Your data stays 100% anonymous.
100% GDPR-compliant.
Anonix Privacy Proxy
Use AI. Protect data. No compromises.
Contents
- The Invisible Risk2
- The CLOUD Act3
- What Really Happens When Your Software Uses AI APIs4
- The Solution: Anonix Privacy Proxy5
- How the Protection Works6
- Government, Public Administration & Public Sector7
- Hospitals and Clinics8
- Care Facilities9
- Courts and Justice10
- Social Services and Youth Welfare Offices11
- Law Firms12
- Tax Advisors and Auditors13
- Banks and Insurance Companies14
- HR Departments15
- Educational Institutions16
- Pharma and Life Sciences17
- Software Companies and IT Service Providers18
- Why Existing Solutions Fall Short19
- The Architecture at a Glance20
- Investment and Cost-Effectiveness21
- Compliance at the Push of a Button22
- Voices from the Field23
- Your Path to Anonix24
- Legal Notice25
The Invisible Risk
Imagine this: your line-of-business application sends citizen data to an AI service via API to make official notices easier to understand. Your law firm software has draft contracts containing client names reviewed. Your hospital system asks the AI about treatment options and transmits the patient record in the process. Or an employee copies sensitive data straight into ChatGPT®.
It happens. Every day. In thousands of German companies and public authorities. And in most cases, management has no idea.
Sources: Bitkom Research 2025, Cornerstone OnDemand 2025
Why Bans Don’t Work
Companies that simply ban AI lose twice. First, employees use the tools anyway—just without oversight and without any safeguards. Second, these companies give up the productivity edge that AI tools provide. Market research firm Gartner predicts that by 2030, 40 percent of all organizations worldwide will experience security incidents caused by uncontrolled AI use.
The CLOUD Act—the Problem No One Sees
OpenAI® is based in San Francisco. So is Anthropic®. Google®, of course. What many decision-makers don’t know: the US CLOUD Act of 2018 gives American authorities the right to demand that US companies hand over stored data. No matter which server the data is on. No matter which country.
When your software or your employees send personal data to OpenAI®, an OpenAI®-compatible provider such as DeepSeek® or Mistral®, to Claude® or Gemini®—whether through an API integration or direct use—US authorities can, in theory, access that data. This is in direct conflict with the GDPR.
US CLOUD Act
- US authorities may demand data from US companies worldwide
- Applies regardless of where the data is physically stored
- No judicial review by EU standards required
- Affects OpenAI®, Google®, Microsoft®, Anthropic®, DeepSeek®, Mistral®, xAI®, Groq®, Perplexity®, and all other US and cloud providers
EU GDPR
- Personal data requires a legal basis for transfers to third countries
- The Schrems II ruling invalidated the Privacy Shield
- The EU-US Data Privacy Framework applies only to certified companies
- Art. 48 GDPR prohibits disclosure without a mutual legal assistance treaty
The Supposed Solution: An EU Data Center
Many companies believe they have solved the problem by not booking AI models directly from the provider, but running them through AWS® Bedrock or Microsoft® Azure® in a European data center. The data never physically leaves the EU—problem solved?
No. The CLOUD Act is tied not to the location of the server but to where the company is headquartered. AWS® is a subsidiary of Amazon® (USA). Microsoft® Azure® is a product of Microsoft® Corporation (USA). Both are subject to the CLOUD Act—regardless of whether the data is processed in Frankfurt, Dublin, or Stockholm.
With Anonix, the server location no longer matters: the AI provider—whether accessed directly or through an EU data center—sees only anonymized data with placeholders. Even in the event of a CLOUD Act request, there is nothing usable to hand over.
The Consequences Are Real
Sources: DLA Piper GDPR Fines Survey 2025, Bitkom Research 2025
What Really Happens When Your Software Uses AI APIs
Let’s look at a typical process. Your line-of-business application calls an AI API to make an official notice easier to understand:
Please rewrite the following notice so it is easier to understand:
Dear Ms. Ingrid Bergmann,
Your application for housing benefit (Ref. WG-2026-04817) has been approved.
