Products
SCRS — the AI data firewall Other Me — the workspace Compare both products
Solutions
All solutions AI Assistants Email + Projects CRM Live Chat Ticketing Flows HR-lite Control Center
By industry
Accountancy Legal Mortgage & IFA Healthcare
Company
Custom Solutions Pricing Blog About Us
Log in
SCRS login Other Me — Business Other Me — Family Get started with SCRS
Architecture · · 6 min read

What Is a Patent-Pending AI Data Firewall?

AS

Founder & CEO, Pop Hasta Labs

From my perspective, the phrase “AI data firewall” is doing a lot of work and most people using it don’t mean the same thing. I want to describe what we mean by it in SCRS — our patent-pending AI data firewall (UK Patent Application 2602911.6), the standalone product Other Me is built on — because the mechanics matter.

What a firewall is, in this context

A traditional firewall sits between two networks and allows or blocks traffic basis rules. An AI data firewall sits between your users and the AI model, and allows or blocks the data that’s about to be sent for inference. The critical word is “about to be.” The firewall intercepts before the data reaches the model, not after.

Most AI tools have the opposite architecture — the data goes to the model, and if something sensitive is returned, they try to redact it post-retrieval. This is like letting the cat out and then trying to catch it. Especially for regulated practices, pre-retrieval blocking is the architecture I’d want to stand behind under scrutiny.

What our firewall actually does

Three structural properties. One, pre-retrieval scope enforcement — permissions are checked during search, so out-of-scope items never enter the candidate set. Two, zero plaintext in the vector index — the search index contains mathematical representations of content, not readable text; sensitive content lives in a separate encrypted store released only on verified retrieval. Three, 100% fail-closed — any failure at any stage returns zero content, never a best-effort guess that might leak.

Apart from this, PII redaction happens before send — NINOs, DOBs, names, addresses replaced with placeholder tokens before the model sees the content. And a per-user kill switch means when a staff member leaves, their historical prompts become un-decryptable.

Why this matters for UK SMEs

Especially for regulated practices, the firewall is designed to support your obligations under ICAEW, SRA, FCA, RICS, GDC and similar regulator frameworks. Without it, client data travels to the AI model in readable form and may be used for training. With it, client data stays in your tenant and the AI works from redacted representations — the model never sees the client’s actual identifiers.

I believe this is the specific architectural choice that turns AI from “possible compliance risk” into “confident compliance story.” A privacy policy says what the vendor intends. A firewall enforces what the vendor does.

Learn more

Technical detail on the Security page. Specific workflows on the Built for SMEs and vertical pages. You can get started with SCRS and examine the firewall behaviour directly.

AS

Abhishek Sharma

Founder & CEO of Pop Hasta Labs. Building SCRS — the patent-pending AI data firewall — and Other Me, the governed workspace built on it. Based in London.

Govern the AI your team already uses.

SCRS keeps client data out of the model — and Other Me is the whole governed workspace, built on it. No sales calls; set yourself up in minutes.