Skip to content
CamouDatAI
HUEN
Live demo →

Features

What the platform can do

Eight functional areas, 63 capabilities presented. Capabilities marked NEW arrived with release v6.

01

Chat & user experience

Secure AI conversation for everyday work, in Hungarian and English, on a clean interface.

Code execution in an isolated sandboxNEW

The Python program bundled with a skill runs in a dedicated, network-free, isolated sandbox, cut off from every other client and from the server's own secrets. It can only see its own working directory, freshly created for each run, and turning the switch on by itself starts nothing until the sandbox has been provisioned on the server. Both the output length and the program's resource usage are capped, and the installed package goes through the same virus and data-protection checks as any uploaded file. The feature can be switched on separately for each tenant.

MS Office file editing and PDF creationNEW

Word, Excel and PowerPoint files uploaded into the chat can be edited within the application: the user specifies the requested change, for example a word replacement, a new paragraph or an overwritten cell, and the system returns the modified file for download. The uploaded file goes through the usual virus, type and data-protection checks, and the text written back passes through a further, outbound data-protection check. The feature is off by default, since this is the point where an edited file leaves the system, so switching it on is a deliberate, per-tenant decision. This way a draft contract or a budget spreadsheet can be corrected in a single pass, without leaving the chat. A chat response can also be downloaded as a Word or PDF document on request, going through the same outbound data-protection check as any other downloadable file.

Managing capabilities (skills)NEW

Administrators or team leads can install company-specific knowledge and working-method packages, known as skills, that give the assistant background material on a given topic, for example the structure of a document template or the steps of an internal procedure. On installation, a skill goes through the same virus, secret and data-protection checks as an uploaded file, and only becomes available after approval. Users can also upload their own skill for their own conversations. A skill's text runs as part of the user's own message through the full data-protection pipeline, so it cannot bypass any check.

Secure AI conversation

Real-time, continuously streaming answers on a clean interface, available in Hungarian and English, with light and dark themes. Every request passes through the protection pipeline before anything leaves the organisation. Masking and content filtering run in the background, without slowing down the pace of the conversation. Users get the same convenience as a public AI tool, while company data stays inside.

Projects and workspaces

Conversations and their associated knowledge can be organised into projects, keeping different topics and clients separate. An existing conversation can also be moved into the right project from the sidebar with a simple drag and drop. Documents attached to a project are only available within that workspace. This means material from one client cannot leak into another client's conversation.

Automatic titles and tagging

The system automatically gives conversations a fitting title, so there is no need to name them by hand. The title is generated from the content, so the list still makes sense weeks later. Conversations can also be organised with tags, and tags can be used for filtering. When searching, title and tag narrow down the results together, which matters once there are many conversations.

Message editing and regeneration

A sent question can be edited afterwards and resubmitted, and the answer can be regenerated. A response that is still being generated can be stopped partway through if it is clearly heading in the wrong direction. Earlier versions are not lost, so the conversation can be reshaped freely. This means a longer task can be carried through in a single conversation, without starting a new thread.

Rich content and canvas

Answers appear with formatted text, code highlighting and mathematical formulas. In the canvas panel, longer texts can be edited in place, without needing to copy them into a separate editor. The finished material can be downloaded directly from there. The panel stays alongside the conversation, so the text and the question behind it are visible at the same time.

Conversation export to a branded document

A complete conversation can be downloaded as a tidy, company-branded PDF or Word document. The export preserves formatting, code snippets and source references. It is ideal for archiving, internal sharing or documenting a decision. The file can then be stored through the usual corporate channel, for example SharePoint.

Fast, responsive experience

Even long conversations scroll smoothly, and the first answer arrives quickly. The system caches repeated content, which reduces both waiting time and cost. The interface does not reload itself at every step, so work stays continuous. This is felt most clearly in daily, frequently repeated use.

Command palette

A single keyboard shortcut brings up a quick search for instant navigation. Conversations, menu items and common actions are all accessible from one place. Work can be carried out entirely with the keyboard, without needing the mouse. This benefits both heavy typists and accessible use alike.

Built-in bilingual help

There is no need to leave the interface: a side help panel explains what the given page does. It describes what can be done there and what is worth paying attention to. It is available across every area of the chat and the admin console, in Hungarian and English. This means onboarding does not depend on separate training material, since help is available right where the work happens.

Guidance on every control

Every switch and button has a short, plain-language explanation available. It can be brought up by touch or keyboard alike, so it also works on a phone. The text follows the language of the interface, in both Hungarian and English. This means no one has to guess what a setting does before changing it.

Installable web app

The interface also works as an installable web app (PWA), with its own icon on the device. It launches directly from the browser, without a separate installer package or store distribution. Localisation is complete, available in both Hungarian and English. The same protection rules apply here as in the browser interface.

