PoliciesFor administrators

Configuring data protection

Choose whether personal data is pseudonymised, blocked or sent as typed before it reaches a model, and add rules of your own.

In the Data protection section of the workspace settings you decide what happens to personal data before a message or an attachment reaches a model. The setting applies to every member, and nobody can weaken it for themselves.

Only admins see these settings, in the sidebar under Workspace, Settings. Every switch saves at once. Every change is recorded in the activity log.

Choose the protection mode

Open Settings

Click Settings in the sidebar. At the top is Data protection: one row per setting, the description on the left, the control on the right.

The “Data protection” section in the settings: the “Protection mode” row with the choice Off, Pseudonymise (selected) and Block, and below it the categories, each with a switch.

Choose a mode

In the Protection mode row, choose between Off, Pseudonymise and Block. The row describes exactly what the selected mode does.

Check the categories

Under Categories, every detected category has a row with a switch and one line explaining what is detected. The switch applies to the whole workspace.

Try it with your own text

Unfold Try it, paste a typical text and check what a model would receive.

The three modes compared

A new workspace starts on Pseudonymise.

PseudonymiseBlockOff
Names, addresses, emails, phone numbersreplaced with placeholderssent as typedsent as typed
AHV, IBAN, card number, UIDreplaced with placeholdersmessage refusedsent as typed
Match of a custom rulereplaced with placeholdersmessage refusedno effect
Attaching imagespossible, not checkednot possiblepossible, not checked
Work is interruptedneveron a matchnever

Every detected value is replaced before sending with a placeholder such as <NAME_1> or <IBAN_1>. The same value keeps the same placeholder throughout the chat, and Custodos puts the originals back into the reply. Nothing is refused.

The trade-off: Custodos recognises names as first and last name together ("Anna Weber") or after a salutation such as "Mr" or "Herr". A first name on its own stays, and so do well-known product and model names such as "Claude" or "Max"; a surname without a salutation can be missed. The Name row under Categories describes how your workspace detects names.

Images cannot be pseudonymised. In this mode an attached image reaches the model as it is, with everything that can be read on it.

Block

A message containing a hard identifier (AHV number, IBAN, card number, UID number) or a match of a custom rule is refused before it leaves the workspace. The same applies to files containing such details. Names, addresses, emails and phone numbers are not blocked; that is what Pseudonymise is for. Images cannot be attached at all, because they cannot be checked. Choose this mode when a hard identifier must never reach a model, not even as a placeholder.

Off

No scanning; messages and attachments go out as typed. Custom rules have no effect. Chats in security mode still pseudonymise.

While the workspace is set to Off, even brains that pseudonymise on their own cannot pseudonymise retrieved excerpts in chat. More under Data protection in a brain.

Switch categories on and off

Categories lists every category that is pseudonymised, each with a switch. In Block mode the list shows only the four hard identifiers. The choice applies to chat, attachments and brains, but not in security mode: there every category is pseudonymised.

CategoryDetected, for example
nameMr Peter Müller, Hello Anna
addressBahnhofstrasse 15, 8001 Zürich
birth dateonly after a cue such as "born on"
AHV number, IBAN, card number, UID number756.1234.5678.97, CH93 0076 2011 6238 5295 7, CHE-123.456.789
email address, phone number[email protected], +41 79 123 45 67
reference numberonly after words such as "customer number", "contract number" or "invoice number"

If Custodos keeps replacing a product name, switch name off only if names rarely appear in your chats. Often it is enough for members to release the value in the chat with Send original.

Add custom rules

Custom rules cover what only your company has: client numbers, project names, internal identifiers. A number like "KD-482113" with no cue word such as "customer number" in front of it is only detected with a rule. In Pseudonymise mode a match is replaced, and members cannot send it as the original. In Block mode the message is refused with the rule's name.

Open a new rule

Under Custom rules, click New rule.

Set rule type and pattern

Leave Prefix + digits selected. Enter "Client number" as Rule name, "KD" as Prefix and exactly 6 under Digits. Below, Saved as pattern: shows the resulting pattern.

Test with an example

Under Try it with an example, type a sentence such as "Mandate KD-482113 is closed". If would be detected appears, the rule fits.

A new rule under “Custom rules”: “Rule name” Client number, “Prefix” KD with six digits, and the example KD-482113 is detected.

Save the rule

Click Add rule. The rule applies at once.

Rule typeUsed for
Prefix + digitscustomer, contract or invoice numbers like KD-482113
Exact texta project name or term, for example "Project Eagle"
Expressiona regular expression for everything else, for example \bKD-\d{6}\b
  • Between prefix and digits there may be a hyphen, a space or nothing. The prefix "KD" therefore covers KD-482113, KD 482113 and KD482113.
  • If you paste a whole number as the prefix, Custodos suggests splitting it into prefix and digits. Apply takes the suggestion.
  • Under Digits choose exactly, at least, between or any number of.
  • Upper and lower case make no difference.
  • The switch in the list turns a rule off, the bin icon deletes it. Rules marked built-in can only be switched off.

Rule name: at most 60 characters. Pattern: at most 500 characters. Digits in Prefix + digits: 1 to 20. Expressions that nest one repetition inside another, such as (a+)+, are refused because they can hang on some texts.

Try it

Try it sits folded under the categories in Pseudonymise and Block mode. Unfold it and paste text or click Insert an example. You see what a model would receive, or whether the message would be blocked. The check runs in your browser; nothing is sent or stored. It uses the active categories and the saved rules that are switched on.

The “Try it” panel with a sample text and, beside it, the result in which the name, IBAN, email and phone number appear as placeholders.

What members see

  • While typing, a hint shows how many values were detected. In the panel that lists them, a member can send a value as typed for this chat with Send original, except for matches of custom rules and in security mode.
  • In Block mode an affected message is not sent and the reason is given. When attaching an image, a message explains that images are locked.
  • Their account shows the current protection mode under "How your data is handled here".

Best practices

  • Stay on Pseudonymise. Block stops screenshots, and with them a lot of everyday work.
  • Add a rule for every internal number format and test it with one example that must match and one that must not.
  • Use Exact text for code names of confidential projects.
  • Tell the team clearly that images are not checked.
  • For client and personnel data, also offer security mode.

Frequently asked questions

Next steps

Share the Protecting personal data in chat page with your team.

On this page