Donald Murre

← Research

Using cloud LLMs on confidential documents

Question
How can a lawyer use a cloud language model on a client file without the identifiers reaching the provider, and how do you prove it?
Status
Built and in use as a prototype. A paper on the evaluation method is in preparation, so details here are deliberately general.
Languages
Dutch, French, German, Italian, English

A browser-based pseudonymisation gateway for confidential legal and fiduciary documents. Detection and replacement run on the device before anything reaches a model provider, and the answer is restored locally. The design principle is exposure accounting: every optional layer can only add protection, every server payload is either what the provider receives anyway or ciphertext, and each rule or model decision that leaves an identifier unchanged is listed with a measured leak rate.

  1. Document in the browser
  2. Local detection and pseudonymisation
  3. Optional encrypted check and server model on the protected text
  4. Protected text to the model provider
  5. Answer restored locally

What I built

How it is evaluated

What I found

Other research areas