Why customer data must never reach the language model in clear text
An AI assistant needs context, not names. How masking works — and why it must not be a switch anyone can forget.
The problem
A language model answers well when it knows the context: which appointment, which request, which history. The obvious approach is to simply give it everything — name, address, phone number, number plate. That is precisely the mistake. What leaves the building is no longer under your control, and data protection law requires that only what the purpose needs is passed on.
How masking works
Before a text goes to the model, personal data is replaced by placeholders: “Mrs Meier, Bahnhofstrasse 12, 079 …” becomes “Customer-1, Address-1, Phone-1”. The model works with the placeholders — it can plan appointments, phrase replies, set priorities, without ever seeing a real name. When the answer comes back, the placeholders are restored inside our own system. The customer gets a personal reply; the model never learned who they are.
We detect and replace names, addresses, phone numbers, email addresses, IBANs, number plates and AHV numbers — in German, French and Italian, because Swiss businesses have customers in all three languages.
Why it is not a switch
Masking that can be switched on can be switched off — by accident, for convenience, by an update. That is why ours sits at the single point where text leaves the system, and it cannot be disabled. Every request logs how many values were replaced; you see that number in your cockpit. The text itself is not stored.