02

Knowledge & documents

An assistant that works from your own documents and cites its sources.

Web accessNEW

When the organisation's own knowledge is not enough to answer a question, for example the current text of a standard or a market figure, the assistant can also run a public web search. The search is run by AWS's own search service (Amazon Bedrock AgentCore Web Search), built on an Amazon-operated web index and the search infrastructure that also powers Alexa+ search. The search phrase goes out separately from the conversation and any attached documents, depersonalised, through an EU (Ireland) AWS Region, and according to AWS it does not leave the AWS infrastructure or reach any third-party search engine. The feature is off by default, and opening it requires the tenant switch, the user's own permission and a per-request toggle all at once, and the user can only use it after reading and acknowledging the risk. This is the one point in the system where user-written text intentionally reaches an outside party, so every activation and search leaves a logged, traceable record.

Answers from your own documents

The assistant finds its answers in your uploaded company documents, not on the internet. It marks which source it worked from, so the answer can be traced and verified. The search follows the user's own permissions, so it only surfaces what they would have access to anyway. This makes the answer accountable, not merely convincing.

Source preview in the answer

Hovering over a citation immediately shows a short excerpt of the source. There is no need to open the full document to verify a claim. The preview appears alongside the answer, so it does not interrupt reading. This speeds up verification most with long contracts and policies.

Broad document support

PDF, Word, Excel and PowerPoint files can be uploaded to the knowledge base. The system extracts the text and screens it against the protection rules already during processing. Anything that does not comply is not added to the searchable content. This means protection does not start at the question, but at the upload itself.

Scanned document recognition

The text of scanned, image-based documents is recognised through OCR. This makes old, paper-based material searchable and usable as well. The recognised text goes through the same protection check as any other document. This means a scanned contract cannot bypass masking either.

Image analysis, only on verified clean images

Image files can be uploaded too: the system recognises the text within them and delivers it to the model in masked form. The image itself is only sent onward if the system can positively confirm it contains no recognisable sensitive data. In every other case, only the masked text excerpt goes forward, never the image. The system can also cover flagged areas with black rectangles, and it re-checks that cover on the final outgoing image.

"What goes out?": preview the outgoing image

With a single click, the user can see exactly the image the system would send to the model. The image is shown covered and stripped of metadata, that is, in the form it would actually leave in. This is a human checkpoint: automatic recognition does not always catch handwriting, faint text or faces. The user can see them, however, and can stop the send.

Deep research

For complex questions, the system researches the internal knowledge base more thoroughly, over several rounds. It summarises the partial results and gives an answer backed by sources. The longer run can be followed on the interface, so it is visible how far it has got. It is worth switching on when a question requires comparing several documents.

Reusable knowledge collections

Documents can be organised into thematic collections, with whole folders uploaded at once if needed. A single collection can be assigned to several conversations and projects. This way the assistant always works from the right knowledge base, not the entire archive. Maintenance also happens in one place, rather than separately for each conversation.

Spreadsheet understanding

The system builds a profile of uploaded spreadsheets: columns, data types and magnitudes. Based on this, it can ask targeted questions about the relevant details. It does not send the whole table, only the part needed to answer the question. This means even a large dataset can be used without the whole of it leaving the organisation.

03

Enterprise data integrations

Connecting to existing enterprise systems, with each user's own permissions.

Microsoft 365, SharePoint, OneDrive

The assistant accesses SharePoint and OneDrive content with the user's own permissions. It only ever sees what that particular colleague is already entitled to see. There is no separate service account with access to everything. A permission change takes effect from the very next request, with no manual syncing needed.

Calendar integration

Calendar reading happens directly from the conversation, through the Microsoft 365 account. Event handling is approval-gated, so the system never writes to the calendar on its own. Suggested time slots are generated from actual free and busy availability. This way scheduling can be handled in one place, without leaving the familiar calendar.

On-premise file server agent

An installable agent searches and reads on the company's own file server, on the user's behalf. It respects live NTFS permissions, so it never grants access beyond what the colleague can already see. The index is stored encrypted, and the agent works with no inbound port opened. This way the file server's content becomes usable without opening the network outward.

Semantic search on the file server too (RAG)NEW

The on-premise file server agent can search by content, not just by keyword: the user's full question, not only its keywords, reaches the tenant's own file server agent, which can send back a short excerpt alongside the most relevant results. Results still follow the signed-in user's live NTFS permissions, so only what that colleague could already access on the file server is returned. The returned excerpt passes through the usual secret filter and data loss prevention before the assistant receives it, and every outgoing question is recorded in an encrypted, logged entry. The feature only works alongside the on-premise agent channel, and can be switched on separately per tenant.

SAP integration

Read-only SAP queries can be run directly from the conversation. Modifying operations require separate approval, so they never run on their own. Data loss prevention checks the result before anything reaches the model. This way business data can be queried without it leaking out unchecked.