Payment account: DE89 3704 0044 0532 0130 00
Address: Goethestr. 14, 60313 Frankfurt am Main
Without Anonix, four categories of personal data leave your infrastructure: name, case reference, IBAN, and full address. They end up on servers in the US.
BEFORE: Without Protection
AFTER: With Anonix Privacy Proxy
Please rewrite the following notice so it is easier to understand:
Dear [PERSON_1],
Your application for housing benefit (Ref. [CASE_NO_1]) has been approved.
Payment account: [IBAN_1]
Address: [ADDRESS_1], [ZIP_1]
The AI works just as well with the placeholders as with the real data. In the response, Anonix automatically reinserts the original data—in real time, even for streamed responses. Nothing changes in the workflow for your software or your employees.
4The Solution—Anonix Privacy Proxy
Anonix is a transparent proxy that sits between your applications and the AI provider—whether OpenAI®, DeepSeek®, Mistral®, Groq®, Perplexity®, xAI® Grok®, Claude®, Gemini®, or a self-hosted model. Every request is automatically anonymized before it leaves the EU infrastructure. Every response is automatically de-anonymized before it reaches the employee.
What Makes Anonix Unique
For Decision-Makers
- GDPR-compliant by design—personal data never leaves the EU
- CLOUD Act neutralized—US providers see only placeholders
- No loss of productivity—employees work as usual
- EU-hosted SaaS—ready to use immediately, full data sovereignty
- Multi-tenant—isolated data per department or customer
For IT
- Cloud-based—no server of your own required, ready to go immediately
- All major LLM APIs—OpenAI® + all OpenAI®-compatible (DeepSeek®, Mistral®, Grok®, and many more), Claude®, Gemini®
- Streaming—real-time de-anonymization, even for SSE responses
- Admin GUI—manage providers, configure rules, monitor costs
- Audit log—complete logging, CSV export
Supported AI Providers and Models
| Provider / Protocol | Models (Examples) | Streaming |
|---|---|---|
| OpenAI® and all compatible APIs | GPT®-4o, GPT®-4, GPT®-3.5 Turbo, o1, o3 | Yes (SSE) |
| OpenAI®-compatible providers | DeepSeek®, Mistral®, xAI® Grok®, Perplexity®, Together AI®, Groq®, OpenRouter®, and many more | Yes (SSE) |
| Anthropic® Claude® | Claude® 4 Opus, Claude® 3.5 Sonnet, Claude® 3 Haiku | Yes (SSE) |
| Google® Gemini® | Gemini® 2.0 Flash, Gemini® 1.5 Pro, Gemini® 1.5 Flash | Yes (SSE) |
| Local / self-hosted models | Ollama®, LM Studio®, vLLM® (any OpenAI®-compatible model) | Yes (SSE) |
How the Protection Works
Anonix doesn’t detect personal data with a single method, but through four successive layers of protection. Each layer catches what the previous one missed.
Email, IBAN, phone, addresses
People, places, companies (8 languages)
Industry-specific, no training
Finds what everything else missed
Layer 1: Pattern Recognition
More than 60 patterns detect structured data such as email addresses, phone numbers, IBANs, tax IDs, monetary amounts, and dates. This works reliably and quickly because these data types follow a fixed format.
Layer 2: Anonix ConvNet NER
For unstructured data such as personal names, company names, and places, a neural network is used. It understands linguistic context and recognizes that “Munich” is a place and “Ms. Weber” is a name. In eight languages: German, English, French, Spanish, Italian, Dutch, Portuguese, and Polish.
Layer 3: Anonix Zero-Shot NER
Some industries have their own sensitive data types: diagnoses, case references, project numbers, cost centers. Anonix detects these without any programming. You describe the category in your own words, and the system learns it instantly.
Layer 4: AI Quality Check
A dedicated small language model checks the already anonymized text once more for overlooked fragments. It acts as a second opinion that judges independently of all other layers.
