Data privacy
We know how important your data privacy is. Our platform was built around a redaction engine. Everything drawn from your documents, and every word of your interviews, passes through it. What Spakari buys from you is completely anonymized. That means no names, no identifying numbers, no addresses. Your employees appear only by their roles. Your employees' names never leave Spakari, and when your package is complete they are removed from our systems.
Schedule a meeting with one of our reps to discuss our data privacy procedures.
Each card says what we do in plain words. Tap Technical details for a deeper view.
Identifying numbers come out first
Social Security numbers, employer ID numbers, and account and loan numbers are removed the moment a file is read and never carried into any record or turned into tags.
Identifying numbers come out first
A pattern pass for known number formats (SSN, EIN, routing and account numbers, loan numbers) at intake. Matches are dropped, not tokenized, and never carried into any record. The source file itself is held under access rules until it is deleted on schedule.
Names go into a digital vault
The names of your employees, customers, vendors, and locations are held in a locked digital vault. A Spakari team member may see a document only when needed and only with your approval. Every access is logged.
Names go into a digital vault
Names are found by two independent model readings in context, applied together; anything one reading finds and the other does not goes to you to confirm, because you can recognize the people. The vault is a separate encrypted store with application-level encryption and its key held in a key-management service. Names are read only through an audited service path, each access recorded with who, why, and when.
Every name gets a tag
Outside the digital vault, each name is replaced by a tag with a plain description, for example "the assistant manager" or "the second location." The same person or place gets the same tag in every record and every question our interviewer asks.
Every name gets a tag
Tags are deterministic per entity (a type prefix and a sequence number) with a descriptor drafted by the model and confirmed by you. The same tag is used across every record type so the data stays connected without identity. The vault, which maps tags to real names, never ships; each tag's description does.
You confirm before anything is committed
After each set of documents is read, you confirm the people, places, and roles it mentions. Near the end of the process, you complete a final review of the package before signing off.
You confirm before anything is committed
A review gate closes each document set; the end-of-cycle review records the consent version with your approval. Export cannot start without an approval record. Your edits are checked for identifying information by the model before they are saved.
Your original files are held under access rules
Only the few people at Spakari who need to see your original files can open them, and we delete the files on a set schedule. The transcripts of the interviews carry tags in place of names, and all identifying numbers are removed.
Your original files are held under access rules
Uploads land in a private, encrypted bucket, read only through access-controlled, logged paths. Deletion follows a set schedule and is logged; a storage lifecycle rule backs up the explicit delete so nothing lingers past it.
Gates before anything leaves
Nothing leaves Spakari until every check passes — every declared document was read, every record carries its provenance, and a final scan finds no name or identifying number.
Gates before anything leaves
Coverage gate: declared, read, and exported counts must match, or export stops. Provenance gate: five fields on every record (source, collection date, consent ID, agreement version, redaction version). Residual scan: a model pass over every exported record; any hit blocks the export until resolved.
Names become fingerprints when your package is complete
When the package is complete, the names are completely removed from our system. They are replaced with a digital fingerprint.
Names become fingerprints when your package is complete
A keyed one-way hash produces the fingerprint; the per-business key is destroyed at completion, so the fingerprint cannot be reversed even by Spakari. Tags are retained; raw names are deleted and the deletion is logged.
Who sees what
Spakari staff and the vendors we contract, all bound by confidentiality, see your documents and interviews only when needed and only with your approval. Spakari buys only the anonymized package. No names, no identifying numbers, no addresses remain in the data.
Who sees what
Role-based access with per-access logging on the vault and the file store. Vendor terms cover confidentiality, no training on the data, and retention limits. If data is exposed outside policy, you are told. Access-under-policy language is part of the contract. When a document's layout is new to us, our model reads it in a sealed workspace with no internet connection, working from a copy that has already had identifying numbers removed.
