Stand-ins instead of client identities, why a stand-in is not a name in disguise, and why the next chat holds nothing either.
Updated July 2026
The model reasons on the firm's material with the identities removed. Before a request leaves the firm's environment, Proxara's policy engine replaces the people, organizations, accounts, and other protected references with consistent stand-ins. The model answers in kind, and the employee sees the real result in a Proxara view inside the chat.
| The model receives | The model never receives |
|---|---|
| Each record's title, its date, and labels such as location, status, and due date | The sender, the organizer, the attendees, or the recipients, all left out of its copy |
| The body text, with every protected reference replaced by a stand-in | The names, organizations, accounts, and amounts behind those stand-ins |
| An opaque reference to the private view | Anything inside that view |
Wording that is not sealed crosses as written, up to about seven thousand characters per record. After the substitution, Proxara re-reads what the model would receive and looks for the real names and addresses it knows about. If one survived, the whole request is stopped and nothing is released.
The reply is checked too: every stand-in the model writes back has to be one this work already owns, so it cannot invent a reference and have a real value filled in.
To decide what must be protected, Proxara passes the text to an Anthropic model on AWS Bedrock, in the region configured for the firm. That model does see the material as written. The call is not logged and not cached, and it is a separate step from the assistant, which only ever receives the version with stand-ins.
A stand-in looks like [Person_0CE2473EA47B] or [Organization_0599F9C6AF50]: one of ten labels, then an opaque suffix. The ten are Person, Organization, Household, Account, Address, Contact, Amount, Project, Identifier, and Credential. The label says what kind of thing it is, nothing else.
A stand-in is derived per piece of work. The same client keeps one stand-in throughout a single brief, so relationships, timelines, and sums stay coherent, then receives a different and unrelated one next time. A test allocates a stand-in for one client in two separate pieces of work and asserts that the two values differ.
The derivation is keyed with a secret that belongs to the firm, and the internal reference it is built from is random rather than a scrambled name. There is no hidden copy of a name in the tag, nothing outside the firm can work backwards from one, and a stand-in pasted into another conversation resolves to nothing.
Whatever the assistant's provider keeps of the conversation is what was sent: a brief about stand-ins. It carries no client name, no sender, no attendee, and its stand-ins belong to that one piece of work. What they mean lives only in the firm's environment.
Proxara's own copy is short lived. The material, the private view, and the mapping between stand-in and real value all expire an hour after the brief is prepared.
Redaction is not anonymity, and no firm should be sold it as such. Enough surrounding detail can still point at a person. That is true of every redaction, which is why the firm decides which AI sees the work at all.
One boundary sits outside all of this: anything typed directly into an AI chat is visible to that AI, and a connector does not change that. Connect or Endpoint sets out what each product covers.