Before and After: An Example
Dr. Thomas Richter (t.richter@kanzlei-richter.de) represents Ms. Ingrid Bergmann in case Ref. 7 O 234/26. The next hearing will take place on 04/22/2026 at the Frankfurt Regional Court.
[PERSON_1] ([EMAIL_1]) represents [PERSON_2] in case [CASE_NO_1]. The next hearing will take place on [DATE_1] at the [ORG_1].
The AI still understands the context perfectly. It knows that this is about a court hearing, who represents whom, and when the hearing is scheduled. It just no longer knows who exactly is involved.
6Government, Public Administration & Public Sector
Ministries, state agencies, municipalities, and subordinate authorities process citizen data at the highest protection level. At the same time, Germany’s Online Access Act (OZG) mandates digitalization. Several German states have already adopted AI strategies, yet data protection officers block every direct API connection to US AI services. A political dilemma that can be solved technically.
The Challenge
- Citizen data is subject to BSI IT baseline protection and VS-NfD (restricted classified information) requirements
- Registration data, social benefit applications, building permits, and tax data must not reach third parties
- Police and security authorities process investigation data and witness protection information
- Educational institutions process student data and exam results
- State data protection laws prohibit cloud AI involving personal data
Anonix in Practice
Rewrite this administrative notice in plain, citizen-friendly language.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Dear Ms. Ingrid Bergmann, pursuant to Sections 1 and 3 WoGG (Housing Benefit Act), your application (Ref. WG-2026-04817) is granted. The benefit will be transferred to account DE89 3704 0044 0532 0130 00. | Dear [PERSON_1], pursuant to Sections 1 and 3 WoGG (Housing Benefit Act), your application (Ref. [CASE_NO_1]) is granted. The benefit will be transferred to account [IBAN_1]. | Dear Ms. Ingrid Bergmann, Good news: your housing benefit application (WG-2026-04817) has been approved. We will transfer the money directly to your account DE89 3704 0044 0532 0130 00. You don’t need to do anything else. |
Hospitals and Clinics
Under Art. 9 GDPR, health data enjoys the highest level of protection. Findings, diagnoses, medication plans, and treatment histories are special categories of personal data. A violation isn’t just a fine—it destroys the trust between doctor and patient. At the same time, AI-powered systems promise enormous advances in diagnostics, documentation, and treatment planning.
The Challenge
- Art. 9 GDPR: health data is a special category whose processing is prohibited in principle
- German state hospital laws impose additional requirements
- Hospital information systems (HIS) contain complete patient records
- Medical confidentiality under Section 203 of the German Criminal Code (StGB): disclosure to third parties is a criminal offense
- Enormous documentation burden: physicians spend up to 40% of their working time on documentation
Anonix in Practice
Turn these notes into a structured physician’s letter to the family doctor.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Patient Thomas Weber, DOB 03/14/1968. Diagnosis: type 2 diabetes. HbA1c: 8.2%. Medication: metformin 1000 mg. | Patient [PERSON_1], DOB [DATE_1]. Diagnosis: [DIAGNOSIS_1]. HbA1c: [VALUE_1]. Medication: [MEDICATION_1]. | Dear Colleague, We are writing regarding our patient Thomas Weber, DOB 03/14/1968. Diagnosis: type 2 diabetes Labs: HbA1c 8.2% Medication: metformin 1000 mg Plan: We recommend adjusting the therapy and a follow-up visit in 3 months. |
Care Facilities
Germany has more than 15,000 nursing homes and home care services. The skilled labor shortage is acute: over 35,000 positions are unfilled. Caregivers spend up to 30% of their working time on documentation instead of with residents. AI can reduce this burden—but care documentation contains health data under Art. 9 GDPR that must not reach external services.
