Sidian DataGuard - Nothing sensitive leaves your firm. Even into AI.

by•
Checks everything leaving your firm, redacts what shouldn't go, and gives you a governed private AI you own instead of a black box you rent.

Add a comment

Replies

Best
Maker
📌
Hey Product Hunt! I'm Ben, founder of Sidian. Before this, I built classified redaction systems for Canadian intelligence, inside one of the most secure environments there is. Part of my job was helping government teams move sensitive data across jurisdictions without a single leak, while following multiple regulation that came with it. When I left that world and started looking at law firms, I saw the same problem sitting in a different room. Since starting this company, I've talked to over 1,000 law firms, and the pattern showed up almost everywhere. Firms share just as much sensitive data as the agencies I used to work with. They're held to real regulations too. But almost none of them have the tooling to actually do it right. Here's the thing most firms get backwards. They've spent years locking down the front door: firewalls, access controls, MFA. Guarding against someone breaking in. But the real leak risk isn't a hacker at the gate anymore. It's an employee with more file access than their role needs. It's a routine email to opposing counsel. It's a paralegal pasting case notes into ChatGPT to save an hour. The front door's guarded. The back door's been open the whole time, and AI just added a dozen more doors nobody's watching. That's what became DataGuard. A full data protection platform for the part of the problem regular security tools don't touch: everyday sharing, and everyday AI use. Here's what that looks like in practice. A paralegal attaches a discovery file to send to opposing counsel. Before it goes out, DataGuard checks it against the firm's own policy, built from whatever mix of CPRA, GDPR, and HIPAA actually applies to that client. It finds a privileged note buried in the file. It catches a client's SSN a few pages later. It redacts both and lets the rest through untouched. Every decision gets written down: what was found, which rule caught it, who approved it. If the firm ever has to defend that disclosure later, the record's already there. Most firms still catch this by hand today. A paralegal reads the whole file before it goes out to litigation, an expert witness, or opposing counsel. That takes real time out of a busy week, and people still miss things. DataGuard runs on an entity recognition system built for legal documents, about 98% accurate, so the check happens in the background instead of eating someone's afternoon. The risk here is real money. IBM's 2025 research put the average cost of a data breach at $10.22 million, and that's before any regulatory fine on top. What DataGuard does: Pre-flight check on everything leaving the firm: email, file share, data room, AI chat. Redacts what shouldn't go, releases the rest right away. Outside AI Protection: use ChatGPT, Claude, or Copilot on your files safely. Sensitive info swaps for realistic stand-ins before a frontier model ever sees it. Governed private AI: run an open-weight model on hardware your firm owns, with our control layer on top. As one example, Qwen3.6 27B scores 80.1% on its own on GPQA Diamond. Add our layer, same model, same hardware, and it jumps to 92.4% on the first pass, closing most of the gap to Gemini and GPT while staying private. The layer grounds every answer in your actual source documents instead of the model's memory, and catches low-confidence answers before they go out instead of letting them hallucinate through. Audit log: a hash-chained record of what left, what was caught, and who cleared it. It plugs into what you already use: Outlook, Gmail, Clio, SharePoint, OneDrive, Drive. Files stay where they live. We don't copy or store them. What we keep is the record of what was checked, never the content itself. SOC 2 Type II, built to GDPR and HIPAA requirements. Built for law firms first, since they have the sharpest version of this problem. But it holds anywhere sensitive data leaves a company and someone needs to prove it left clean. What would make you trust an AI layer with your real client files?