Below the writing area, one control carries the confidentiality level of the message you are about to send. Six notches, from Not confidential to Highly confidential. The starting point is Standard confidentiality, because a consultant’s message touches a client file until proven otherwise.

The question the level answers

It is not “how sensitive is this data”. It is sharper than that:

What harm would this text do if a third party read it, once your data is masked?

The distinction matters, because the masking is identical at every level. It cannot be tuned, weakened or bypassed. What you declare is what remains on the table after the masking has done its work.

An example. You write:

Sylvain Beaudry, let go on 14 April by Groupe Fontaine inc. after eleven years as sales director.

What goes to the model:

PERSON_001, let go on 14 April by ORG_001 after eleven years as sales director.

Not one name left. And yet anyone who knows the file recognizes immediately who this is. That is what the level measures.

The six notches

0 — Not confidential

Nothing touching a person or a client. A general question, a template, market watch. The message could be published as it stands.

Examples: “what are the steps of a grievance”, “draft a demand letter template”.

The trap: an “invented” example that traces a real file is not level 0. If someone who knows the file recognizes it, you are at level 3 or higher.

1 — Slightly confidential

Business information from your firm, not public, with no identifiable person: your methods, your templates, your general positions.

2 — Moderately confidential

Personal information the masking removes in full. After masking, all that remains is business context nobody could tie to anyone.

Example: “PERSON_001 at ORG_001 is asking for thirty days to pay AMOUNT_001.”

3 — Standard confidentiality

The starting point. An identified client file whose context stays meaningful even masked: a dispute, a transaction, a mandate, a timeline.

This is the notch of the example above, and it covers most of your work. At this level, read the payload before sending: it is the measure that makes the send defensible, and the app puts it one click away (see Verify what goes on the network).

4 — Very confidential

Two ways in, and either one is enough.

  • Sensitive information: health, judicial or criminal record, biometrics, origin, beliefs, orientation, detailed financial situation. Or professional secrecy explicitly at stake.
  • An answer that will help decide a person’s fate: hiring, dismissal, promotion, access to credit, to housing, to an essential service, or a judicial matter.

At this level, the app steps in. If the provider you picked is one whose commitments could not all be verified, the send stops and tells you so. You can choose a direct provider, take the local model, or confirm the send knowing what you are doing: your decision is recorded.

5 — Highly confidential

The notch where masking is no longer enough. Three cases:

  1. Re-identification from context alone is likely. A unique person in a small community stays identifiable without their name: “the region’s only pediatric cardiologist”, “the CFO let go in April at a 40-person co-op”.
  2. A court order requires it: confidentiality, sealing, closed hearing, a non-disclosure undertaking.
  3. The foreseeable harm is serious: someone’s safety, domestic violence, whistleblowing, a minor’s data in a protection context.

At this level, the message does not leave your machine. Only the local model handles it. This is not a warning you can wave away: to send elsewhere, you must lower the level, and that is a deliberate act.

What the level does not do

  • It does not change the masking. Your entities are pseudonymized the same way at all six notches.
  • It excuses nothing. Even at level 0, your firm still owes its governance policy, its incident register, and its responsibility for what it entrusts to a third party.
  • It does not decide for you. At levels 4 and 5 the app stops you and says why. The judgment about your file is yours.

What gets recorded

Every send writes into your audit trail the declared level, the model aimed at, and what the rule decided. The number and the category only, never a word of your message. It is a record of your diligence, and it is written before the send, not after.

Next