The Challenge
- Care documentation, medication plans, and care logs contain Art. 9 data
- Resident data includes diagnoses, cognitive impairments, and behavioral issues
- Inspections by the Medical Service (MDK) require complete, audit-proof documentation
- Care home supervisory authorities and data protection authorities regularly review data processing
Anonix in Practice
Turn these notes into a structured handover report for the night shift.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Resident Ms. Helga Schneider, room 214, increased fall risk. Medication Marcumar adjusted to 2.5 mg. | Resident [PERSON_1], room [ROOM_1], increased fall risk. Medication [MEDICATION_1] adjusted to [DOSAGE_1]. | Night Shift Handover Ms. Helga Schneider (Rm. 214): - Increased fall risk—raise bed rails - Marcumar adjusted to 2.5 mg - Close monitoring required - Schedule next INR check |
Courts and Justice
The German justice system handles millions of proceedings every year. Case files, judgments, indictments, and witness statements contain the most sensitive personal data there is: victim data, witness protection information, statements by minors. Judicial confidentiality prohibits any uncontrolled disclosure. At the same time, the pressure is growing to shorten proceedings through AI-assisted research.
The Challenge
- Case files contain the names of defendants, victims, witnesses, and expert witnesses
- Juvenile criminal law: special protection for underage defendants and victims
- Witness protection programs: any disclosure of data can endanger lives
- Judicial independence requires that no external third parties gain access to case data
Anonix in Practice
Draft the operative part of a court order for these facts.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Defendant Marcus Klein, Ref. 7 O 234/26. Charge: fraud under Section 263 StGB. Injured party: Müller GmbH, Frankfurt. | Defendant [PERSON_1], Ref. [CASE_NO_1]. Charge: fraud under Section 263 StGB. Injured party: [ORG_1], [LOCATION_1]. | Order In the criminal case against Marcus Klein, Ref. 7 O 234/26, for fraud under Section 263 StGB to the detriment of Müller GmbH, a date for the main hearing is set at the Regional Court of Frankfurt. |
Social Services and Youth Welfare Offices
Youth welfare offices and social service agencies process the most sensitive data in our society: child endangerment, taking children into care, addiction issues, domestic violence. Case reports and assessments concern people in crisis. A data breach here is not an abstract compliance violation—it can destroy families and put children at risk.
The Challenge
- Case reports contain highly sensitive data about children, parents, and family situations
- Section 65 of Book VIII of the German Social Code (SGB VIII): social data is subject to heightened confidentiality protection
- Assessments contain psychological evaluations and psychiatric diagnoses
- Caseworkers are chronically overloaded; AI could ease the documentation burden
Anonix in Practice
Turn these notes into a structured case summary with recommended measures under SGB VIII.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Yilmaz family, 3 children (ages 4, 7, 12). Report by school, suspected child endangerment. Home visit on 02/12/2026. | [PERSON_1] family, [COUNT_1] children (ages [AGE_1]). Report by school, suspected child endangerment. Home visit on [DATE_1]. | Case Summary Family: Yilmaz Children: 3 (ages 4, 7, 12) Report: school Suspicion: Section 8a SGB VIII Home visit: 02/12/2026 Recommendation: Initiate parenting counseling under Section 28 SGB VIII |
Law Firms
Attorney-client confidentiality is not only protected by professional rules—a breach is a criminal offense under Section 203 of the German Criminal Code (StGB). Draft contracts, briefs, due diligence reports, and client data must never be disclosed to third parties under any circumstances. At the same time, AI offers enormous potential: contract analysis, research, brief review, and legal tech are fundamentally changing the industry. Law firms that don’t use AI lose clients.
The Challenge
- Section 203 StGB: disclosing data is a criminal breach of attorney-client confidentiality
- Contracts contain company names, trade secrets, purchase prices, and terms
- M&A transactions: due diligence documents of the highest confidentiality
- In the event of a data breach, opposing counsel could claim a conflict of interest
Anonix in Practice
Draft a liability clause based on this contract data.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Seller: TechVision GmbH, represented by Dr. Stefan Hofmann. Purchase price: EUR 4.2 million. Liability cap: EUR 840,000. | Seller: [ORG_1], represented by [PERSON_1]. Purchase price: [AMOUNT_1]. Liability cap: [AMOUNT_2]. | Section 7 Liability (1) The liability of TechVision GmbH, represented by Dr. Stefan Hofmann, is limited to EUR 840,000. (2) The buyer’s claims become time-barred 24 months after handover. (3) This limitation does not apply in cases of intent or gross negligence. |
Tax Advisors and Auditors
Tax confidentiality under Section 203 StGB protects client data under criminal law. Tax returns, balance sheets, salary information, and tax audit documents are among a company’s most confidential business data. A violation doesn’t just threaten the advisor’s license—it can trigger liability claims that threaten their very existence.
