Your AI never meets your customer.It meets their twin.

Nakato is a private layer between your sensitive data and public AI models. Your real data never leaves your environment. The model works on a semantic twin, and you still get the accuracy you needed.

Synthetic example. No real customer data appears on this page.

See the swap in four sectors

How it works

  1. 01 Semantic

    Detection that reads meaning

    Nakato reads the whole document and finds every sensitive detail — direct or indirect, including the indirectly identifying information that pattern matching misses.

  2. 02 Pseudonymisation

    A twin, not a hole

    Every sensitive value is swapped for a semantic twin: fictional, but statistically faithful — same shape, same context, different person. The model only ever sees the twin.

  3. 03 Reversible

    A perfect reversal

    When the answer comes back, the swap is exactly reversed and every substitution is auditable. Your real data never leaves your environment.

The ledger for this record
TypeOriginalState
personMargaret Ellisfound
date of birth1961-04-12found
account number20-45-11 88451203found
address14 Rowan Grove, Sheffieldfound

4 values found, read for meaning rather than matched.

It happens live, at the moment of each query — not as an up-front dataset transformation. The model gets the context it needs to reason, and it has no reasonable means of identifying your customers.

The demo

Real decisions. Fictional identities.

One layer, wherever regulated data is the blocker. Pick a sector: the record on the left stays in your environment, and the model reasons on the column beside it.

Banking

Credit decisions on the full picture

Record · BankingTwinned at query time
FieldOriginal stays with youTwin what the model seesPreserved
CustomerMargaret EllisEleanor Grantgender, name origin
Date of birth1961-04-121959-11-03age band
Sort code20-45-1131-08-64valid format
Balance£18,240.55£17,905.12within 2%

Credit decisions on the full picture. Strip demographics and you strip the vulnerability signals credit analysis depends on most. The twin keeps every signal and removes every identity, so the model reasons on complete records.

The model only ever saw the right-hand column; the answer you read had the originals restored. Where the two columns match, that is the point — the twin changes what identifies and keeps what the reasoning needs.

Evidence

Nothing here needs to be believed. It can be checked.

The field is the benchmark. Each point stands for the same number of test cases. Each mark reaches as far as that tool's figure.

  • Placeholder masking
  • Nakato
  • The rest

Summarisation accuracy on the same cases. A longer bar is better.

  • Nakato
  • Placeholder masking41.3%
  • Tokenisation12.8%

Shown alone. A comparison is drawn only where the same benchmark produced one.

Shown alone. A comparison is drawn only where the same benchmark produced one.

Leak rate under the same attack. A shorter bar is better.

  • Nakato
  • GLiNER7.8%
  • Microsoft Presidio22%

Checked across 500,000 financial-services test cases; every benchmark is published for review.

What the security review will ask.

Sign-off waits on a familiar set of questions. The short answers are here; the particulars — and the frameworks the layer is built against — are on their own page.

Where does our data go?

Your real data never leaves your environment.

The model never receives a real value, and the transformation never leaves your infrastructure — so nothing about your existing data classification has to change.

Runs in
Your VPC or on-premise
Model
A self-hosted small language model

What happens when detection is unsure?

Fail-closed by design.

An entity the detector is not certain about is held back rather than passed through. The layer is designed so the model has no reasonable means of identifying your customers.

Confidence gate
95%
Entity types
50+, direct and indirect

Can we evidence what was substituted?

Every substitution is auditable.

Every swap is written down — what was replaced, with what, and when — so a reviewer can retrace a decision without ever seeing the underlying data.

Trail records
Each transformation and its reversal
Ready for
Supervisory review

Built against the EU AI Act, DORA, FCA and PRA expectations, GDPR and SOC 2 from the start.

Read the full breakdown

Join us

A problem most companies cannot even attempt.

Generating a twin that keeps its meaning is not a solved problem. It takes an unusual mix of semantic ontology and computer science, and no two domains ask the same thing of it.

The problem changes shape with every domain. What preservation means for medical data looks nothing like insurance.

We intend to be the ones who define how this is done.

Put your real data to work.

Your real data never leaves your environment. The model only ever sees the twin, and you still get the accuracy you needed.

© 2026 Nakato. All rights reserved.Equivalent. Not identical.