Custom rules and profiles: masking what is specific to your company
Built-in detectors cannot know your client names or project codes. How custom rules, profiles and Also mask cover them, and the exact plan limits.
Built-in detectors find values with a known shape, such as an email or an IBAN. They cannot know that Orion is your secret project, or that Globex is your biggest client. You teach ONYRI Sanitize these terms with custom rules, grouped in profiles. One-off words go under Also mask.
It all runs in your browser, and your document is never uploaded. The Free plan includes 3 custom rules. Pro and Team have no limit on rules and profiles.
What can't built-in detectors know about your company?
A detector looks for a pattern. An IBAN has a country code and check digits. A project code name has no such shape: to the engine, Orion is just a word. There is no detector for company names either, because any word can be one.
- Client and supplier names
- Project and product code names
- Internal references, such as a framework agreement number
- Nicknames or initials that the name detector misses
How does a custom rule work?
You build a rule in Detection settings, under Rules & Profiles. Give it a name and answer four questions. You never write a regular expression: the form builds the search pattern for you. Then tick the rule in a profile, as shown below.
| Field | What it does | Example |
|---|---|---|
| Category | Text, Number, Date or Time. The Advanced rule tab adds True / False, Binary and ranges | Text |
| Type | Strict: only the exact value you type, capitals included. All: any value of the category, such as any date | Strict |
| Value | What to look for | Orion |
| Token prefix | Up to 20 capitals, digits or underscores, starting with a letter. The Token mode label keeps only the first 5 characters before any underscore | PROJ, shown as [PROJ1] |
Why no regular expressions? MDN describes them as patterns that match character combinations in text. OWASP warns that badly built patterns can become extremely slow on some inputs and make a program hang. The trade-off: a rule finds one value, or one kind of value, not a free format such as CTR plus four digits.
What do useful rules look like?
A client list
Create one Text rule per client, with the type Strict and the value Globex. Use a short, neutral prefix such as CLIA: in Token mode (Pro), Globex becomes [CLIA1]. Never use the client's name as the prefix: the label would show it. Avoid CLIENT_A and CLIENT_B: both labels would read [CLIEN1]. Strict respects capitals, so if a letterhead says GLOBEX, add it under Also mask. On the Free plan, 3 rules cover three names.
A contract or case reference
For a reference that recurs in many files, such as framework agreement FA-2026-117, create a Text rule with the type Strict, that exact value and the prefix REF. For a number that changes in every file, use Also mask instead.
A project code name
Create a Text rule with the type Strict, the value Orion and the prefix PROJ. Beware of common words: a project called Atlas also hides Atlas in a sentence about the Atlas Mountains. A rule also matches inside longer words, so Orion hides the start of Orionis. Check the preview.
How do profiles organize rules by team or matter?
A profile saves a name, a detection country, the built-in detectors that are on and the custom rules that apply. You pick it on the Documents screen, under Detection profile. Switching profiles re-checks the open document. A rule works only if it is on and ticked in the active profile.
- Sales, Globex deal: the client rules and the Orion rule, country GB.
- HR: personal and financial detectors, site names as rules, country US.
- Litigation: the names of the parties and the case reference, country DE.
The default profile turns on most built-in detectors, but none of the rules you create. You cannot edit or delete it. To use your rules, duplicate it or create a new profile, tick your rules and select that profile.
When should you use Also mask instead of a rule?
Also mask sits next to the preview. Type a word, a name or a value of two characters or more. Every occurrence in the current document is masked, whatever the case. The list is not saved: the next file starts empty.
| Situation | Tool | Why |
|---|---|---|
| A client named in most documents | Custom rule | Set once, reused every time |
| The other party in one contract | Also mask | No need to keep it |
| A word the detectors missed | Also mask | Quick fix before download |
| A person's name, such as Jane Example | Also mask | Not saved in your account |
Why mask business terms before a document leaves?
Most of what custom rules hide is business information, not personal data. Under the EU Trade Secrets Directive 2016/943, information is a trade secret only if, among other conditions, the person lawfully in control of it took reasonable steps to keep it secret. In the US, the federal definition in 18 U.S.C. § 1839, used by the Defend Trade Secrets Act, also requires reasonable measures. Masking client names before a file goes out can be one such step, not the only one.
When a rule hides personal data, the GDPR applies. Article 25 asks controllers for measures designed to apply principles such as data minimisation. By default, only the personal data needed for each specific purpose should be processed. A profile that masks every file of a kind the same way fits that logic. It does not make you compliant by itself.
What are the limits of custom rules?
- A Text rule holds one value.
- Rules match text, not meaning: Atlas the project looks like the Atlas Mountains.
- On scans, rules only see what the on-device OCR reads, in English, French or German. Handwriting is not read.
- Detection is not exhaustive: review the preview, item by item, before you download.
- No restore feature: keep your original file.
Masking reduces exposure. It does not, by itself, make a document anonymous or GDPR-compliant.
Which plan do you need?
| Plan | Rules and more | Price, excl. VAT |
|---|---|---|
| Free | 3 custom rules, 3 documents per day, 10 pages per document, Black marker | No subscription |
| Pro | Unlimited rules, profiles, documents and pages, Token mode, technical-secret detectors | €9.90 per month or €99 per year |
| Team | Pro for each seat, 3 seats minimum, priority email support. Shared workspace, roles and audit logs: coming soon | €24.90 per user per month or €249 per user per year |
| Enterprise | SSO and SCIM on request (roadmap) | On quote |
Pro starts with a 7-day trial. A card is needed, and nothing is charged today.
Frequently asked questions
- Do I need to know regular expressions?
- No. You pick a category, a type, a value and a prefix, and the builder writes the pattern. The flip side: no free-form patterns.
- How many custom rules does the Free plan include?
- Three. Pro and Team have unlimited rules and profiles. Pro costs €9.90 per month or €99 per year, excl. VAT.
- Are my rules sent along with my documents?
- No document is ever uploaded: detection and masking run in your browser. Your rules and profiles are saved in your account. Also mask terms are not saved.
- Can my whole team share the same rules?
- Not yet through a shared workspace, which is coming soon on the Team plan. Today, export your rules and profiles to a file for each colleague to import.
Sources & references
- Regulation (EU) 2016/679 (GDPR), Articles 5 and 25 — EUR-Lex, Publications Office of the European Union
- Directive (EU) 2016/943 on the protection of trade secrets, Article 2 — EUR-Lex, Publications Office of the European Union
- 18 U.S. Code § 1839, definitions (Defend Trade Secrets Act) — Legal Information Institute, Cornell Law School
- Regular expression Denial of Service (ReDoS) — OWASP Foundation
- Regular expressions, JavaScript guide — MDN Web Docs
Mask a document without uploading it
ONYRI Sanitize finds names, identifiers, bank details and secrets in a PDF, a Word file or a scan, and masks them in your browser. You check the preview, then download a flattened copy.