Control what is shared.
Find sensitive values and apply the right treatment: tokenise, redact, keep local or block the request.
Kordane BoundSenseInformation control for AI
Set the terms before information reaches a model. Protect sensitive values, decide where a request can run and keep a record of the decision.
Demonstrated in the browser · available in pilots
Interactive demonstration
Choose a policy, run a request and inspect the result. See what is protected, where the request may go and which decisions are recorded.
User or applicationSensitive contextAI model or toolResponse or action
Sensitive values are tokenised or redacted, codewords may not leave at all, and the request is routed only to an approved external model.
Synthetic demonstration. Runs deterministically in your browser on fictional data. Nothing is transmitted.
Ready. Choose a profile and run the crossing.
Route: the approved external model.
Restore is a local substitution inside your browser. Reset clears the request, result, and audit trail.
Find sensitive values and apply the right treatment: tokenise, redact, keep local or block the request.
Define which models, tools and environments are allowed. Require human approval when the action needs it.
Review the information found, the policy applied and the destination selected in one trace.
BoundSense Audit
The decision record a single synthetic crossing leaves behind.
Operational briefing (synthetic fixture)
Every crossing produces a reviewable record: what was found, what policy did, where the request went.
Illustrative decision record · Synthetic data
Sensitive values are found in the request before anything moves: identifiers, codewords, references, contact channels.
Each value is assigned a class your policy can reason about: identity, document, contact, codeword, reference.
The active profile decides per class: pass, tokenise, redact, block, or contain. Decisions are explicit and versioned.
Values that may cross in shape but not in substance are tokenised; values that must never cross are redacted at source.
The request goes only to an approved destination: external model, private deployment, or a local model with no egress.
The downstream answer returns through the boundary, carrying tokens instead of your originals.
The answer is checked before anything is restored: an unknown token, a malformed one, or a sensitive value the model produced on its own stops the crossing.
Where policy permits, tokenised values are restored locally, inside your environment, after the crossing.
Each decision lands in a detailed audit trail: what was found, what policy did, where the request went, what came back.
Planned
The same control plane, placed in each customer-controlled environment rather than only in front of one.
Which evaluation package or query is allowed to reach this environment at all.
Which candidate model may run locally, from the set already permitted for the task.
Which local dataset or source is eligible for this specific run.
Which metrics, excerpts, structured facts or local answers policy authorises out of the node.
The crossing record each node keeps locally, and the identity it contributes to the combined record.
A node is a placement of BoundSense, not a separate product. Nothing here adds a product family or a navigation entry.
A first conversation
Tell us the task and where the information must stay. We'll show a relevant example and discuss whether a scoped pilot makes sense.
Request a demopilot@kordane.ai