Extensible connector catalogue

New enterprise systems can be connected to the platform through a uniform descriptor. Connectors can be enabled per tenant, so nothing switches on for everyone at once. Permission handling and logging apply to new sources in exactly the same way. This way the platform grows with the organisation's needs, without custom development.

04

Channels

CamouDatAI is available from the familiar Microsoft tools, with the same protection.

Microsoft Teams bot

The assistant can be used directly from Teams, with no separate interface to open. Protection and DLP rules apply here in full. Signing out of Teams genuinely ends the CamouDatAI session too. Session expiry is stored persistently on the server, so it is not the client that decides how long it lives.

Proactive Teams notifications

The system can also send notifications in Teams on its own, not only respond to questions. For example, about a finished report or a completed workflow. The notification content goes through the same protection checks as the conversation. This way a colleague does not need to watch the interface to be informed in time.

Outlook add-in

AI assistance for e-mail directly in Outlook. Summarising, reply suggestions and extraction, without leaving the message. Sign-in uses the corporate account, with no separate password. The message content goes through masking just like any other request.

Office add-in

The assistant is built into the Word, Excel and PowerPoint interface. This makes it available while working on the document, without copying or switching windows. Selected content can be sent as a question, and the answer can be written back into the document. Protection checks run here too, before anything is sent.

Automatic user provisioning

Users and groups are created in sync from the corporate directory (SCIM). Departing colleagues' access is removed automatically through the same channel. There is no manual upkeep, so no orphaned accounts remain in the system. Group membership carries over to roles too, so permissions move together with the organisation.

05

Security & data protection

The heart of the product: protecting sensitive data at every point.

Claude on Amazon Bedrock, inside the EU

We use the Claude models through the Amazon Web Services Bedrock service, called from an EU Region (Frankfurt). The EU inference profile processes requests only in AWS Regions within the European Union, and they cannot be routed outside it. Bedrock works with zero data retention (ZDR): according to AWS, prompts and responses are not stored by default, are not used for model training, and are not accessible to AWS operators. On top of that, only masked content that has passed data-loss prevention ever reaches the model.

Automatic sensitive-data masking

The system detects personal and sensitive data and pseudonymises it before the request reaches the model. In the answer, the real values are automatically restored for the user. The AI provider therefore never sees the actual data, only the placeholder. The system also continuously and automatically checks that no internal path can bypass the masking layer.

Data loss prevention (DLP)

Customisable rules decide what may leave: block, warn or mask. The system checks responses even as they are generated, and stops them if it detects a leak. Rules can be set per tenant, so they can be tailored to the organisation's own risk profile. Every decision is logged, so afterwards it remains visible what was blocked and why.

Per-user encryption

Every user's conversations are stored encrypted with their own unique key. This makes it technically impossible for anyone else to see into another colleague's conversation. This applies to the administrator too, not only to other users. Protection therefore does not depend on policy, but on how the data is stored.

Encrypted storage and key management

Every sensitive field is stored encrypted, and the master keys live in a hardware key store (HSM or Key Vault). Key rotation is regular and automatic, not a manual task. For client deployments, passwords and keys come from Azure Key Vault by default, not from the server's disk. This way a compromised server alone does not give up the secrets.

Sign-in protection: SSO, MFA, roles

Corporate single sign-on (Entra ID) with multi-factor authentication. Permissions can be set in a fine-grained, role-based system. The system strictly validates the identifiers received at sign-in, so nobody can get into another account with a similar but non-genuine identifier. There is no separate password on the platform, so there is no additional secret that can leak.

Confirmation for sensitive actions

Irreversible actions require a fresh, repeated corporate sign-in to start. This includes data deletion, the kill switch and compliance exports. Confirmation is required even when the user is already signed in. Sensitive actions sit on a single central list, and the system provably requires confirmation for every one of them, not just a few manually listed cases.

Secret scanning in uploads

Passwords, keys and tokens accidentally left in uploaded files are automatically filtered out. A match is quarantined, and an alert is raised. This way an exported configuration file cannot carry live credentials out. The scan runs at the start of processing, so the secret never even enters the searchable content.

Anomaly detection

The system watches for unusual usage patterns and flags anything suspicious. This can include a sudden spike in downloads or a bulk query starting at an unusual time. The goal is early incident detection, not after-the-fact explanation. The flag is also written to the log, so the investigation can be traced back.

Self-tuning protection proposals

The system generates proposals from the logs to refine protection rules. This can include adjusting thresholds or reducing false alarms. Rollout is always subject to human approval; nothing takes effect automatically. Accepting a proposal that weakens protection requires a separate, explicit confirmation, together with the displayed warning text.

06

Compliance & governance

Transparency, accountability and cost control, in the language of management and auditors.

