anonymization.ai - Your sensitive documents. AI-ready.

Open to any AI, without vendor lock-in.

anonymization.ai prepares your sensitive data—anonymized or pseudonymized, depending on the purpose - and returns it to you as a clean foundation: for your operational AI processes today and your own development tomorrow. Any AI, any use case, no model and no vendor lock-in in between. On-premise deployment possible, without data ever leaving your system. Based on nearly 20 years of NLP engineering.

  • On-premise or SaaS in Germany
  • Web app for manual review processes
  • API for automated AI pipelines
  • Secure and customizable for regulated environments
  • Made in Germany

Easy anonymization within one minute

See how documents can be processed quickly and transparently with Glanos anonymization.ai. The video shows the typical workflow, from handover to usable output.

Schedule a demo

From sensitive document to usable output

1. Submit a document or text

Users upload Word, Powerpoint, Excel, PDF files, scans, emails and other formats containing contracts, case files, expert and business reports, letters, tickets, free-text fields, or internal knowledge documents via the web app, or transfer content automatically through the API.

2. Detect sensitive information

Based on the target process, the system determines how detected information should be handled. anonymization.ai analyzes the content and automatically identifies personal, confidential, or otherwise sensitive information. This includes names, addresses, or contact details and, depending on the use case, also indirect references, roles, organizations, locations, dates, file numbers, or domain-specific contextual information.

3. Optionally review and correct

For particularly sensitive processes, a manual review step can be included. Subject-matter experts or data protection officers can check the results before a document is reused.

4. Generate usable output

Depending on the process, the result may be anonymized, pseudonymized, or redacted versions, structured outputs, or API responses for downstream systems. For AI workflows, analytics processes, internal sharing, quality assurance, archiving, or publication.

AI projects don’t fail because the idea is weak. They fail because sensitive data stays locked behind compliance barriers.

The most valuable information often lies in unstructured documents – contracts, files, expert opinions, emails, case notes. This is where the expertise resides that makes AI relevant. But this very content is sensitive: personal data, professional and business secrets, internal details.

Manual redaction doesn’t work, it’s too slow, too error-prone, and not scalable for recurring processes. What’s missing is a controlled, auditable intermediate step. Without it, valuable data remains unused, shadow processes emerge, and AI pilots remain in experimental mode.

Others sell a tool. Glanos gives you back your data.

Most tools solve this by requiring you to integrate into their environment, their model, their workspace, their use cases. This gets your data moving, but it also ties you to that specific tool. Glanos reverses this approach: Instead of a tool you work with, you get your data back, processed and ready to use, wherever you want. Today in your operational processes, tomorrow in your own development, always with the AI ​​of your choice.

This also relieves the burden on your employees: no manual redaction, no pressured deliberations about whether something can be released, the processing is controlled and transparent. And it’s not a one-off task, but an ongoing capability; data processed from the outset remains freely usable, reinforced by a regulatory framework (EU AI Act, DORA) that increasingly requires verified data use.

Use cases - Where anonymization.ai creates value

Relevant wherever sensitive content needs to be processed, shared, or made usable for AI. anonymization.ai protects operational data and preserves the knowledge base you have built over years, in compliance with GDPR and confidentiality requirements.
GenAI and LLMs with sensitive operational data

Prepare documents and free text for AI assistants and analysis workflows. Personal information is temporarily separated from the business content—pseudonymized. The key remains with you and can be reused at the end of processing to assign the result to the correct person or file.

Knowledge systems and AI training

Merge existing datasets and make them usable for training proprietary AI models or building permanent knowledge and RAG systems — irreversibly anonymized, without a back key and without exposing raw data.

Sharing confidential documents

Share documents in a controlled way with internal teams, external service providers, experts, auditors, or partners

Analytics, quality assurance, and internal evaluation

Make protected content usable for analysis, quality checks, training data review, or process improvement.

Archiving and later use

Avoid GDPR deletion obligations. Reduce risks related to storage, internal availability, and later reuse.