The Challenge
- Tax confidentiality under Section 203 StGB and Section 57 of the German Tax Advisory Act (StBerG)
- Client data includes revenue, salaries, assets, and tax IDs
- Tax audit documents contain detailed business figures
- The German Public Accountant Act (WPO) and ISA standards require strict information security for auditors
Anonix in Practice
Draft an objection letter to the tax office for this client.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Client Bäckerei Kraus GmbH, tax no. 013/123/45678. Objection to 2025 VAT assessment. Vehicle: 60% business, 40% private. | Client [ORG_1], tax no. [TAX_ID_1]. Objection to 2025 VAT assessment. Vehicle: 60% business, 40% private. | Objection Tax Office ... Tax no.: 013/123/45678 On behalf of and as authorized by our client Bäckerei Kraus GmbH, we hereby object to the 2025 VAT assessment. Grounds: With 60% business use, a proportional input tax deduction under Section 15 UStG must be recognized. We request a suspension of enforcement. |
Banks and Insurance Companies
BaFin-regulated companies are subject to banking secrecy and, since January 2025, under DORA (Digital Operational Resilience Act), to the strictest IT security requirements in the EU. Account data, loan applications, claims reports, and risk assessments require the highest level of protection. At the same time, banks and insurers are investing billions in AI-powered process automation.
The Challenge
- Banking secrecy under Section 383 of the German Code of Civil Procedure (ZPO) and the banks’ general terms and conditions
- DORA: strict requirements for IT risk management and third-party oversight
- MaRisk/BAIT: outsourcing rules for IT services
- Customer KYC data, account transactions, and credit scoring results are highly sensitive
Anonix in Practice
Turn this claims report into a settlement letter to the policyholder.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Policyholder Sabine Hartmann, policy no. KFZ-2026-881234. Accident on 03/03/2026 in Munich, Leopoldstr. 42. Damage: EUR 12,400. | Policyholder [PERSON_1], policy no. [POLICY_NO_1]. Accident on [DATE_1] in [LOCATION_1], [ADDRESS_1]. Damage: [AMOUNT_1]. | Dear Ms. Hartmann, Regarding your claim of 03/03/2026 (policy no. KFZ-2026-881234), we are pleased to inform you that the settlement process has been initiated. Location of loss: Munich, Leopoldstr. 42 Reported damage: EUR 12,400 An adjuster will contact you within 5 business days. |
HR Departments
Every company—regardless of industry—processes highly sensitive employee data in its HR department. Personnel files, applicant data, salary information, sick notes, and employee evaluations are personal data whose disclosure to third parties has consequences under both employment and data protection law. AI-powered recruiting, performance reviews, and workforce planning are booming—often without the data protection officer’s knowledge.
The Challenge
- Section 26 of the German Federal Data Protection Act (BDSG): strict purpose limitation when processing employee data
- Applicant data: compliance with the German General Equal Treatment Act (AGG) and discrimination risks in AI-assisted pre-screening
- Works agreements often explicitly regulate the use of AI tools
- Salary data, sick notes, and formal warnings are particularly sensitive
Anonix in Practice
Turn this internal job description into an external job posting.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Successor for Martin Schäfer, Controlling dept. Salary: EUR 78,000. Manager: Dr. Lisa Berger. Resignation effective 06/30/2026. | Successor for [PERSON_1], Controlling dept. Salary: [AMOUNT_1]. Manager: [PERSON_2]. Resignation effective [DATE_1]. | Controller (m/f/d) Your responsibilities: - Budget planning and forecasting - Monthly and annual closings - Reporting to Dr. Lisa Berger What we offer: - Compensation: EUR 78,000 - Start: as soon as possible |
Educational Institutions
Universities, colleges, schools, and research institutions are under double pressure: on the one hand, they are expected to be AI pioneers and provide students with modern tools. On the other hand, they process student data, exam results, and personal research data covered by state data protection laws. Several state data protection commissioners have already published recommendations against using US cloud AI services.
