The process
Steps 1 and 2 happen entirely in your browser before any network request is made.
You
Your original text
Anonymization
PII replaced in browser
Encryption
AES-256-GCM + RSA wrap
AI Provider
Sees only placeholders
You
Your original text
Anonymization
PII replaced in browser
Encryption
AES-256-GCM + RSA wrap
AI Provider
Sees only placeholders
01
You type a question or paste a document. Nothing has left your device yet.
02
Names, emails, phones, IBANs and more are replaced with tokens like [NAME_1]. You review before sending.
03
The anonymized text is encrypted with a one-time AES-256-GCM key, wrapped with our RSA public key.
04
Claude, GPT-4 or Gemini receives anonymized, encrypted content. Your identity never reaches them.
Transparency
We believe honesty is a feature. Here's exactly what ARCANAI does and doesn't guarantee today.
⚠ Important: Our server does decrypt your anonymized text briefly to call the AI provider. We immediately discard the plaintext. This is not true zero-knowledge — we technically have access during that window. True TEE-based zero-knowledge is on our roadmap.
Roadmap
Where we're headed — and when.
Now — Q2 2026
Q3 2026
Q4 2026
Q1 2027
Q2 2027