Veld Intelligence

Built · not switched on · no provider engaged

An assistant that is never shown your records.

Every other product in this category answers questions by giving a model access to your database. Veld cannot: your records are sealed with a key we do not hold. So the model is given tools instead — tools that run in your browser and hand back an answer with the names taken out.

Not switched on yet, and this page is here first on purpose. The assistant is built, no model provider is engaged, and nobody can use it today. We are publishing how it works before it ships rather than after, so you can assess it while your answer can still change ours. Where this page describes contractual terms, those are requirements we have committed to meet before launch — six of them, each pass or fail — and not terms already in force. When one is signed, the provider is named on the security page and in the privacy notice, and this box goes.
The shape of it

You ask about your book; the model never sees it

Ask "which of my clients has something overdue" and nothing about your practice is uploaded to answer it. The model asks for a tool by name. The tool runs on your machine, against the workspace already open in front of you, and returns a deliberately narrow answer with every name stripped out.

What the model reasons about is request 7f3a91c4. What your screen shows is A. Okafor — Harborview Housing Association, because the substitution happens back on your device after the answer arrives.

  • Eleven tools, every one of them read-only
  • Client and subject names never leave your browser
  • The transcript lives on your device and travels with each turn
  • Off unless you switch it on, on a plan you have chosen to pay for
What it can be asked

Eleven tools, and not one of them can write

The assistant answers from your workspace, not from what a model remembers about UK GDPR. Each tool declares in code exactly which fields it may emit, and the gateway rejects any result carrying a field outside that list. Six of the eleven, to show the shape of them:

What is overdue, and what is close

Every clock across the whole book, ranked by how much time is left rather than by client. A deadline that has passed and one a fortnight away are told apart, because the work they imply is not the same.

Where one request stands

The right relied on, the status, the date received, the statutory deadline and whether an extension is running. Enough to answer "what is happening with this one" without opening it.

Which clients are exposed

Sector, data-protection role and open work per client, plus the health score and the components it is built from — the same arithmetic the dashboard shows you, so the two can never disagree.

Gaps in the registers

Which Article 30 entries are missing a purpose, a lawful basis or a retention period; which DPIAs are sitting unreviewed and for how long. Presence and absence, not the content of the entry.

Breaches and their hours

The 72-hour clock in the units it actually runs in, with the time left to notify. What the breach was about stays on your device; how long you have does not need to.

What is in a bundle

How a disclosure bundle is made up — how many documents, how each is marked, how large. The documents themselves are never read by a model; the scan that looks inside them runs on your device and involves no model at all.

The loop

Four steps, and you can watch every one

You ask

In the app, in the workspace you already have open. The question is the only thing you write.

The tools run here

The model names a tool; your browser runs it against the decrypted workspace. There is no server-side copy for it to reach, because there is no server-side copy.

A minimised result goes up

Identifiers and dates, checked against the declared field list on the way out. Names, notes and free text are not in it.

The answer comes back

Your device puts the names back in before you read it. What you see is about your clients; what travelled was not.

What actually leaves, in full

This is the part to check rather than take on trust. Ask "what is overdue" and the tool does not send the request — it sends this:

A. Okafor — Harborview Housing Association Subject access · due 14 July 2026 · 12 days over
{ "kind": "dsar", "ref": "7f3a91c4", "dueOn": "2026-07-14",
  "daysOver": 12, "clientRef": "c2b80e15" }

No subject name. No client name. No notes, no free text, nothing about what the request is for. ref and clientRef are your workspace's own internal identifiers — random strings that mean nothing outside your browser.

Stays on your deviceGoes to us, in transit onlyReaches the model provider
The workspace and every record in itYour questionYour question
Client and data subject namesThe minimised tool resultThe minimised tool result
Notes, correspondence, documentsToken counts, for billing—
Your encryption key——

Our gateway keeps no conversation between one turn and the next — the transcript travels with each request and lives in your browser. We write no prompts, no answers and no tool results to any log, trace or error report; what we record is an account id, token counts, and which model answered. The security page sets out how that claim is tested, and what you can verify yourself from the Network tab.