Disclosure and access requests

Prepare documents before external sharing, publication, or file inspection. Handle GDPR data subject access requests securely and within the required deadlines.

Schedule a demo

Security, governance, and operations

Auditable for data protection, IT, and security

Sensitive content needs more than good detection. What matters is an operating model that fits data protection, IT security, and governance requirements.
Glanos anonymization.ai is designed to be embedded into auditable enterprise processes.

Operating options

The operating model depends on the protection requirements of your content: on-premises in your own environment or SaaS in Germany with German hosting providers.
In on-premises operation, the data never reaches Glanos. Anonymization runs as a layer and skill within your existing infrastructure, not as a new cloud service on top of it.

Certified controls

Glanos is certified by Rödl Audit according to ISAE 3402 Type 2. The specific scope and relevant evidence can be provided as part of an audit.

Data protection and contractual documents

Relevant documents can be provided for data protection and organizational review, depending on the deployment scenario. These may include: data processing agreement (DPA), technical and organizational measures, information on hosting and subprocessors, architecture and data flow information, deletion and retention information, and a non-disclosure agreement (NDA) if required.

Traceability throughout the process

In regulated environments, not only the result matters, but also the path that leads to it. Depending on the configuration, processing rules, editing steps, review processes, and outputs can be designed so they remain internally traceable and auditable.

Schedule a demo

What companies should know about anonymization

1. Confidential data and personal data are not the same

Both types of data require special care when using AI, but for different reasons.

Confidential data protects companies: trade secrets, intellectual property, internal strategies, NDAs, or professional secrets. Personal data protects people. It is governed by the GDPR, with requirements regarding purpose, legal basis, transparency, data minimization, and protective measures. Particularly sensitive data, such as health data, is subject to additional requirements. It may only be processed under stricter legal conditions.

2. Personal data may be processed, but not arbitrarily

Personal data may also be processed without anonymization if the purpose, legal basis, and protective measures are appropriate. A contract, consent, or legitimate interest may serve as a legal basis. However, they do not replace purpose limitation. Data collected for support, contract fulfillment, or billing may not automatically be used for every later AI use case. Violations of these principles can have serious consequences, including GDPR fines of up to EUR 20 million or 4 percent of worldwide annual turnover, whichever is higher.

3. Once the purpose has ended, the real data question begins, including deletion obligations

When the original purpose has been fulfilled, personal data may not simply continue to be used in the production system. Depending on the type of data, retention obligations, documentation obligations, or legitimate defense interests may exist. In most cases, however, this does not mean unrestricted further use. It usually means blocking, access restriction, minimization, or deletion.

4. Pseudonymization reduces risk, but does not automatically remove personal reference

Pseudonymization replaces direct identifiers with pseudonyms. However, attribution usually remains possible, for example through a separate mapping table. For this reason, pseudonymized data generally remains personal data. The benefit is not that the GDPR no longer applies, but that risks are reduced and data can be used more safely.

5. Effective anonymization removes personal reference

Effectively anonymized data is no longer subject to the GDPR because no individual can be identified. The decisive factor is not whether names have been removed, but whether re-identification can be ruled out using means that are reasonably likely to be available. This depends on the data context, additional knowledge, data combinations, and technical capabilities.

6. Incorrect anonymization is often only visual redaction

Redaction must technically remove information, not merely hide it visually. Especially in PDFs, text may still remain embedded in the document underneath black boxes. The file may look anonymized, but technically it is not.

7. Structured data requires different methods than text data

In tables, columns and data types are usually known. Direct identifiers can therefore be handled in a relatively targeted way. Combinations are more difficult: age, location, professional role, rare event, or timestamp may become identifying when combined.

8. Unstructured data is the real stress test for AI

In emails, tickets, contracts, legal briefs, or free-text fields, personal references do not appear in fixed positions. Names, places, organizations, phone numbers, IBANs, dates, medical references, rare events, and indirect contextual information must be detected and handled consistently. For AI use cases, there is an additional requirement: the subject-matter meaning should be preserved, while identifying information is reliably removed or replaced.

