© KVA Team

Technology / Privacy Gateway

The gateway between regulated documents and your AI stack.

The document passes. The identity stays. Valico transforms documents and tabular extracts so they can reach an external recipient, an internal assistant or a test environment — and writes the dossier that documents why that release is defensible.

Every AI project inside a bank or an insurer hits the same wall: the documents that carry the value also carry personal data. Valico is the gateway in between — a KVA venture, built for the Italian financial sector, that lets a document leave the perimeter with only the data the recipient actually needs.

Valico runs today as a demonstrator on real bank documents, with the path to production mapped port by port. The engine, the policy model and the dossier are the product; what changes in production are the detectors behind them.

THE CLAIM, STATED PRECISELY

Robust pseudonymisation with recipient de-scoping under CJEU C-413/23 P. Never “anonymisation”: whether a released document is still personal data depends on who receives it and what means they hold — not on how aggressive the transformation was. A vendor who promises anonymity is selling a risk that the controller has to sign.

Pipeline

Nine stages. The order is the contract.

Verification comes after transformation, not instead of it — what the second reading finds is treated before delivery, not merely reported. The dossier is sealed last, after human review and after a named person has accepted the threshold.

S1

Ingestion and quarantine

Real file type, active content, hash of the original, chain of custody opened.

S2

Native or scanned

Routes every page: the native text layer on CPU, only the rasterised remainder to a vision model. It moves total processing time by an order of magnitude.

S3

Native extraction before OCR

Text layer, XML, MIME parts, comments, tracked revisions, embedded attachments — then OCR on what is left.

S4

Canonical representation

Document, page, block, span, each with coordinates and provenance. Offsets are integrity-checked at build time: a span that slides by two characters is a redaction in the wrong place.

S5

Detection in union

Every detector reads the text independently; detections merge into resolved spans and conflicts close by checksum, agreement or priority. Recall adds up across the union; precision is recovered downstream.

S6

Policy engine

Differentiated transformation by declared purpose and by the legal qualification of the recipient. The rule that fired is written down for every decision.

S7

Transformation and file fidelity

Redaction, realistic surrogates, and neutralisation of everything that is not visible on the page — metadata, superseded generations, embedded objects.

S8

Independent second reading

A second detector set, built on different technology from the first, re-reads the transformed document. What it finds is treated before release: a verification whose findings only get reported is a report, not a control.

S9

De-scoping dossier

Hashes of original, transformed file and dossier; chain of custody, decision register, verification metrics and the accepted threshold. Sealed after human review.

Deterministic where a rule decides. A model only where language is needed.

Italian tax codes, VAT numbers, IBANs and card numbers are settled by checksum — DM 23/12/1976 including omocodia, DPR 633/1972, ISO 13616 with the national CIN, Luhn. A validator confirms or it does not; there is no confidence score to tune, and a valid VAT number belonging to a company is recognised as not personal data instead of being blacked out.

Names, addresses, places and free text go to open-weight models, whose output passes through the same validators. Legal-form recognition answers the question a general entity recogniser oscillates on — is this denomination a person or a company? — from a closed list, without disturbing a reviewer.

The hidden layers are where most products fail. A signature certificate carries the signer's tax code in a field no text extraction reads; XMP packets and superseded generations keep what the page no longer shows; an IBAN split across the boxes of a form is invisible to any search for twenty-seven consecutive characters, and is recomposed here by rule and confirmed by MOD-97.

Policy engine

Who receives decides what leaves.

The legal qualification of the recipient is an architectural constraint, not a contract clause. It is modelled in the types, so the software cannot promise what the law does not allow.

Recipient qualification

Internal unit

The data stays with the controller. De-scoping is not pertinent; purpose minimisation is.

Processor — GDPR Art. 28

Processes on the controller's behalf. De-scoping never applies, and no amount of transformation moves that: making the document less recoverable buys no protection, only a document the recipient cannot use.

Autonomous controller

Determines its own purposes and means. This is where de-scoping is decided — C-413/23 P §77 — on the means of re-identification reasonably available to that recipient.

Public disclosure

No bounded recipient to assess against: the strictest regime of the four.

Exit modes

Irreversible redaction

Identifiers removed with no key and no mapping table. For broad sharing, aggregate analysis and external models.

Consistent pseudonymisation

Realistic, stable surrogates; the mapping table stays with the institution in a separate domain. The document stays readable and linkable across files — and stays personal data.

Regulated per-recipient release

Transformation calibrated on a single recipient, with watermark, bounded scope and access log. The mode that carries de-scoping when the recipient is an autonomous controller holding no key.

Purpose minimisation

Only the categories without which the declared engagement cannot be performed. The lever here is not how irrecoverable the data is, it is how little of it leaves.

When de-scoping does not apply, the dossier says so and says why — processor under Art. 28, means of re-identification, key custody, onward chain to third parties. The residual value is written next to it: it is never “nothing”.

Two review queues, not one.

01

What the engine failed to recognise is a limit: it is measured, and it shrinks as the engine improves. On a structured, natively digital form it tends to zero.

02

What the engine recognised perfectly, but whose fate depends on something that is not in the document, is not a defect. That queue does not shrink — which is exactly why it satisfies Art. 14 of the AI Act: human oversight that exists only where the model errs disappears the day the model stops erring, and defensibility disappears with it.

The dossier prints how many cases were presented, the override rate, the median time per case and the reviewers. It is the numeric proof that oversight happened, rather than someone pressing “accept all”.

