01
Intended recipient
Holds the documents and nothing else. Narrows inside the released set, comparing one position against the others received — no external register required.
Technology / Privacy Gateway
The document passes. The identity stays. Valico transforms documents and tabular extracts so they can reach an external recipient, an internal assistant or a test environment — and writes the dossier that documents why that release is defensible.
Every AI project inside a bank or an insurer hits the same wall: the documents that carry the value also carry personal data. Valico is the gateway in between — a KVA venture, built for the Italian financial sector, that lets a document leave the perimeter with only the data the recipient actually needs.
Valico runs today as a demonstrator on real bank documents, with the path to production mapped port by port. The engine, the policy model and the dossier are the product; what changes in production are the detectors behind them.
THE CLAIM, STATED PRECISELY
Robust pseudonymisation with recipient de-scoping under CJEU C-413/23 P. Never “anonymisation”: whether a released document is still personal data depends on who receives it and what means they hold — not on how aggressive the transformation was. A vendor who promises anonymity is selling a risk that the controller has to sign.
Pipeline
Verification comes after transformation, not instead of it — what the second reading finds is treated before delivery, not merely reported. The dossier is sealed last, after human review and after a named person has accepted the threshold.
Real file type, active content, hash of the original, chain of custody opened.
Routes every page: the native text layer on CPU, only the rasterised remainder to a vision model. It moves total processing time by an order of magnitude.
Text layer, XML, MIME parts, comments, tracked revisions, embedded attachments — then OCR on what is left.
Document, page, block, span, each with coordinates and provenance. Offsets are integrity-checked at build time: a span that slides by two characters is a redaction in the wrong place.
Every detector reads the text independently; detections merge into resolved spans and conflicts close by checksum, agreement or priority. Recall adds up across the union; precision is recovered downstream.
Differentiated transformation by declared purpose and by the legal qualification of the recipient. The rule that fired is written down for every decision.
Redaction, realistic surrogates, and neutralisation of everything that is not visible on the page — metadata, superseded generations, embedded objects.
A second detector set, built on different technology from the first, re-reads the transformed document. What it finds is treated before release: a verification whose findings only get reported is a report, not a control.
Hashes of original, transformed file and dossier; chain of custody, decision register, verification metrics and the accepted threshold. Sealed after human review.
Italian tax codes, VAT numbers, IBANs and card numbers are settled by checksum — DM 23/12/1976 including omocodia, DPR 633/1972, ISO 13616 with the national CIN, Luhn. A validator confirms or it does not; there is no confidence score to tune, and a valid VAT number belonging to a company is recognised as not personal data instead of being blacked out.
Names, addresses, places and free text go to open-weight models, whose output passes through the same validators. Legal-form recognition answers the question a general entity recogniser oscillates on — is this denomination a person or a company? — from a closed list, without disturbing a reviewer.
The hidden layers are where most products fail. A signature certificate carries the signer's tax code in a field no text extraction reads; XMP packets and superseded generations keep what the page no longer shows; an IBAN split across the boxes of a form is invisible to any search for twenty-seven consecutive characters, and is recomposed here by rule and confirmed by MOD-97.
Policy engine
The legal qualification of the recipient is an architectural constraint, not a contract clause. It is modelled in the types, so the software cannot promise what the law does not allow.
Recipient qualification
The data stays with the controller. De-scoping is not pertinent; purpose minimisation is.
Processes on the controller's behalf. De-scoping never applies, and no amount of transformation moves that: making the document less recoverable buys no protection, only a document the recipient cannot use.
Determines its own purposes and means. This is where de-scoping is decided — C-413/23 P §77 — on the means of re-identification reasonably available to that recipient.
No bounded recipient to assess against: the strictest regime of the four.
Exit modes
Identifiers removed with no key and no mapping table. For broad sharing, aggregate analysis and external models.
Realistic, stable surrogates; the mapping table stays with the institution in a separate domain. The document stays readable and linkable across files — and stays personal data.
Transformation calibrated on a single recipient, with watermark, bounded scope and access log. The mode that carries de-scoping when the recipient is an autonomous controller holding no key.
Only the categories without which the declared engagement cannot be performed. The lever here is not how irrecoverable the data is, it is how little of it leaves.
When de-scoping does not apply, the dossier says so and says why — processor under Art. 28, means of re-identification, key custody, onward chain to third parties. The residual value is written next to it: it is never “nothing”.
01
What the engine failed to recognise is a limit: it is measured, and it shrinks as the engine improves. On a structured, natively digital form it tends to zero.
02
What the engine recognised perfectly, but whose fate depends on something that is not in the document, is not a defect. That queue does not shrink — which is exactly why it satisfies Art. 14 of the AI Act: human oversight that exists only where the model errs disappears the day the model stops erring, and defensibility disappears with it.