What it will not do

A feature page that lists only capabilities is an advertisement. These are the limits, and they are the reason the design looks the way it does.

  • It cannot change anything. Every tool is read-only — not "we instruct it not to write", but no tool that writes exists, so there is nothing to instruct. Anything the assistant suggests is a suggestion you act on yourself.
  • Prompt injection has no complete defence, here or anywhere. A document in a disclosure bundle could carry text addressed to the model rather than to you. What contains it here is that a successful injection can mislead a human and cannot act.
  • It can be confidently wrong. It is told to answer only from what the tools return, and it will still occasionally produce a wrong number stated plainly. Every answer points at the records it came from so you can check it in one click.
  • It means a third party processes a request about your work. That is the honest trade and it is why the feature is optional. If your practice cannot send anything to a model provider under any conditions, leave it off — everything else in Veld works exactly the same.
  • It will not be free. Every question costs us money at a provider rather than being a switch we flipped, so it sits on a paid plan. That is the one thing in Veld that is genuinely not in the free version.

The six requirements, before anyone can use it

Decided in the abstract, on purpose, rather than later against a provider someone has already fallen for. All six are pass or fail — a strong provider does not offset a weak term — and if none meets all six, the outcome is no assistant, not a rewrite of this page.

  • Zero retention of request and response content. Not "deleted after thirty days": not written to durable storage at all, or deleted within a defined short window with the window stated.
  • No training on customer content, explicitly, covering fine-tuning, evaluation sets and human review.
  • UK or EU region processing, contractually pinned rather than set in a console — an operator can change a setting and cannot change a term.
  • Content-free logging, or contractual limits on what may appear in provider-side logs. Logs are where content leaks unnoticed.
  • Sub-processor transparency: a published list and advance notice of changes. We cannot promise downstream what we are not promised upstream.
  • A DPA on Article 28(3) terms, including audit rights and breach notification within a defined period.

None of these is in force today, because no provider is engaged. They are the bar a candidate is measured against, and the reason this page can describe an assistant nobody can switch on.

Questions

The things practitioners ask first

Can I use it today?

No. The assistant is built and it is not switched on yet — no model provider is engaged, and there is nothing to enable in your settings. Everything else on this site is available now, including the whole free portal.

Does the model see my clients' names?

No. Tools run in your browser and return pseudonymous references; the substitution back to real names happens on your device after the answer arrives. The gateway independently rejects any tool result carrying a field outside the list that tool declared, so a mistake in that code fails your request rather than quietly sending more than it should.

Could it delete or change a record?

No. There is no tool that writes. The model can ask eleven questions and take no actions, which is also the honest answer to prompt injection: text hidden in a document can mislead you, and cannot do anything.

What happens to my workspace if I leave it off?

Nothing changes. It is off unless you switch it on, and the rest of Veld — the clocks, the registers, the response packs, the on-device document scan — behaves identically whether the assistant exists or not.

Who is the model provider?

There isn't one yet, and that is a deliberate state rather than an oversight. A candidate has to meet six mandatory requirements, starting with zero retention of request content and no training on it. When one is contracted it will be named here, on the security page and in the privacy notice, and it becomes a sub-processor with the notice period set out in our processing agreement.

Why is this the one feature behind a paid plan?

Because every question costs us money at a model provider. Everything that runs on your own machine is in the free portal for as long as you want it, with no trial clock and no cap on clients or records. An assistant is not that kind of feature, and pretending otherwise would mean either a worse assistant or a worse company.

Will this page change when it ships?

Yes, and that is the point of publishing it early. The pre-launch box at the top comes off when a provider is contracted, the DPIA is signed rather than drafted, the Article 28 schedule names the provider, and the verification steps on the security page are followable by a reader. Until all of those, the hedging stays.

The rest of it works today

The assistant is the one part you cannot try yet. The workspace it would answer questions about is open now, on your machine, with nothing to provision.