Alongside the queue, the full picture of the document groups every element by how the decision was taken: confirmed by calculation, recognised by form, recognised by content, recognised and deliberately left alone, decided by a person. The last two are the ones no competitor shows.

Residual risk

How many people can the released document still designate?

Not an aggregate F1. Three attacker models built on capability and reasonably available means — never on motivation, which the EDPB guidelines do not adopt — and for each one the number of people the document can still single out, with the chain of steps that got there. The result is a band between a low and a high hypothesis on declared parameters, and it is labelled as such rather than dressed up as a confidence interval.

01

Intended recipient

Holds the documents and nothing else. Narrows inside the released set, comparing one position against the others received — no external register required.

02

OSINT

Cross-references public sources: business register, official notice boards, cadastre, local press, demographic statistics.

03

Agentic

Cross-references the same sources alone and in minutes. A worst case built on capability, not intent.

Who accepts the threshold

Risk appetite is expressed per attacker model as a minimum number of people the document must still be able to designate, and it is accepted by whoever answers for the process on behalf of the controller. The DPO gives an opinion; the decision is not theirs. A threshold accepted on different parameters is not the same decision, so the dossier records the parameter version next to the name and the timestamp.

Tables: the same discipline, decided by a count.

In a table every row is a person. Columns are classified — by checksum where the cells are tax codes or IBANs, by a declared dictionary elsewhere, printed in the dossier with its provenance — and each column gets a rule at the grain the declared purpose needs: profession to category, postcode to province, birth date to decade, balance to bands.

Then the count. For each row, how many rows share its combination of quasi-identifiers at the released grain. Below the threshold written in policy the row does not leave, and the dossier gives the count and the reason. The exported CSV is deterministic: the count can be redone from the file in a spreadsheet.

k covers record isolation inside the released set — the first of the EDPB's three criteria. Linkability with other extracts and attribute inference are assessed separately. Saying so is the difference between a measure and a claim.

Free-text columns — the relationship manager's notes — are the one place a table needs to understand language. They go through the document engine cell by cell, with the same rules and the same review queue, or they do not leave.

Dossier

What the de-scoping dossier contains.

One HTML document per release, print-ready, with its own hash. It is the artefact a compliance function, an auditor or an authority reads — and the reason the whole pipeline is deterministic where it can be.

01

SHA-256 of the original, of the transformed file and of the dossier itself, recomputable with any standard tool

02

Recipient record: role, purpose, jurisdiction, key custody, onward chain to third parties, contractual safeguards and whether they are monitored

03

De-scoping assessment with its legal basis and citations — including the case where it does not apply

04

Policy in force, versioned, and the rule that fired on every single decision

05

Detector cards: engine, version, architecture, declared coverage and provenance of each parameter

06

Entity inventory by type and level: found, validated, transformed

07

Human review: cases presented, override rate, median time per case, reviewers

08

Independent verification: disjoint detector sets, divergences found, per-category recall with sample and interval, share of documents clean on first pass

09

Residual-risk measure per attacker model, with the threshold, who accepted it, when, and on which parameter version

10

Chain of custody: hash-linked events, actor and action for each

Nothing leaves the institution.

Open-weight models — chosen and configured by Valico, hosted by the institution: on a dedicated machine delivered pre-configured, or in the institution's own cloud. Model size follows the machine; the software is identical in both cases.

Zero outbound calls at runtime, telemetry off, no usage data back to us. The mapping table between surrogate and real value never enters the dossier package and never leaves the institution: whoever does not hold it does not get back to the people. The model extracts spans with constrained structured output — it never rewrites the document.

Deployment invariants

on-premisededicated machine or institution cloudopen-weight models (Apache-2.0 / MIT)0 outbound requeststelemetry offexclusive key custody

Formats PDF (native and scanned), Word, Excel, CSV, SQL extracts

Delivery

How an institution gets to a first release.

Four phases. Each ends with something the institution owns, and none of them asks you to take our word for the previous one. Indicative durations — the perimeter, not the technology, sets the pace.

01

Perimeter and policy

2–3 weeks

Recipients, purposes and exit modes written down; the data catalogue qualified column by column and signed by whoever owns the data; risk appetite set per attacker model. The output is a versioned policy, not a slide deck — and it is the institution's, not ours.

02

Bench on your own documents

2–4 weeks

The re-identification bench runs inside the perimeter on real documents from the institution: what the released copy still designates, step by step, against the sources an attacker would actually hold. Where the engine cannot decide, it says so instead of pretending.

03

Pilot

6–10 weeks

One release flow end to end inside the perimeter: local models on the institution's machine, both review queues staffed, the DPO's opinion, the threshold accepted by the process owner, the first dossiers issued and read by compliance.

04

Production

ongoing

Policy rules signed and versioned; surrogate keys in KMS/HSM with declared rotation; RFC 3161 timestamping and WORM archiving of the dossier; SBOM, CVE handling, signed updates and a declared support period for the Cyber Resilience Act.

The release lifecycle

Once live, every file in the outbound queue sits in exactly one of these states. The dossier is sealed only at the last.

  1. To prepare
  2. Under review
  3. Independent verification
  4. DPO opinion
  5. Released

Your documents are the asset. The identities are the liability.

If there is a document flow you cannot open to AI — or to a recipient outside the perimeter — that is the conversation. We start from one real flow, one recipient and one purpose.