Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
Pop Hasta Labs Ltd

AI you can point at
your clients’ data.

We started Pop Hasta Labs because the firms with the most to gain from AI — accountants, lawyers, advisers, clinics — are the ones who can least afford to leak client data. So we built the firewall first: SCRS, sold on its own to govern any AI. Then we built Other Me, a whole workspace, around it.

The problem we set out to fix

Every AI tool wants access to your data, and most are happy to send it to a model that remembers it. For a regulated practice, that’s a non-starter: confidentiality isn’t a setting, it’s the job. The result is that the teams who’d benefit most from AI keep it switched off.

Our answer: govern by construction

The Secure Context Retrieval System (SCRS) is a patent-pending firewall (UK App 2602911.6) that detects and tokenises personal data before any model or index sees it, and rehydrates it only for authorised people at the moment of use. The AI gets to be useful; your clients’ information never leaves your control. SCRS is our flagship — a per-company product you can put in front of the AI you already use. And Other Me is the whole governed workspace built on it: CRM, email, the free Document, Workbook and Deck editors, live chat, tickets, automation and compliance — all on top of that one guarantee.

What we believe

SCRS and Other Me are products of Pop Hasta Labs Ltd. SCRS is patent-pending (UK Application 2602911.6).
The origin story

We built the firewall first, then the workspace around it

Most AI products bolt governance on at the end. We did the opposite — because for a regulated practice, the order matters.

1

The realisation: a filter isn’t enough

Redacting an answer after the model has already read the raw record is a filter, not a firewall. The data was still exposed — to the index, to the prompt, to anything that logs along the way. For confidential work, “mostly removed” is the same as leaked.

2

The design: block before search

SCRS enforces permissions during retrieval, so out-of-scope data is removed before any result exists. The vector index holds zero plaintext — no readable text, ever; the content sits in a separate encrypted store and is released only after cryptographic verification.

3

The guarantee: fail-closed by default

If any check fails, the system returns nothing rather than guessing. Personal data is tokenised before a single character reaches a third-party model — the AI sees client_4821, your authorised user sees Henderson Ltd.

4

The product: a whole workspace on one guarantee

Once the firewall held, we built the rest in-house — CRM, email and projects, live chat, ticketing, flows, HR-lite, finance and a full governance suite — so the same protection runs end to end instead of stopping at a connector.

How the firewall actually works

One guarantee, enforced four ways

These aren’t settings you switch on. They’re how the system is built — which is the whole point.

01

Block before search

Permissions are applied during retrieval, so anything outside your remit never makes it into the candidate results. It’s a firewall, not a filter — the out-of-scope data is gone before there’s anything to redact.

02

Zero plaintext in the index

The vector index holds no readable text. Content lives in a separate encrypted store and is only released after cryptographic verification — so a leaked index leaks nothing legible.

03

Tokenise before the model

11 built-in regex types (email, UK/US phone, NI number, passport, postcode and more) plus spaCy NER for names, organisations and places. Personal data is tokenised before any third-party model call; tokens rehydrate only for the authorised user.

04

Fail-closed kill-switch

Any failure returns nothing instead of guessing. And when someone leaves, offboarding logically revokes their data access — the leaver kill-switch is wired straight into HR.

Read the deeper write-up on the security & governance page.

Patent-pending · UK company

A UK company, building on UK & EU rails

SCRS and Other Me are built by Pop Hasta Labs Ltd in the United Kingdom. Data stays on UK/EU residency, and we never use client data to train models. The core firewall is the subject of a UK patent application — it’s genuinely patent-pending, not borrowed governance dressed up as a feature.

UK

Pop Hasta Labs Ltd

A UK company building SCRS — the AI data firewall — and Other Me, the governed workspace on it.

P

Patent-pending

UK Application 2602911.6 covers the SCRS firewall. Patent-pending — never “patented”.

EU

UK/EU residency

Your data stays in-region. No client data is used to train any model.

42

ISO 42001 on our roadmap

ISO 42001, SOC 2 and ISO 27001 are on our roadmap. We are not certified against them today.

Where we stand today — in plain English
StandardStatus
UK GDPRAligned
UK Age Appropriate Design CodeAligned
ISO 42001On roadmap
SOC 2 Type IIOn roadmap
ISO 27001On roadmap
HIPAANo claim
EU AI ActMonitoring

Hard rule we hold ourselves to: nothing is described as certified until it is. We say “on track” and “on roadmap” because that’s the truth.

Built for the way regulated firms actually work

One governed workspace, not a stack of risks

Because every module is first-party and sits behind the same firewall, the protection holds end to end — instead of stopping at the first connector.

A

AI assistants & office editors

Best model per job across GPT, Claude, Gemini and Grok — with shared memory and free Document, Workbook and Deck editors on every AI plan.

Meet the assistants →

C

CRM, finance & flows

Pipeline and deals, quote → invoice → pay, e-sign, matters with ethical walls, and forms, booking pages and automation — Flows is included on every seat.

See the CRM →

G

Governance & compliance

DSAR, RoPA, consent, DPIA, AI impact assessments, audit trail, operational registers and legal hold — the paperwork the regulator asks for, kept as you work.

Explore governance →

Every module is described in detail on the product overview.

How we price, and why

Two products, priced plainly. No tier games.

Our values aren’t a poster on the wall — they show up in the price list.

Two products

SCRS £24/company · Other Me from £24/seat

SCRS is per company — £24/mo, 7M tokens + 5GB. Other Me is per seat — £24/mo for the admin, £15/mo per extra member, the whole AI suite included. Office editors are free with AI; Flows is included on every seat.

Clear add-ons

The AI suite is seat-included

No per-tier model gating — everyone gets best-model-per-job routing. The only paid extras are clearly priced: CRM & Operations (+£11/mo), e-signature (£2/employee) and extra storage.

Revolut

Simple, honest billing

Payments run through Revolut. Customer data is stored in the UK/EU as standard, and SCRS supports bring-your-own model keys today — there’s no separate “enterprise” upsell to unlock the basics.

Come build the governed future with us

Whether you want to put SCRS in front of your AI, run your practice on Other Me, or help build them — we’d love to hear from you.