Step 1: Identify what identifies the client
Before drafting with AI assistance, identify every element that would identify your client, the matter, or the opposing party: names, case references, dates, addresses, financial figures, contact details. In a short memo this is quick. In a multi-page brief with complex fact patterns, manual review is unreliable under time pressure — an attorney scanning for "sensitive information" before a filing deadline will miss things.
Step 2: Replace each identifier with a consistent placeholder
Swap each identified element with a neutral label — [CLIENT], [CASE_NUMBER], [DATE_OF_INCIDENT]. Consistency matters: the same entity should use the same placeholder throughout the document. A mismatch creates an incoherent prompt ("the agreement between [CLIENT] and [PARTY_A] was signed by [PERSON_2]") and a response that refers to the same person by multiple labels.
Step 3: Submit the redacted prompt
ChatGPT receives only the anonymized text. It returns a response using the same placeholders. Your client's name, case number, and identifying details have not reached OpenAI's servers. The AI's analysis is complete and usable — it just refers to [CLIENT] and [CASE_NUMBER] throughout.
Step 4: Restore real values in the response
Replace each placeholder in the ChatGPT response with the real value. In a short document, a find-and-replace handles this cleanly. In a long brief with many entities — particularly one where you've used generic placeholders like [PERSON_1] and [PERSON_2] for multiple individuals — this step requires care. A missed placeholder remaining in the final draft is a different problem than a disclosure, but it is an embarrassing one.
The automated version of this workflow
Naosuu runs steps 2–4 automatically for every prompt you submit to ChatGPT, Claude, or Gemini. It detects entities using pattern matching and an on-device NER model, substitutes unique named placeholders (not generic numbered ones) before transmission, and restores real values in the response with no manual find-and-replace required.
The redaction workflow becomes invisible — you draft normally, you read a complete response with real client names and case numbers in place, and nothing identifying has left your browser. The compliance step happens in the background on every prompt, not just the ones you remember to check.
Why the manual workflow fails at scale
Manual redaction works reliably for short, simple prompts where an attorney has time to review carefully. It fails for long documents, complex fact patterns, time-pressured work, and any situation where non-obvious identifiers (combination risk, unusual financial figures, distinctive locations) appear. The manual workflow is also inconsistent — applied carefully by the same attorney on Monday and carelessly on Friday under a deadline.
A technical measure that applies the same standard to every prompt, regardless of the attorney's attention at that moment, is more defensible under the "reasonable efforts" standard of Rule 1.6 than a workflow that depends on consistent human performance.
Automate the redaction step entirely
Naosuu handles steps 2–4 on every prompt, automatically. You type normally; your clients' data stays on your device. 30-day free trial, no credit card required.
Start free trial