Nameshift

Find the personal data. Replace it with something believable.

Nameshift finds names, emails and phone numbers in your data and swaps each one for a realistic surrogate. Your tests, prompts and dashboards keep working. The real people are gone.

Pre-launch. Early access opens in batches; no spam.

support_tickets.csv · row 4 812scanning…
detectedreplaced

How it works

01

Detect

Point Nameshift at a file, a database or a stream. It finds names, emails and phone numbers, including the ones that don't match a regex.

02

Shift

Every match is replaced with a surrogate of the same shape: a Dutch name stays Dutch, a mobile number stays mobile, an email keeps its domain type.

03

Stay consistent

The same person becomes the same surrogate everywhere, so joins, counts and conversations still make sense.

Where it goes

Test and staging data

Production-shaped data without production people in it.

LLM prompts and logs

Send context to a model, not your customers.

Support tickets

Share conversations with vendors and analysts, readable and anonymous.

Analytics exports

Same rows, same joins, no identities.

Compliance

For whoever receives it, surrogate data is not personal data: the model, the vendor or the analyst cannot get back to the person. Only you hold the key.

  • CJEU C-413/23 P: pseudonymised data is not personal data for a recipient who cannot re-identify
  • Runs in your environment; the key never leaves it
  • Deterministic replacement, keyed to your secret
  • Every replacement reported back with the response

Try it

Type a message with private data in it and watch it leave as somebody else. This runs against a live gateway, the same code that sits in front of the model. Nothing you type is kept.

00 ms · you

You write it

Type freely
— · nameshift

It shifts

foundsurrogate
Mapping kept in this tab only. Only the right-hand side would reach a model.

Pricing

To be decided.

We're pre-launch and still working out the plans. Waitlist members get early access and a say in them. This is what runs today:

Finds eight kinds of personal data

People, e-mail addresses, phone numbers, addresses, dates, account numbers, URLs and secrets. A language model trained for the job, backed by checksum validators for IBAN, BSN and card numbers.

Surrogates that hold up

A name keeps its gender and origin, an address its city and street style, a date its distance to the others, an IBAN a valid checksum. The model reads something believable.

Consistent and reversible

The same value becomes the same surrogate every time, a first name on its own included. The mapping comes back to you with every request; nothing is stored on our side.

Drop-in gateway

Point an OpenAI or Anthropic client at it, streaming included, or call scrub and restore directly. One binary, runs on a CPU.

Five languages

Dutch, English, German, French and Italian text, detected per message.

Runs where your data is

Your laptop, your CI, your VPC. Only the surrogates go to the model.

Not there yet: tool calls, an audit log, a hosted version.

Questions

Is this the same as masking?

No. Masking gives you J*** D**. Nameshift gives you a different real-looking name, so downstream code and people can still work with it.

Can a surrogate be reversed?

Only if you keep the mapping, and only by you. The mapping is keyed to a secret you hold; without it there is no way back.

Where does my data go?

Nowhere. Nameshift runs where your data is: your laptop, your CI, your VPC.

Which languages and formats?

Dutch, English, German, French and Italian text at launch, through the API or as a drop-in gateway in front of OpenAI and Anthropic. More on the roadmap; tell us what you need on the waitlist form.

When do I get access?

We onboard in small batches so we can talk to everyone. Expect an email within a few weeks.

Nameshift

Be first in line. We'll write when your batch opens.