Celatum detects and anonymizes personal data in Word documents — entirely on your machine. Built for Swiss lawyers, fiduciaires, and healthcare professionals bound by professional secrecy.
✓ 100% offline · ✓ DE / FR / IT / EN · ✓ Aligned with FADP & GDPR
Professional personal identifiers anonymization for legal, compliance, and enterprise teams.
Our AI model detects 50+ Personal identifier types — names, emails, SSNs, addresses, phone numbers, IBANs, dates of birth, and more. Runs on CPU, no GPU required.
Consistent, document-scoped replacements (Person A, Organization 1) preserve readability while masking real identities. Export pseudonym key files for reversible workflows.
Drop files or paste text. Process single files or batch entire folders. Output to DOCX with anonymized or pseudonymized content, ready for filing or publication.
The AI model runs entirely on your local machine. Documents never leave your device — no cloud, no uploads, no third-party APIs. Air-gapped environments supported.
Toggle detected entities on or off before anonymizing. Add custom terms, adjust detection labels, right-click to merge or split entities. You decide exactly what gets anonymized.
Restore original values using encrypted key files. Reversible anonymization for internal review, legal proceedings, or audit trails.
Built-in glossary with Swiss legal terms in EN, DE, FR, and IT. Translate personal identifiers labels, titles, and legal terminology. Fully customizable per user.
Built so your processing stays compliant. Documents never leave your device — no transfer, no third-party processor, no cross-border data flow to assess. Secure memory zeroing, AES-256 encrypted license data, append-only audit log, no telemetry.
Save pseudonymized documents as .piia templates. Re-populate with real or alternative data later — ideal for court filings, case studies, and recurring document workflows.
Built with enterprise-grade security controls from day one. No data ever leaves your machine.
Encryption for stored keys, OS-level access controls, automatic memory wipe at session end, signed and timestamped builds, and a minimal network surface — every layer engineered to fail closed.
Document content never leaves your machine — no uploads, no telemetry, no error reports. License and update checks carry zero document data. Reproducible builds let you verify the binary matches the public commit.
Designed for professionals bound by legal confidentiality obligations. Compliant with GDPR and the Swiss Federal Act on Data Protection (FADP/DSG). All personal identifiers processing is fully local — zero data transmission to third parties.
Simple, transparent pricing. All features included. No hidden costs.
Multi-seat discounts: 5+ seats 10% off · 10+ seats 15% off · 25+ seats 20% off
Need more than 50 seats or custom deployment? Contact us for enterprise pricing.
Yes. Celatum is designed around the local-only processing principle: no document content is transmitted, stored, or logged outside your device. This aligns with the data minimisation, purpose limitation, and security-of-processing requirements under FADP Art. 6 and 8 (and the equivalent GDPR Art. 5 and 32).
No. The Personal identifier detection model and all anonymization logic run on your CPU, locally. The only network traffic is a periodic license-validity check (once a month, with offline fallback) and the optional automatic update check — neither carries document content, file names, or detected entities.
Cloud LLMs require sending the original document content to a third-party server, which is generally incompatible with professional secrecy obligations (Art. 321 StGB) and creates a meaningful FADP exposure. Celatum performs the same kind of named-entity detection but locally, so the document never leaves your device. Use cloud LLMs for non-sensitive drafting; use Celatum for client material.
Manual redaction tools require you to select each item to anonymize, one at a time. Celatum auto-detects names, addresses, AHV numbers, IBANs, dates of birth, and 45+ other entity types in DOCX, lets you toggle them in a review panel, and applies the anonymizations in one pass. It also supports reversible pseudonymization — replacing real values with stable placeholders — which selection-based tools do not.
Each license activates one seat on one device. For firms, multi-seat plans bundle multiple activations under one billing entity, with discounts at 5+, 10+, and 25+ seats. Seat re-assignment between devices (for example when a colleague leaves) is straightforward — contact us and we'll release the old activation.
Your license remains active until the end of the period you have already paid for. After that, the app stops applying new anonymizations but you keep access to documents you have already produced. You can re-subscribe at any time and resume on the same device. There is no separate "data export" step because all your data is already on your machine.
The detection model is trained on multilingual text and works on documents in German, French, Italian, and English (the four Swiss working languages). It recognises 50+ entity types including persons, organisations, addresses, AHV/AVS numbers, IBANs, dates of birth, phone numbers, email addresses, court references, case numbers, and more. The full label list is configurable inside the app.
Latest version: 1.0.1
Intel Mac users: contact us for an x86_64 build.
Disclaimer: This application is designed to assist with Personal identifier detection and anonymization, not to replace human judgment. All output should be reviewed by a qualified person before use. Automated detection may produce false positives or miss certain data. The user bears full responsibility for verifying the accuracy and completeness of anonymized documents.