Translyx

Trust & product status

What Privexa does — and how mature each part is.

We'd rather you know exactly where each capability stands. This page carries the nuance so the rest of the site doesn't have to.

What Privexa is designed to do

A governed boundary before AI egress.

Privexa is designed to support governed AI use: it applies organisation-defined privacy policy to sensitive information before it reaches an AI model, preserves enough meaning for the task, restores authorised context inside the boundary, and records evidence of what left.

Product status

Capability status.

Available
Built and available for organisation use, subject to commercial agreement.
Pilot
Available to selected organisations in supervised pilots.
Controlled access
Built and available on request, with access granted per organisation.
Under validation
Developed capability currently undergoing extended testing and qualification.
Research
Exploratory work. Not offered for operational use.
Privexa module status
Module / modalityStatus
Privexa Secure AIControlled access
Privexa Documents & KnowledgeControlled access
Privexa Image PrivacyControlled access
Privexa Large Image ProcessingControlled access
Privexa WSIUnder validation
Privexa ScribePilot
Privexa GovernanceControlled access
Privexa API / GatewayControlled access

Privacy architecture

Authority you can trace.

durable instructions → versioned resolution → immutable derived protection → audited egress → scoped reconstruction

  • Tenant isolation

    Each organisation's data, policy and authority are explicitly scoped.

  • Server-authoritative model policy

    Approved providers and models are enforced on the server, not chosen by the client.

  • Versioned privacy authority

    Protection is derived from versioned state. Reprocessing creates new authority.

  • Exact protected-version approval

    Approval is bound to the exact protected representation. Stale approvals do not silently transfer.

  • Audited AI egress

    Evidence of exactly which protected representation was authorised to leave the boundary.

  • Fail-closed protection

    When protection cannot be established, the workflow stops rather than sending raw data.

  • Controlled reconstruction

    Original context is restored only for authorised users, inside the boundary.

Provider handling

Approved providers and models are set by the organisation and enforced server-side. Current engineering supports configurable access to OpenAI, Anthropic Claude and Google Gemini models, with private/self-hosted models as a deployment direction. Specific models are approved per organisation, not assumed.

Human review

Image and slide protection include reviewer workflows. Generated outputs that matter — clinical notes, protected slides — are designed for human review before release.

WSI validation status

Whole-slide privacy is a developed capability under extended validation. Evaluations confirm format coverage, throughput and reviewer workflow against your slides.

Deployment approach

Managed, private cloud, on-premises and restricted environments are scoped per customer. Not every mode is qualified at production scale for every module.

Auditability

Each AI egress is recorded against the exact protected representation, model and workflow that was authorised.

Security testing

Security testing is part of Privexa engineering. We discuss testing scope and results directly with prospective customers during evaluation.

Responsible claims

What we don't claim.

  • Perfect privacy or zero leakage under all circumstances
  • Automatic detection of patient identity within tissue morphology
  • Compliance with any specific regulation by default — compliance depends on your deployment and policy
  • Support for every whole-slide image format
  • Regulatory approval or certification that has not been obtained
  • Production deployment of every module in every environment