HCPD — Holistic Contextual PII Detection

A document can identify its author without a single name. Its twin cannot.

Legal agreements, board papers and investor materials carry contextual fingerprints — a jurisdiction, a team size, a pilot quarter, a house term. HCPD extends the twin to those signals. Step through one below.

Read for meaningEvery entity is found, and so is every contextual signal: the house term, the regulator, the office, the size of the team, the quarter. None of it leaves your environment.

1 · As written — your environment

This Agreement is between Halden Data Ltd (the Discloser) and Merrow & Finch LLP (the Recipient).

The Discloser’s reversible semantic pseudonymisation applies a stained glass transform to data before any large language model sees it.

The Recipient will evaluate it within its FCA-regulated compliance operations, under English law, through its 12-person compliance team at its Edinburgh office during a Q4 2025 pilot on the Cortex platform.

Signed by Daniel Whitmore and Priya Natarajan, 14 November 2025.

Read for meaning → 5 entities, 8 contextual signals

Two threat models

Different documents. Different threat model.

RSP handles the documents a regulated business processes every day. HCPD is for the ones it shares with people who would recognise it — where the names are only part of what gives the author away.

Operational documents

Complaints, correspondence, internal processing.

What identifies the record is the customer: a name, a date of birth, an account number, an address. RSP swaps each one for a semantic twin, and the model reasons on a complete record.

RSPentity-level twin

High-sensitivity documents

Legal agreements, board papers, investor materials.

What identifies the document is its context: the jurisdiction, the office, the size of the team, the quarter of the pilot, the house name for a method. Together they narrow a counterparty’s guess to one company. HCPD twins those signals too.

RSP + HCPDentity and contextual twin

The documents

Same agreement. No author.

Three kinds of document that never used to go near a model. Open one: what you see is what HCPD sends — every entity and every contextual fingerprint already its twin, and every twin reversible.

NDA

2 entities, 9 contextual signals — all twinned.

nda.txtWhat HCPD sends

MUTUAL NON-DISCLOSURE AGREEMENT

Between Corvale Systems Ltd (the Discloser) and Ashby Rowe LLP (the Recipient).

The Discloser’s context-preserving substitution applies a lattice transform to sensitive data prior to processing by large language models.

Governed by Irish law; the courts of Ireland have exclusive jurisdiction. The Recipient is CBI-regulated.

The 9-person compliance team at the Cork office are the sole users during the Q2 2026 pilot on the Meridian platform.

An agreement names two parties. Its terms name a third: the author. The method has a house name, the pilot has a quarter, the team has a size and a city. A counterparty who knows the market can put those together. The twin keeps the agreement’s shape and takes the fingerprint out of it.

The model only ever saw the twinned document; the answer you read had the originals restored — entities and context alike, from the same audit trail.

When to use each

The right layer for the document.

Redaction removes the names and the meaning with them. RSP keeps the meaning and twins the names. HCPD twins the rest of what gives a document away.

PropertyStandard redactionRSPRSP + HCPD
Entity-level PIIRemovedNames and addresses replaced with placeholdersTwinnedSemantically equivalent replacementsTwinnedSemantically equivalent replacements
Semantic contextLostPlaceholder masking destroys itPreservedFull analytical utility retainedPreservedFull analytical utility retained
Contextual fingerprintsStill readableStill readableTwinnedDomain, jurisdictional, organisational and temporal signals
Use caseLimitedModel output quality degradesOperationalComplaints, customer correspondence, internal processingHigh-sensitivityLegal, board and investor documents
ReversibilityNoneThe original is lostFullVia the entity mappingFullEntity and contextual mappings

Legal and regulatory basis

Where the regulator draws the line.

Identifiability is judged on every means reasonably likely to be used, not on names alone. Here is the basis, framework by framework, in the regulator’s own words where it has them.

What matters, the courts have held, is whether the recipient has any realistic means of identifying anyone. Regulators call that boundary the pseudonymisation domain. With HCPD the model sits outside it for the document as a whole, not only for the names in it.

Coverage

What each layer twins.

The same document, recorded twice: once as RSP sends it, once as RSP with HCPD sends it. Equivalent in every way that matters, different in the one that counts.

SignalEntity-level twin · RSPEntity and context twin · RSP + HCPD
Direct identifiers — a name, a national IDTwinnedTwinned
Quasi-identifiers — a date of birth, a postcodeTwinnedTwinned
Domain terminologyStill readableTwinned
Jurisdictional signalsStill readableTwinned
Temporal markersStill readableTwinned
Organisational fingerprintsStill readableTwinned
Combinatorial re-identificationPossibleMitigated
The motivated intruder testFailsPasses

Both columns reverse exactly. The contextual mappings are written to the same audit trail as the entity mappings, so a reviewer can see every substitution and its reversal in one place.

Operational documents. Legal documents. One layer.

RSP for the documents you process every day. HCPD when the threat model demands it. Both reverse exactly, and both write to the same audit trail.

Put your real data to work.

Your real data never leaves your environment. The model only ever sees the twin, and you still get the accuracy you needed.

© 2026 Nakato. All rights reserved.Equivalent. Not identical.