The glass ledger · content-blind analysis

Analyse the spreadsheet you could never paste into an AI.

Payroll, pipeline, patient lists, cap tables. cloak-sheets detects sensitive cells and swaps them for realistic surrogates on your device. Ask a question in plain English — the model writes the analysis, and the code runs locally, over your real numbers. The names it detects never leave the tab; what detection covers, and what it misses →

Upload your own ↓
  • schema + 8 cloaked rows is all that is relayed
  • on-device Pyodide analysis
  • measured egress receipt

The workbench

Everything below happens in this browser tab. Only your question, the column names and a cloaked 8-row sample are relayed — never the full table.

Drop a CSV, TSV or xlsx here — or click to choose

The file is parsed and cloaked entirely on your device. Nothing uploads.

or paste rows

How it stays content-blind

01

Cloak on the device

Every cell runs through the on-device engine. The values it detects become realistic, locale-matched surrogates; those real values and the map to restore them never leave the tab.

02

Send only the schema

Your question goes to the model with the column names and a handful of surrogate rows — enough to write correct analysis code, nothing real. It's relayed through the CloakAPI gateway, billed as markup.

03

Run the code here

The model's Python runs in a sandboxed worker on your device — pandas and matplotlib over your real rows, with no network. The answer and charts render locally; the receipt shows the raw-PII byte count measured on the bytes that left the tab.

Free to cloak and analyse. Pay only for the ask.

On-device cloaking and the full analysis runtime are free, forever. Natural-language analysis is billed as markup on the model — Personal $15/mo, Business $35/seat.