The Challenge
- State data protection laws and higher education acts govern the handling of student data
- Exam results, student ID numbers, and reasons for withdrawal are specially protected
- Research data involving personal information is subject to ethics committees
- Lecturers are already using AI extensively—often without institutional approval
Anonix in Practice
Turn this course evaluation into a structured improvement report for the academic committee.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Course BWL-301, Prof. Dr. Andreas Keller. Grade: 2.3. Comment: ‘The lecturer explains well, but Ms. Schneider from the tutorial was unprepared.’ | Course [COURSE_1], Prof. [PERSON_1]. Grade: [VALUE_1]. Comment: ‘The lecturer explains well, but [PERSON_2] from the tutorial was unprepared.’ | Evaluation Report Course: BWL-301 Lecturer: Prof. Dr. Andreas Keller Overall grade: 2.3 Strengths: Clear explanations in the lecture. Action needed: Involve and prepare the tutorial leader (Ms. Schneider) more closely. |
Pharma and Life Sciences
The pharmaceutical and life sciences industries process clinical trial data, patient information, and proprietary research results. GxP regulations, FDA 21 CFR Part 11, and the EU Clinical Trials Regulation set the highest standards for data integrity and confidentiality. AI speeds up drug development by years—but trial data must not fall into the wrong hands.
The Challenge
- Clinical trial data contains patient names, diagnoses, and treatment histories
- Proprietary compound data and research results are trade secrets
- GxP compliance requires complete traceability of all data processing
- Adverse event reports contain personal reports of side effects
Anonix in Practice
Turn this data into a structured adverse event report in CIOMS format.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Subject ID-4821, investigator: Dr. Maria Engel. Adverse reaction: grade 2 nausea after Compound XR-7. | Subject [ID_1], investigator: [PERSON_1]. Adverse reaction: [SYMPTOM_1] after [COMPOUND_1]. | CIOMS Adverse Event Report Subject: ID-4821 Investigator: Dr. Maria Engel Event: grade 2 nausea Suspect drug: Compound XR-7 Causality: possible SAE: No Action: symptomatic treatment, continued monitoring |
Software Companies and IT Service Providers
Software companies and IT service providers integrate LLM APIs into their own products—for customers in every industry. They are responsible for ensuring that their end customers’ data remains protected. A data protection violation affects not only their own company but every customer whose data flows through the API. Here, Anonix becomes an infrastructure component built into the product itself.
The Challenge
- Data processing under Art. 28 GDPR: the software provider is liable for its customers’ data
- Customer data from regulated industries (healthcare, finance, legal) flows through the API
- SOC 2 and ISO 27001 certifications require demonstrable data protection measures
- Customers increasingly demand proof of GDPR-compliant AI use in tenders
Anonix in Practice
Use this application data to write a structured acknowledgment of receipt to the applicant.
| Original Data | Sent to the AI | Result (De-anonymized) |
|---|---|---|
| Application from Anna Fischer, anna.fischer@email.de, for Senior Controller at Autohaus Schmidt GmbH. Desired salary: EUR 85,000. | Application from [PERSON_1], [EMAIL_1], for [POSITION_1] at [ORG_1]. Desired salary: [AMOUNT_1]. | Dear Ms. Fischer, Thank you for your application for the position of Senior Controller at Autohaus Schmidt GmbH. We have received your documents and are reviewing them carefully. You will hear from us within 10 business days. Sincerely, The HR Team at Autohaus Schmidt GmbH |
Why Existing Solutions Fall Short
There are certainly products that can detect personal data. But none of them solves the actual problem: using AI APIs securely without data leaving the organization.
