The redaction standard
Version 1.0. Written to be read by counsel. The technical annex, published with each package under its version number, covers how names and numbers are detected, how codes and fingerprints are built, what each gate checks, and how the final scan runs.
How names and identifiers are found
A pattern pass removes identifying numbers at intake. Two independent model readings then look for names in context. Anything one finds and the other does not goes to the owner, who is the one person who can recognize them. Before export, every record that will ship is read twice more.
Identifying numbers are removed, not coded
Social Security numbers, EINs, and account and loan numbers are removed the moment a file is read and never carried into any record. Only the few people at Spakari who need to see an owner's original files can open them, and we delete the files on a set schedule.
Codes instead of names
A person, place or company gets one code and keeps it in every record type and every year. The description that ships with the code, "the foreman hired in 2021," is what a reader needs. The name never ships. After delivery Spakari no longer holds it either, only a one-way fingerprint that keeps the code stable if the same person appears again.
Other people appear by role
No name or identifier of a third party appears in a package. Employees, customers and vendors appear by role. Government agencies and programs are named as they are, the IRS or the SBA for instance, and a local office keeps its function but loses its town.
The owner confirms the names
After each set of documents is read, the owner confirms who each person and company is, in plain words, before the records that mention them are used. At the end, the owner approves the package. Any check that depends on recognizing a person is done by someone from the business who knows them.
Nothing ships incomplete
The export stops if any declared document was not read, if any record is missing a provenance field, or if a record would be dropped silently. Every code in the records has an entry in the dictionary and every entry has a record. The manifest records the result of each check.
A final scan of every record
Two models read every exported record, looking for anything that reads as a name or an identifying number. Anything either one flags is settled before export. The descriptions that ship with codes are checked by the same rule, so a description never contains a word of the name it replaces.
Who takes part
Privately owned businesses. Two kinds are excluded. Publicly traded companies and the companies they own are one. Healthcare businesses, and any business that handles patients' health information, are the other. A financial-services business can take part with its own records, and its clients' records never come in.
What Spakari does not judge
The standard says nothing about whether a business's numbers are right. Every record states its source and its grain. None carries a flag or a variance. When two of an owner's documents disagree, both ship as they are. When an owner declines to settle a data item, the manifest says so and the records ship as the documents show them.
Annex of known behaviors
- The owner's first name, wherever it appears as a capitalized whole word, is replaced by the owner's code. When the owner's first name is also an ordinary word, that word is replaced too, so a capitalized common word can disappear from a line that never named anyone. Spakari accepts this over-match as the safe direction.