The dossier prints how many cases were presented, the override rate, the median time per case and the reviewers. It is the numeric proof that oversight happened, rather than someone pressing “accept all”.
Alongside the queue, the full picture of the document groups every element by how the decision was taken: confirmed by calculation, recognised by form, recognised by content, recognised and deliberately left alone, decided by a person. The last two are the ones no competitor shows.
Residual risk
Not an aggregate F1. Three attacker models built on capability and reasonably available means — never on motivation, which the EDPB guidelines do not adopt — and for each one the number of people the document can still single out, with the chain of steps that got there. The result is a band between a low and a high hypothesis on declared parameters, and it is labelled as such rather than dressed up as a confidence interval.
01
Holds the documents and nothing else. Narrows inside the released set, comparing one position against the others received — no external register required.
02
Cross-references public sources: business register, official notice boards, cadastre, local press, demographic statistics.
03
Cross-references the same sources alone and in minutes. A worst case built on capability, not intent.
Who accepts the threshold
Risk appetite is expressed per attacker model as a minimum number of people the document must still be able to designate, and it is accepted by whoever answers for the process on behalf of the controller. The DPO gives an opinion; the decision is not theirs. A threshold accepted on different parameters is not the same decision, so the dossier records the parameter version next to the name and the timestamp.
In a table every row is a person. Columns are classified — by checksum where the cells are tax codes or IBANs, by a declared dictionary elsewhere, printed in the dossier with its provenance — and each column gets a rule at the grain the declared purpose needs: profession to category, postcode to province, birth date to decade, balance to bands.
Then the count. For each row, how many rows share its combination of quasi-identifiers at the released grain. Below the threshold written in policy the row does not leave, and the dossier gives the count and the reason. The exported CSV is deterministic: the count can be redone from the file in a spreadsheet.
k covers record isolation inside the released set — the first of the EDPB's three criteria. Linkability with other extracts and attribute inference are assessed separately. Saying so is the difference between a measure and a claim.
Free-text columns — the relationship manager's notes — are the one place a table needs to understand language. They go through the document engine cell by cell, with the same rules and the same review queue, or they do not leave.
Dossier
One HTML document per release, print-ready, with its own hash. It is the artefact a compliance function, an auditor or an authority reads — and the reason the whole pipeline is deterministic where it can be.
SHA-256 of the original, of the transformed file and of the dossier itself, recomputable with any standard tool
Recipient record: role, purpose, jurisdiction, key custody, onward chain to third parties, contractual safeguards and whether they are monitored
De-scoping assessment with its legal basis and citations — including the case where it does not apply
Policy in force, versioned, and the rule that fired on every single decision
Detector cards: engine, version, architecture, declared coverage and provenance of each parameter
Entity inventory by type and level: found, validated, transformed
Human review: cases presented, override rate, median time per case, reviewers
Independent verification: disjoint detector sets, divergences found, per-category recall with sample and interval, share of documents clean on first pass
Residual-risk measure per attacker model, with the threshold, who accepted it, when, and on which parameter version
Chain of custody: hash-linked events, actor and action for each
Open-weight models — chosen and configured by Valico, hosted by the institution: on a dedicated machine delivered pre-configured, or in the institution's own cloud. Model size follows the machine; the software is identical in both cases.
Zero outbound calls at runtime, telemetry off, no usage data back to us. The mapping table between surrogate and real value never enters the dossier package and never leaves the institution: whoever does not hold it does not get back to the people. The model extracts spans with constrained structured output — it never rewrites the document.
Deployment invariants
Formats — PDF (native and scanned), Word, Excel, CSV, SQL extracts
Delivery
Four phases. Each ends with something the institution owns, and none of them asks you to take our word for the previous one. Indicative durations — the perimeter, not the technology, sets the pace.
2–3 weeks
Recipients, purposes and exit modes written down; the data catalogue qualified column by column and signed by whoever owns the data; risk appetite set per attacker model. The output is a versioned policy, not a slide deck — and it is the institution's, not ours.
2–4 weeks
The re-identification bench runs inside the perimeter on real documents from the institution: what the released copy still designates, step by step, against the sources an attacker would actually hold. Where the engine cannot decide, it says so instead of pretending.
6–10 weeks
One release flow end to end inside the perimeter: local models on the institution's machine, both review queues staffed, the DPO's opinion, the threshold accepted by the process owner, the first dossiers issued and read by compliance.
ongoing
Policy rules signed and versioned; surrogate keys in KMS/HSM with declared rotation; RFC 3161 timestamping and WORM archiving of the dossier; SBOM, CVE handling, signed updates and a declared support period for the Cyber Resilience Act.
Once live, every file in the outbound queue sits in exactly one of these states. The dossier is sealed only at the last.
If there is a document flow you cannot open to AI — or to a recipient outside the perimeter — that is the conversation. We start from one real flow, one recipient and one purpose.