| Criterion | Anonix | OpenRouter® | Microsoft® Presidio® | Google® Cloud DLP | AWS® Comprehend |
|---|---|---|---|---|---|
| Transparent AI proxy | Yes | Yes (AI gateway) | No | No | No |
| Supported LLM providers | OpenAI® + all compatible, Claude®, Gemini® | 400+ models | No proxy | No proxy | No proxy |
| Data stays in the EU | Yes (EU SaaS) | EU routing from Business plan | Yes | Google® Cloud | AWS® Cloud |
| Automatic de-anonymization | Yes | No, redaction only | No | No | No |
| Industry-specific detection | Zero-Shot NER | 8 types + regex | Standard only | 150+ types | Standard only |
| Multilingual (> 5 languages) | 8 languages | Not documented | Partial | Yes | 2 languages |
| AI-powered quality check | SLM review | No | No | No | No |
| Real-time streaming | SSE support | No de-anonymization | No | No | No |
| Typo tolerance | Fuzzy matching | No | No | No | No |
| EU-compliant deployment | EU SaaS | US Cloud Act | Open source | US Cloud Act | US Cloud Act |
Where Is the Difference?
OpenRouter® is an AI gateway with over 400 models and has recently added redaction of sensitive data. But the check only happens on the servers of the US company, so the data leaves the organization in plain text. The redaction is permanent: every name becomes [PERSON_NAME], the AI can no longer tell people apart, and the response contains no original data. OpenRouter® detects names and addresses only as a beta feature. If this check times out, the request is forwarded unredacted.
Google® Cloud DLP and AWS® Comprehend do detect personal data, but they are themselves cloud services of US companies. Taking a detour through AWS® Bedrock or Microsoft® Azure® in an EU data center doesn’t change anything either: the CLOUD Act applies regardless of server location, because the parent company is based in the US.
Microsoft® Presidio® is open source and can be run locally. But it has no proxy function, no de-anonymization, and no zero-shot detection. It is a toolkit, not a finished product.
The Architecture at a Glance
Anonix consists of five components that are operated as a fully managed SaaS service in the EU. Not a single byte of personal data leaves the European infrastructure.
The Five Building Blocks
| Component | Function | Technology |
|---|---|---|
| Anonix Backend | Proxy engine, anonymization, user management, API | Python® / FastAPI |
| Anonix Frontend | Admin interface for providers, rules, audit log | React |
| Anonix ConvNet NER | Neural network for detecting names, places, companies | CNN microservice (8 languages) |
| Anonix Zero-Shot NER | Industry-specific detection without training | Transformer microservice |
| AI Quality Check | Final review layer for overlooked data | Small language model (local or API) |
Security at Every Level
- AES-256-GCM encryption of all stored API keys
- Argon2id password hashing (military-grade standard)
- Isolated databases per tenant
- Two-factor authentication (TOTP)
- Rate limiting and CSRF protection
- Structured audit logging
Investment and Cost-Effectiveness
Data protection doesn’t have to be a cost driver. Anonix costs a fraction of what a single data protection violation would cost. And at the same time, it enables the productive use of AI that your employees are already asking for.
What a Violation Costs
What Anonix Costs
Anonix charges by usage—not by users. A base fee plus a price per anonymization request. Unlimited users in every plan.
| Volume / Month | Price per Request | In Euros | Notes |
|---|---|---|---|
| Up to 50,000 | 1.4 cents | EUR 0.014 | Entry level / small customers |
| 50,000 – 250,000 | 0.7 cents | EUR 0.007 | Standard / mid-sized companies |
| Over 250,000 | 0.5 cents | EUR 0.005 | Enterprise / large customers |
Base fee: EUR 99 – 999 / month depending on plan and company size. All prices plus VAT. SLM premium module (AI quality check with dedicated GPU inference): +1.4 cents per request.
Example: 100 Employees
Example: 500 Employees
Example: 1,000 Employees
Example: 5,000 Employees
Basis: ~10 AI requests per employee per working day × 22 working days = approx. 220 requests per employee per month. The more your company uses AI, the cheaper each individual request becomes.