Let's talk

Industries

Many organizations possess valuable text data, but cannot readily use it for AI, analytics, or knowledge management.

In documents, emails, reports, and case files, personal data, confidential information, and identifying contextual details are often deeply embedded in free text.
The same principle applies in every industry: The processed data belongs to you and remains open to any AI and any use case — not tied to a single tool.

Law firms and legal departments

Contracts, pleadings, client documents, emails, and internal case notes contain particularly confidential information. This makes AI-assisted research, contract analysis, and internal knowledge work more difficult. anonymization.ai prepares legal text data so that confidential content is protected and relevant knowledge structures can be used for internal AI applications.

Insurance companies

Claims files, expert reports, customer communications, and case notes contain valuable information for automation and AI-driven process improvement—but are personal and confidential. anonymization.ai prepares these documents for case analysis, operational support, and the training of proprietary models, even on-premises, without any data leaving the company.

Public sector

Public administrations work with files, applications, decisions, citizen communications, and internal processes. These documents are relevant for automation and AI pilots, but often contain sensitive personal information. anonymization.ai prepares administrative documents for secure AI pilots, internal analysis, publication, or sharing, in a controlled, structured, and traceable way.

Consulting, Professional Services, and Audit Organizations

Project reports, expert opinions, proposals, workshop documentation, and analyses contain valuable experiential knowledge. At the same time, they are often mixed with confidential customer, project, and case details. anonymization.ai helps turn this material into an AI-ready knowledge base. Sensitive information is detected, removed, or abstracted, while methods, case patterns, reusable text modules, and lessons learned remain available for new projects.

Healthcare

Hospitals, care facilities, and psychiatric institutions work with highly sensitive free-text documents: medical letters, care reports, progress notes, discharge summaries, and case notes. anonymization.ai supports the preparation of medical and care-related text data for research, quality assurance, analytics, and AI applications, without exposing sensitive information in an uncontrolled way.

Banks and financial service providers

Consultation records, contract documents, compliance documents, and customer-related communications are subject to stringent requirements regarding data protection, confidentiality, and auditability. anonymization.ai makes this text data available for AI and analysis in a controlled manner, on-premise inside your infrastructure.

Discuss your use case

Why Glanos?

Open, not locked in

Glanos sells no model and no AI workspace. anonymization.ai prepares your data and returns it to you as a clean foundation — free for any AI, any use case, and your own development. What you do with it stays your decision: no lock-in, no bundling into someone else’s tool.

Whether manually via the web app or automated via the API, whether a contract or a medical report, internal AI search or external publication — the rules adapt to document type, protection needs, and target process.

Sovereign, not outsourced

Independence starts with the infrastructure. anonymization.ai runs as SaaS in Germany or on-premise in your own environment — and on-premise, the data never reaches Glanos:

267 / 5.000

Independence begins with infrastructure. anonymization.ai runs as SaaS in Germany or on-premises in your environment — and in on-premises operation, the data never reaches Glanos: a layer and capability within your landscape instead of a cloud service in front of it.
Nearly 20 years of NLP engineering — one problem, solved right

Anonymization looks simple until the edge cases arrive. That depth comes from nearly 20 years of NLP engineering, not from a short-lived AI hype. We do one thing, and we do it right — and we stay with you beyond rollout, because we don’t sell the tool that others lock you into.

Anonymization is rarely just technical: domain expertise, data protection, security, and process reality all have to come together. That’s why we support the whole path:

  1. Frame the use case — which document types, which sensitive data, anonymize / pseudonymize / redact, which target system?
  2. Define protection needs and rules — the business, data protection, IT, and security decide what is handled how.
  3. Pilot with real documents — not a polished demo, but a reliable assessment: does the preparation hold up for the actual process? How much review effort is involved?
  4. Plan integration and operation — operating model, interfaces, roles, access controls, data protection documentation.
  5. Support productive use — pragmatic and goal-oriented, also after installation.

Anonymization is not a magic button. It is a controlled process that combines technology, domain understanding, and clear governance.