Tamper-evident audit log

Every significant event enters an immutable, hash-chained log, sealed daily. This makes it possible to prove afterwards that the log has not been tampered with. A break in the chain is visible immediately, with no separate investigation required. On request, an independent witness can also be included alongside the daily seal.

Compliance pack in one click

A NIS2- and ISO-oriented compliance report and evidence pack export in a single operation. The pack includes the evidence itself, not just the claims. So preparing for an audit is not weeks of data gathering. The export itself counts as a sensitive operation, so it requires a fresh sign-in.

Retention rules and proof of deletion

Data retention periods are configurable, and deletion is verified with proof. This directly serves GDPR expectations. Expired entries in the audit logs are genuinely removed by a scheduled process. This is not a documented intention but an operation that actually runs on every deployment.

Policy acceptance is provable

Acceptance of the usage policy leaves a server-side trail that cannot be forged after the fact. It records who accepted which version, and when. Per-user history can be looked up in the admin interface. So a disputed case does not have to rely on memory.

Scheduled reports by e-mail

Scheduled management and operational reports are generated at set times. The report lands in the responsible person's mailbox, prepared and ready for review. Sending remains a human step: the system does not send e-mail out on its own. So the content can be reviewed once more before it reaches anyone.

Cost forecasting and quotas

The system forecasts expected AI cost based on measured consumption. Budgets and alerts can be set per group and per user. Users can also see their own consumption, not only the administrator. So there are no surprises on the bill at the end of the month.

Admin console and kill switch

A full management interface covers settings, the dictionary, rules and users. Every change is logged, so it remains visible afterwards who changed what. If needed, outbound AI traffic can be stopped with a single switch. The kill switch requires a fresh sign-in so it cannot be triggered by accident.

Live inspector and demo mode

Admins can follow in real time how a request moves through the protection pipeline. It shows what the system recognised, what it masked and what it let through. This is also excellent for demonstrations and internal training. The inspector shows real behaviour, not a pre-recorded illustration.

07

Automation & workflows

Automating repetitive work, always inside the protection boundary.

Workflow templates

Multi-step, recurring tasks are organised into declarative chains. With management approval, a chain can continue running automatically, so not every step needs to be started by hand. Templates are reusable, so a proven process can be handed on to colleagues. Every step goes through the same protection checks as a manually started request.

Flow editor with decision branches

Automation is built by clicking: inserting, moving and deleting steps, with no coding required. The flow can also decide: if a step's result contains something, or does not, a different branch runs from that point on. The two branches are shown in separate lanes, with the point where they merge marked. The editor only offers what the system can actually execute, and flags errors before saving.

Scheduled runs, requested and approved

Flows can also run on a schedule: daily, weekly, or on a given day of the month, down to the hour. Scheduling is not a silent background setting: staff submit a request under their own case number, and an administrator approves or rejects it. A scheduled run on its own does not authorise outward-facing actions: only someone whose request has been explicitly approved for it can send an email or a document. If a scheduled run is missed, the interface warns, so silent gaps are ruled out.

Output actions

The finished result can be saved to SharePoint, posted to Teams, or written into an Outlook draft with a single button. Outgoing content goes through the same protection checks here too; it does not bypass the rules. A draft stays a draft: actually sending it is a human step. So automation prepares, but does not decide on behalf of the organisation.

Meeting notes

The system turns transcripts of Teams meetings into structured notes. Action items are collected into a separate list, with an owner and a deadline where these were mentioned. The notes can be exported or shared in the usual way. Processing the transcript goes through the same masking as any other content.

08

Platform & reliability

Enterprise-grade foundations working in the background, for trust and continuity.

Custom branding

The interface can be tailored to the client's branding: its own name, logo and colours. This lets CamouDatAI appear to staff as the partner's own solution. The branding also carries through to exported documents and to reports that are sent out. The underlying operation and protection rules stay unchanged.

Flexible model choice

The system works with several AI providers, for example Anthropic models or a European Bedrock route. The choice can be matched to data residency requirements, per tenant. Switching models does not affect masking or logging, which stay on the platform side. So a change of provider does not mean a redesign.

Reliable operations

Automatic backup and restore, together with continuous monitoring, look after continuity. Outbound network traffic is strictly restricted, and only approved destinations are reachable. The server configuration is hardened, and unnecessary services are switched off. Operation is measured, so faults do not surface only through user complaints.

Capacity guard for heavy processing

Image recognition is resource-intensive, so the system limits how much heavy work can run at once. This means a single large upload does not slow down other users. Waiting jobs are queued rather than lost. The cap never lets data out unchecked: if there is no capacity, the request waits, rather than proceeding without review.

Infrastructure as code

The whole environment can be deployed from declarative, versioned code. A new instance can thus be built predictably, with the same configuration. Changes can be reviewed and rolled back like any other code. This is what makes deployment repeatable and auditable.