数据隐私见解
关于人工智能安全、GDPR 合规、医疗数据保护和 PII 匿名化最佳实践的专家文章。
所有文章
法律文件脱敏:格式保留问题的解决方案
Bloomberg Law 2024年调查显示,73%的法律专业人士在使用第三方脱敏工具时遭遇格式损坏。司法部爱泼斯坦档案的脱敏事件揭示了文本层的安全漏洞。
Excel与GDPR:电子表格数据合规风险
GDPR数据访问请求(DSAR)从2021年到2024年增长了180%(欧洲数据保护委员会)。手动处理一份DSAR平均耗时12小时。人力资源部门每月处理大量个人数据……
企业AI:让开发者安全使用AI工具
银行禁用了ChatGPT,但员工在家照用不误。Zscaler调查显示,企业AI聊天机器人中27.4%的内容涉及敏感数据,同比激增156%。
使用 Cursor 与 Claude 进行开发而不泄露代码
Cursor 默认将 .env 文件加载到 AI 上下文中。一家金融服务公司因专有交易算法被发送至 AI 助手而损失了 1,200 万美元。
没有技术管控的 AI 政策,注定失效
77% 的员工即使在政策明令禁止的情况下,仍会向 AI 工具分享敏感工作数据。一名政府承包商将 FEMA 洪灾救助申请者的数据粘贴进了 ChatGPT。
PII 检测工具的「误报税」
Presidio GitHub Issue #1071 记录了系统性误报问题。2024 年一项研究在混合语言企业数据集上测得精确率仅为 22.7%。
大型语言模型遗漏了 50% 的临床 PHI
2025 年一项研究发现,在多语言文档中,LLM 工具遗漏了超过 50% 的临床受保护健康信息(PHI)。34.8% 的 ChatGPT 输入内容包含敏感数据。
阿拉伯语与希伯来语 PII 检测:西方工具力不从心
GDPR 的管辖范围不止于博斯普鲁斯海峡。企业业务流程中的阿拉伯语和希伯来语 PII 长期处于系统性保护空白之中。XLM-RoBERTa 跨语言检测可以有效应对这一挑战。
IDE 与浏览器:开发者 AI 安全的双层防护
开发者在两种环境中使用 AI:IDE(Cursor、VS Code)和浏览器(Claude.ai、ChatGPT)。每种环境都需要不同的安全控制措施。
83% 的 AI 扩展程序从未经过安全审计
USENIX 2025 研究显示,83% 拥有广泛权限的 Chrome 扩展程序从未经过安全审计;45% 的企业员工在使用未经 IT 审批的扩展程序。
GitHub 3900万次泄露:AI编程工具的安全风险
67%的开发者曾意外在代码中暴露密钥(GitGuardian 2025)。2024年GitHub泄露的密钥达3900万个,同比增长25%。
大规模KYC合规:误报的实际成本
一家数字银行每天处理来自15个欧盟国家的5,000份KYC申请,发现其PII检测步骤造成了2天的处理积压。
可解释的文件遮蔽:HIPAA审计合规指南
HIPAA专家认定方法要求记录在案的方法论。法律电子取证要求每项遮蔽的依据。34%的数据保护官报告现有工具不足以满足自动匿名化合规文档的要求。
混合语言文档的PII检测:单语言工具为何失效
72%的欧盟企业同时处理三种以上语言的文档。混合语言文档导致单语言NER工具的PII遗漏率高出45%。
一款工具,45个国家,267+种实体类型
巴西CPF含校验位,印度PAN为10位字母数字混合格式,欧盟IBAN因国家而异。全球电商平台无法为每个司法管辖区分别部署工具。
亚太地区PII检测:泰语、印尼语、越南语
新加坡一家金融科技公司每月处理来自12种亚太语言的50万次支持聊天,发现其纯英语工具在60%的非英语聊天中遗漏了PII。
误报泛滥:为何ML文件遮蔽在法律和医疗领域失效
2024年基准测试发现,Presidio在4,434个样本中产生了13,536个人名误报——将代词、船舶名称和国家名称错误标记为人名。以下是这在法律和医疗环境中的实际代价。
在法庭上捍卫文件遮蔽:AI置信度分数的法律价值
一位法官询问为何文件中47%的内容被遮蔽。「AI标记了这些内容」在法律上无法自圆其说。以下是可供辩护的自动化遮蔽机制应具备的要素。
仅支持英语的PII工具:GDPR法律风险
GDPR执法对所有欧盟语言的违规行为一视同仁。当您以英语为中心的PII工具遗漏德语、法语或波兰语标识符时,企业面临的法律责任不可忽视。
仅支持英语的PII工具:GDPR合规盲区
德国税号(Steuer-ID,11位含校验位)与美国社会安全号码在结构上截然不同。法国NIR号码有15位。波兰PESEL和瑞典Personnummer各有其格式。
ISO 27001加零知识缩短供应商评估时间
2025年一项调查发现,"缺乏认可的安全认证"是CISO淘汰SaaS供应商的第二大原因。ISO 27001加零知识组合能实现什么?