I believe trust in this environment is not created by algorithms alone. It is created through transparent communication, realistic assessment, reliable implementation, and contacts who remain available after the installation.

That is why we support projects not only with a product, but with an understanding of the perspectives of business departments, IT, data protection, and security.

Dr. Christian Bauer – Your contact

Talk with me

FAQ

Which document formats do you support?

Office formats (Word, Powerpoint, Excel), PDFs and scans, emails (.msg and .eml), structured formats like XML, plain text and more on request.

Why shouldn't I use open-source tools for anonymization?

Open source gives you code, but not reliable anonymization: When sensitive data is involved, what matters is expert guidance, measurably high precision and recall, and experience with the hidden classes of errors that can otherwise tie up development teams for months and, in the worst case, silently expose data.

How much effort is it for my IT department?

We can host it in our cloud (Germany or Europe), or you run it on-premise via standardized Docker containers.

Can I integrate it in Sharepoint or in my tool XYZ?

Yes, we already have integrations in common systems like Sharepoint. The modular structure of anonymization.ai also allows it to be integrated into almost any other tool.

How much does it cost?

Pricing is calculated based on the number of pages and users. We offer customized pricing packages – from entry-level packages for small businesses (under €100 per month) to attractive volume pricing for one-off archive anonymizations or large corporations. Contact us for more information.

Do you send the data to an LLM for anonymization?

No, we use a completely in-house developed model that we’ve refined over the years. The advantage for you: everything remains internal, ensuring quality and adaptability.

Can all my employees work with the tool?

Yes – no installation need for end-users – they just open it in a browser

Can you support file format XYZ?

Yes, that is generally possible – talk to our experts.

Which languages do you support?

DE, EN, ES, FR, IT, PT, NL, SV – more languages available on request

Is there a data processing agreement (DPA) and an agreement pursuant to Section 203 of the German Criminal Code (StGB)?

Yes, a data processing agreement (DPA) is always concluded. A confidentiality agreement pursuant to Sections 203 and 204 of the German Criminal Code (StGB) is also available upon request.

Anonymization, Pseudonymization, De-Identification - what's the difference?

The terms are often used inconsistently. Therefore, the result is more important than the specific technique.

De-identification is the overarching term. It means that recognizable clues to personal information or confidential data are removed, replaced, or generalized. This can be achieved through redaction, initials, placeholders like “PERSON1,” fictitious names, or more generic descriptions.

Pseudonymization occurs when identification remains fundamentally possible, for example, via a separately stored table, a key, or other additional information. For individuals or organizations that can reasonably trace the data back to the original person, the data remains personal and continues to fall under the GDPR. However, it is better protected than the original data.

Anonymization only occurs when a person can no longer be identified using reasonably applicable means. This depends not only on whether a key has been stored. Contextual knowledge, rare combinations, or other data sources can also enable re-identification.

Read more here: Anonymisierung vs Pseudonymisierung

Isn't pseudonymization not enough? The data still counts as personal.

For you as the responsible party: yes — as long as you hold the key, the data remains pseudonymized and therefore personal data. However, the crucial factor is who accesses which information.

anonymization.ai keeps both aspects separate: Personal data is replaced by pseudonyms, and the key is stored separately and securely. The AI ​​system that processes the content receives only the pseudonymized data — never the key.

According to recent case law, whether data is personal data is assessed relatively — depending on what means are reasonably available to the respective entity for re-identification. The CJEU recently confirmed this relative approach in its judgment EDPS/SRB (C-413/23 P, 4 September 2025): The same data can be personal data for one entity and not for another that cannot re-identify it. An AI system without access to the key and without a re-identifying context lacks precisely these means.

Get in a touch and book a demo

  • Please contact gerhard.rolletschek@glanos.de for general product inquiries and product demonstrations or call +49 89 998 299 151
  • Please contact christian.bauer@glanos.de for inquiries regarding anonymization.ai
  • If you want to apply for a job, please send your CV to info@glanos.de
  • For all further inquiries please write to info@glanos.de - please do not cold call us if you want to sell to us