Skip to main content

    About Caredact

    Built so care teams can use AI without the breach.

    Care workers were already pasting case notes into ChatGPT to get reports written faster. Nobody was going to stop that by writing a policy. Caredact exists to make the safe way the easy way: the personal data comes out before the text goes anywhere, and goes back in when the work is done.

    What we believe

    Six rules we build to.

    1. 01

      Personal data never reaches the AI

      Identifiers are replaced before the text leaves Caredact. The model only ever sees placeholders, so there is nothing for it to leak, learn from or store.

    2. 02

      A person checks before anything is sent

      Every detection is highlighted on a review screen. Automation does the tedious part; the care worker stays accountable for what goes out.

    3. 03

      Built for care, not adapted to it

      Ofsted URNs, NHS numbers, looked-after-child references, school names and medication names are recognised because we wrote the detection for them.

    4. 04

      Everything stays in the UK

      Processing, storage and the AI itself all run in the UK. No transfers to work out, no adequacy questions to answer.

    5. 05

      Finished means gone

      When a document is complete, the map between placeholders and real details is permanently deleted. We keep the minimum for the shortest time.

    6. 06

      Plain English, no small print surprises

      The Data Processing Agreement, privacy notice and pricing are on the site for anyone to read before they talk to us.

    How it is built

    Our own detection engine, tuned for UK care records.

    Generic redaction tools look for credit card numbers and American social security numbers. Care records are full of things they have never seen: an Ofsted URN, a looked-after-child reference, a placement address, a school, a medication, an NHS number written three different ways.

    Caredact runs an established open-source detection framework with our own recognisers written for those identifiers, plus a second, learned layer that catches the names and relationships the rules miss. Every detection is scored, highlighted and shown to the care worker before anything is sent. Whatever the AI produces comes back with the placeholders still in place, and the export step restores the real details from a map that only Caredact holds.

    The engine keeps improving because we test it against realistic care notes rather than generic benchmarks. If it misses something in your records, tell us; that is how most recognisers were added.

    See the four steps on the homepage.

    Who is behind it

    A small UK company, accountable by name.

    Caredact is built and run by PixelArc Ventures LTD, founded by Matthew Galbraith. It is a small company on purpose: the person who designs the detection engine is the person who reads the support inbox and signs the Data Processing Agreements.

    Caredact has been through an NHS Innovation Service needs assessment, and we are working towards the certifications that NHS-adjacent and local authority buyers ask for.

    Company
    PixelArc Ventures LTD, 16305788
    ICO registration
    ZB962251
    Registered address
    510 Burnley Road East, Rossendale BB4 9LB

    So far

    A short history.

    1. 2025PixelArc Ventures LTD registers with the Information Commissioner’s Office (ZB962251) and starts building the detection engine.
    2. February 2026First production release, then called PasteGuard.
    3. March 2026Renamed Caredact to say what it is for: care, and redaction.
    4. May 2026All processing, storage and AI inference moved into the UK.
    5. September 2026New site and brand, and a public roadmap of guidance pages for care providers using AI.

    Talk to the person who built it.

    A 20-minute demo, or a free trial you can start today.