Security

Know where your data goes.

A practical guide to processing, storage and network access in DataAnonymiser. Understand the default desktop boundary and what changes when your organisation runs Enterprise.

Two editions. Explicit data boundaries.

Individual

On your device
  1. Your content
  2. Local processing
  3. Review & copy

The default desktop mode processes content on your computer. The optional browser extension pairs explicitly with the running app over a local loopback connection; the bridge is disabled by default.

Enterprise

On your infrastructure
  1. Endpoints & connectors
  2. Your server
  3. Your console

Content can travel to the server your organisation operates. Enrolled agents and configured desktop clients use mutually authenticated TLS. Enterprise mode requires an explicit administrator configuration; it is never discovered or enabled silently.

Product content is never sent to DataAnonymiser-operated servers. Sharing the reviewed output with another tool is a separate action you control.

What stays after processing?

Local processing does not mean nothing is stored. Here is the distinction between working content, history and saved settings.

Source content

Individual · device
Raw input is not saved in session history. Original values used for restoration remain in memory for the active session.
Enterprise · customer server
Uploaded and connector-fetched content is processed in memory and discarded, without writing the source content to disk.

Results & findings

Individual · device
Session history stores anonymized output and metadata locally. Folder scans retain findings locally.
Enterprise · customer server
Findings metadata is retained for review. Microsoft 365 mailbox finding labels include the message subject; database findings do not retain sampled values.

Custom term presets

Individual · device
Presets you choose to save are stored locally behind your OS account permissions. They are not encrypted at rest.
Enterprise · customer server
Desktop presets remain local; they are not a central server preset store.

The network boundary

Account services are separate from your content.

These connections support the product’s account, licensing and distribution functions. Enterprise content processing uses your organisation’s configured server, separately.

Account & distribution connections

Account and device metadata
Email, device ID, app version and licence information for sign-in, activation and entitlement checks.
App, model and update requests
Downloads and version checks. Model-pack access requires the relevant entitlement; requests contain no document content.
Optional crash diagnostics
Off by default. Error code, app version, platform and timestamp, without content, outputs, risk reports or filenames.

Content excluded from vendor services

  • Your documents, text, or pasted prompts
  • The contents of PDFs, Word or Excel files
  • Images or screenshots
  • Anonymized outputs
  • Placeholder and restore mappings
  • Risk reports and the values that were found
  • File names and file paths

This website is separate from the desktop app and extension. Website analytics load only after consent; the desktop app and extension contain no analytics. Read the privacy policy

Controls, with their practical limits.

Verified downloads

Model packs are checked against signatures and hashes before use. A pack that fails verification is rejected. Download access depends on your licence.

Offline access

Individual processing works offline after setup, within the licence window. A licence check is required at least every seven days. Enterprise processing requires access to your organisation’s server.

Review before sharing

Detection can miss identifiers and identifying context. Read the output and risk warnings. Protect your device account and backups: locally stored history and presets may still be sensitive.

Verify it yourself

Check the behaviour in your environment.

An offline test demonstrates local processing in Individual mode. It is not a complete security audit or proof of every future network behaviour.

  1. 01

    Set up Individual mode

    Activate the desktop app and finish any entitled model download. Confirm it is in Individual mode, then disconnect the network.

  2. 02

    Run a fictional sample

    Anonymize sample text and review the output and risk report. Processing should complete offline within the seven-day licence check window.

  3. 03

    Observe the connected app

    Reconnect and inspect destinations with your firewall or network monitor. For Enterprise, evaluate the configured customer server and client certificates as part of your deployment review.

Security and privacy, answered.

Can DataAnonymiser read the documents I process?

The product does not send documents, outputs or findings to our services. Individual processes them on your device. Enterprise processes them within your organisation’s infrastructure, under its administration.

Does the browser extension send text to a cloud service?

The extension communicates with the running desktop app over a paired local loopback connection. Its bridge is disabled by default. Sharing text from a website remains a separate action governed by that website.

How do we discuss a security review or DPA?

Contact us through the teams page with your planned edition, hosting setup and questionnaire. Do not include sensitive documents or production sample data in the request.