed for the task. This also lets you change approved model routes without moving the source library into each AI platform.

Who is VaultLM designed for?

VaultLM is designed for European professional-services firms and confidential HR, legal, finance, compliance and leadership workflows. The strongest fit is a team that already sees demand for AI but cannot responsibly use ordinary chat accounts with its documents.

What does a whole-document workflow mean?

It means VaultLM can run a governed task across a complete document or document set, such as summarisation, comparison or extraction. It does not mean a raw dossier is simply pasted into an unrestricted chat prompt.

Does the full document go to an external AI provider?

The route receives the protected context required by the selected workflow and policy. In source-grounded Q&A this is normally selected, permitted passages; governed document jobs process the complete task through the controlled pipeline rather than treating the raw document as a free-form chat upload.

Is the data anonymised?

VaultLM uses data masking and pseudonymisation when it keeps a reversible identity mapping. Legal anonymisation depends on the context and cannot be assumed automatically.

Can the model use knowledge beyond my documents?

Yes, where the workspace policy and the user deliberately select an approved model-knowledge route. Source-grounded mode remains available when answers should be limited to vault sources.

Where is data processed?

Managed VaultLM routes use EU data residency. Customer-controlled provider keys or dedicated routes follow the configuration and contractual terms of that selected route.

Is VaultLM “AI Act compliant”?

There is no useful blanket compliance label for every workflow. VaultLM supports operational controls such as access control, data minimisation, logging, source traceability and human review; the legal classification and duties depend on the organisation, use case and system.

What happens if masking is unavailable?

A required protection step fails closed. The external model request stops instead of forwarding unprotected context.

How can I access VaultLM?

Request access through the VaultLM app. During the final test phase, requests are reviewed before a workspace is created.

Request access

Start with one confidential workflow.

Tell us which documents, users and review steps are involved. We review the data route, protection policy and model route, then open the smallest suitable workspace for a controlled pilot.

  • Verify a work email and organisation
  • Describe one document workflow and its users
  • Review the data route, model route and security needs
Request accessSign in to VaultLMAccess requests are reviewed and workspaces are opened selectively during the final test phase.
Request access