All prices are net prices plus VAT.
Compliance at the Push of a Button
Data protection is not a project with a beginning and an end. It is an ongoing process. Anonix automates the technical measures that regulators require.
GDPR Compliance
- Art. 5(1)(c) (data minimization)—Only placeholders reach the AI provider. Personal data is reduced to the technically necessary minimum.
- Art. 25 (data protection by design)—Anonymization takes place before the API call. Without the proxy configuration, unprotected use is not possible.
- Art. 32 (security of processing)—AES-256 encryption, Argon2id hashing, two-factor authentication, and isolated tenant databases.
- Art. 28 (processors)—The AI provider sees no personal data. The requirements placed on the processor are significantly reduced.
- Art. 30 (records of processing activities)—Complete audit log with full logging of all proxy requests.
CLOUD Act and Third-Country Transfers
EU AI Act (Regulation 2024/1689)
Anonix is a data minimization tool and does not fall into any high-risk category of the EU AI Act. It makes no automated decisions about individuals, creates no profiles, and does not affect anyone’s rights. Rather, it reduces the risks posed by the actual high-risk applications (the external AI models).
Industry-Specific Compliance
| Regulation | Industry | How Anonix Helps |
|---|---|---|
| Section 203 StGB | Lawyers, tax advisors, physicians | Professional secrecy is preserved, since no client/patient data is transmitted |
| DORA (EU 2022/2554) | Banks, insurance companies | ICT risk management through controlled AI use |
| State data protection laws | Public administration | Citizen data stays on municipal/state infrastructure |
| SGB (social data protection) | Social services, youth welfare offices | Social data is anonymized before external processing |
Voices from the Field
The challenge is the same across industries: how can organizations capture the productivity gains of AI without losing control over sensitive data? Three perspectives.
Your Path to Anonix
Anonix is designed to take you from first contact to productive use in just a few days. No lengthy implementation projects, no rebuilding of your existing systems.
Consultation
We analyze your requirements: Which AI providers do you use? Which data types need to be protected? Which industry-specific rules apply?
Pilot Phase
Access to your Anonix SaaS account. Configuration of the anonymization rules. Trial operation with one team.
Production
Rollout to all workstations. Swap the API keys, done. Ongoing support, automatic updates, and assistance included.
Deployment
Anonix is provided as a fully managed SaaS service. Hosting, updates, maintenance, and support are included in the package. You can focus on your core business while we run the infrastructure—exclusively on EU servers, of course.
| Option | Description | Suitable For |
|---|---|---|
| Anonix SaaS | Fully managed solution on EU infrastructure. Hosting, updates, and support included. Ready to use immediately. | Companies, public authorities, law firms, medical practices |
| Enterprise On-Premises | For organizations with special data sovereignty requirements, we also offer a dedicated on-premises installation on request. | On request |
Ready for the Next Step?
Let’s find out together how Anonix fits into your organization.
info@anonix.ai • www.anonix.ai
Legal Notice
Copyright, Trademark, and License Rights
All copyright, trademark, and license rights to Anonix Privacy Proxy and this document are held by:
| Company | Convecto GmbH |
| Address | Ludwigstraße 180d, 63067 Offenbach, Germany |
| Phone | +49 69 40897270 |
| Web | www.convecto.com |
Trademarks
Anonix, Anonix Privacy Proxy, Anonix ConvNet NER, and Anonix Zero-Shot NER are trademarks of Convecto GmbH. OpenAI®, GPT®, Anthropic®, Claude®, Google®, Gemini®, Microsoft®, DeepSeek®, Mistral®, xAI®, Grok®, Groq®, Perplexity®, Together AI®, OpenRouter®, Ollama®, LM Studio®, Cursor®, GitHub® Copilot®, LangChain®, LlamaIndex®, and AWS® are trademarks of their respective owners.
© 2000–2026 Convecto GmbH. All rights reserved.
The information contained in this document has been compiled with the utmost care. However, no guarantee is given as to its accuracy, completeness, or timeliness.