We started Pop Hasta Labs because the firms with the most to gain from AI — accountants, lawyers, advisers, clinics — are the ones who can least afford to leak client data. So we built the firewall first: SCRS, sold on its own to govern any AI. Then we built Other Me, a whole workspace, around it.
Every AI tool wants access to your data, and most are happy to send it to a model that remembers it. For a regulated practice, that’s a non-starter: confidentiality isn’t a setting, it’s the job. The result is that the teams who’d benefit most from AI keep it switched off.
The Secure Context Retrieval System (SCRS) is a patent-pending firewall (UK App 2602911.6) that detects and tokenises personal data before any model or index sees it, and rehydrates it only for authorised people at the moment of use. The AI gets to be useful; your clients’ information never leaves your control. SCRS is our flagship — a per-company product you can put in front of the AI you already use. And Other Me is the whole governed workspace built on it: CRM, email, the free Document, Workbook and Deck editors, live chat, tickets, automation and compliance — all on top of that one guarantee.
Most AI products bolt governance on at the end. We did the opposite — because for a regulated practice, the order matters.
Redacting an answer after the model has already read the raw record is a filter, not a firewall. The data was still exposed — to the index, to the prompt, to anything that logs along the way. For confidential work, “mostly removed” is the same as leaked.
SCRS enforces permissions during retrieval, so out-of-scope data is removed before any result exists. The vector index holds zero plaintext — no readable text, ever; the content sits in a separate encrypted store and is released only after cryptographic verification.
If any check fails, the system returns nothing rather than guessing. Personal data is tokenised before a single character reaches a third-party model — the AI sees client_4821, your authorised user sees Henderson Ltd.
Once the firewall held, we built the rest in-house — CRM, email and projects, live chat, ticketing, flows, HR-lite, finance and a full governance suite — so the same protection runs end to end instead of stopping at a connector.
These aren’t settings you switch on. They’re how the system is built — which is the whole point.
Permissions are applied during retrieval, so anything outside your remit never makes it into the candidate results. It’s a firewall, not a filter — the out-of-scope data is gone before there’s anything to redact.
The vector index holds no readable text. Content lives in a separate encrypted store and is only released after cryptographic verification — so a leaked index leaks nothing legible.
11 built-in regex types (email, UK/US phone, NI number, passport, postcode and more) plus spaCy NER for names, organisations and places. Personal data is tokenised before any third-party model call; tokens rehydrate only for the authorised user.
Any failure returns nothing instead of guessing. And when someone leaves, offboarding logically revokes their data access — the leaver kill-switch is wired straight into HR.
Read the deeper write-up on the security & governance page.
SCRS and Other Me are built by Pop Hasta Labs Ltd in the United Kingdom. Data stays on UK/EU residency, and we never use client data to train models. The core firewall is the subject of a UK patent application — it’s genuinely patent-pending, not borrowed governance dressed up as a feature.
A UK company building SCRS — the AI data firewall — and Other Me, the governed workspace on it.
UK Application 2602911.6 covers the SCRS firewall. Patent-pending — never “patented”.
Your data stays in-region. No client data is used to train any model.
ISO 42001, SOC 2 and ISO 27001 are on our roadmap. We are not certified against them today.
| Standard | Status |
|---|---|
| UK GDPR | Aligned |
| UK Age Appropriate Design Code | Aligned |
| ISO 42001 | On roadmap |
| SOC 2 Type II | On roadmap |
| ISO 27001 | On roadmap |
| HIPAA | No claim |
| EU AI Act | Monitoring |
Hard rule we hold ourselves to: nothing is described as certified until it is. We say “on track” and “on roadmap” because that’s the truth.
Because every module is first-party and sits behind the same firewall, the protection holds end to end — instead of stopping at the first connector.
Best model per job across GPT, Claude, Gemini and Grok — with shared memory and free Document, Workbook and Deck editors on every AI plan.
Pipeline and deals, quote → invoice → pay, e-sign, matters with ethical walls, and forms, booking pages and automation — Flows is included on every seat.
DSAR, RoPA, consent, DPIA, AI impact assessments, audit trail, operational registers and legal hold — the paperwork the regulator asks for, kept as you work.
Every module is described in detail on the product overview.
Our values aren’t a poster on the wall — they show up in the price list.
SCRS is per company — £24/mo, 7M tokens + 5GB. Other Me is per seat — £24/mo for the admin, £15/mo per extra member, the whole AI suite included. Office editors are free with AI; Flows is included on every seat.
No per-tier model gating — everyone gets best-model-per-job routing. The only paid extras are clearly priced: CRM & Operations (+£11/mo), e-signature (£2/employee) and extra storage.
Payments run through Revolut. Customer data is stored in the UK/EU as standard, and SCRS supports bring-your-own model keys today — there’s no separate “enterprise” upsell to unlock the basics.
Whether you want to put SCRS in front of your AI, run your practice on Other Me, or help build them — we’d love to hear from you.