零知识架构缩短销售周期
企业供应商安全问卷平均包含100个以上问题。零知识架构能够明确回答最难的问题,并推动成交。
LastPass泄露:供应商安全教训
LastPass对用户数据进行了加密,保险库仍然被窃取。60万条以上Okta记录随之而来。SaaS安全事件从2022年到2024年增加了300%。
LastPass之后:评估零知识声明
LastPass用户的4.38亿美元在其"加密"保险库遭到攻击后被盗。ICO随后开出120万英镑罚款。这里是评估供应商零知识声明是否成立的核查清单。
About this page
We update this page when our platform or the law changes.
Read our founder note for how we work.
Each change shows up in the timestamp at the top.
Related reading
We follow these rules
- GDPR (EU 2016/679).
- ISO/IEC 27001:2022, held by our hosting provider.
- NIS2 (EU 2022/2555).
- HIPAA safe harbor under 45 CFR § 164.514(b)(2).
Our promise
We do not sell your data.
We do not train models on your text.
We store your files in Germany.
You can delete your account at any time.
You own your work.
Where we run
Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.
Hetzner holds ISO 27001 certification.
All data stays in the EU.
Backups run every day.
Need help?
Email support@anonym.legal.
We reply within one business day.
How we test
Automated checks run on every release.
Each surface gets its own sweep script and report.
Human reviewers spot-check the output each week.
We test detection against sample documents before each release.
A failing unit or integration run stops the release.
What we never do
- We never sell your information to third parties.
- We never train models on what you upload.
- We never keep your work after you delete it.
- We never share keys with any outside firm.
- We never run ads inside the product.
Plans in plain words
We sell credits, not seats.
One credit covers one short job.
Long jobs use a few credits each.
Paid plans can buy top-up credits.
Credits reset at the end of each cycle.
Read the plans page for current rates.
Who built this
A small team of engineers and lawyers built this.
We ship from Europe and work in the open.
Our founder note spells out why we started.
Where to start
- Open the web app and try a sample file.
- Learn how credits get counted.
- See current plans and limits.
- Meet the team behind the product.
How the parts fit
A browser add-on cleans text inside Chrome.
A Word plug-in handles drafts in Office.
A small desktop tool works on whole folders.
An agent protocol link feeds large models safely.
All four share one core engine and one rule set.
Words from our team
We started this work after a lunch about cookies.
One friend kept getting odd ads on her phone.
We asked why a court file leaked through a draft.
We sketched the first build on a napkin that week.
By month three we had a tiny demo for a friend.
She used it on her first case the next day.
Common questions we hear
Can the tool read scanned PDFs? Yes, with OCR.
Does it work on long files? Yes, in small chunks.
Can I roll my own rule set? Yes, save it as a preset.
Does it run offline? The desktop build runs offline.
Do you keep my files? No, the cloud build wipes after each run.
Will it learn from my work? No, we never train on inputs.
A short tour of the workflow
Upload a file or paste a snippet of prose.
Pick the entities you want gone from the draft.
Choose a method: replace, mask, hash, encrypt, or redact.
Press run and watch the side panel show each hit.
Skim the result and tweak any rule that misfired.
Save the cleaned file or send it to a teammate.