Open beta — now enrolling

ShinrAI Encryption Models

Semantic encryption for the AI age: open-weight models that shield who you are before any AI sees your text, with keys that stay yours. Trained at the Jülich Supercomputing Centre, released for everyone.
You use the AI. The AI does not use you.

Semantic encryption, multi-dimensional
Apache 2.0 open weights
DE · EN · JA available today
Runs on your hardware
Trained on JURECA & JUPITER
The Models

Semantic Encryption, Not Redaction

Compact encoder models (ModernBERT family) — the detection layer of ShinrAI semantic encryption. Privacy protection that works in multiple dimensions, across languages and document styles.

Classical PII tools do one of two things: they redact (the default — leaving broken [REDACTED] text no AI can reason about), or they make hard-cut replacements that ignore what the text means. ShinrAI is semantic encryption: replacements are computed in multiple dimensions at once — matched to the context, the culture and the language of the original, and statistically weighted so a substitute never accidentally triggers biases or red flags. The AI receives text that reads natural and reasons correctly; the identities inside were never exposed. And the models are small, fast, and yours: CPU, workstation GPU, or embedded in your own stack — no data ever leaves your infrastructure.

The models are one half; the ShinrAI software completes the encryption. The matching key pair — depending on your deployment — never leaves your device, your backend, or your hosted instance: only the key holder can ever map the protected text back to reality. Optional onion routing in the backend separates who is asking from what is asked, and it works with any model access path — OpenRouter and many more. Ideally you use several: the more independent paths to the same model, the stronger the protection.

Beyond chat, the models privacy-protect data at scale: de-identifying electronic patient files (ePA) for pharmaceutical research, clinical archives, high-security environments and banking datasets — while keeping the data statistically faithful and analytically useful.

Every model ships as open weights under Apache 2.0. A substantial share of the training data will be published too — our data pipeline tracks license provenance for every single record, so we can release the license-clean subsets (CC0, CC-BY, public-domain and our own generated text). For several models that means fully open source: weights and data. Final license review is in progress; open weights are a commitment, not an aspiration.

The training corpus is synthetic — generated, checked and filtered by openly released AI models, anchored in public registries and open data. No customer data, no scraped personal records, no proprietary APIs anywhere in the pipeline.

And if you need this protection now: a compact edition of the German, English and Japanese models already runs in production inside our commercial products — ChtSafe for individuals, and the Innovius Secure AI Suite for organizations (on-premise first, SaaS-hosted on request). Talk to us for the enterprise version.

Available today

German English Japanese

A compact edition of these models already protects production traffic in our commercial products — ChtSafe for individuals, the Secure AI Suite for organizations (on-premise first, SaaS on request).

In training — the open-weight suite

Italian French Spanish Polish Portuguese (PT/BR) Russian Ukrainian Turkish Korean Arabic Dutch Swedish Chinese (Simplified) Your language?

Languages land as they pass our quality gates — and the beta form below directly shapes the order. Tell us what you need.

The Beta

What You Get — and What We Ask

We are slotting a limited beta cohort by language, hardware and domain, so every configuration gets real coverage.

Early checkpoints

Beta participants get model checkpoints and quantized builds before the public release, matched to the hardware you tell us about.

Real influence

Your language wishes, domains and votes feed directly into training priorities. This is genuinely how we decide what to build next.

A direct line

Found a miss, a false positive, an awkward replacement? Beta feedback goes straight to the team that trains the next generation.

Open at the end

Everything lands as open weights on Hugging Face at release — beta participants simply get there earlier and shape what "there" looks like.

Join

Apply for the Beta — or Just Stay in the Loop

Two minutes of your time helps us slot you into the best-fitting cohort. Or leave just an email and we will ping you once at release.

We will send you a single email when the ShinrAI encryption models are publicly released — no newsletter, no follow-ups. Want to help shape the models instead? Switch to the beta application above. You can also follow Innovius on Hugging Face or @InnoviusAI on X for updates.

About you

Languages

Which languages does your AI usage mostly happen in? Pick everything that applies — this decides which language models we hand you first.

Your hardware

Where would you run the models? This drives which builds and quantizations we prepare for you.

Quantization

Interested in specific quantized builds? Pick any — or let us recommend.

Where would you use them?

Areas of use — pick everything that applies.

Vote: where should we specialize first?

How to read this: the Common models already cover everyday text — and with it most other areas — to a solid degree. Specialization matters where the language itself changes: government and aerospace documents carry their own vocabulary and identifier styles, and for coding a specialist is essential — personal data hides in source code, logs and configs in ways prose models don't see. Our roadmap so far: Common ships first, Space Exploration & Aerospace Engineering is a promise we will keep regardless of votes (we love it too much not to), and NSFW comes last. Your vote reorders the middle.

Pick up to 3 areas, in the order you care about them.

Coding it is! Which languages should the coding specialist understand first?

Anything else?

Application received — thank you!

We will review your application and get back to you as we slot the next beta cohort. Meanwhile: follow Innovius on Hugging Face and @InnoviusAI for updates — or talk to us if you need ShinrAI protection in production today.

Credits

Built With — and Thanks To

This programme exists because remarkable institutions and open projects make serious research possible outside big tech.

EECC Research Labs

The ShinrAI encryption models are developed by Innovius together with the research lab of the European EPC Competence Center (EECC) — long-time partners in applied AI and privacy research.

eecc.info · EECC on Hugging Face

Forschungszentrum Jülich — JSC

Training runs on the JURECA supercomputer, with the programme scaling onto JUPITER — Europe's first exascale system — at the Jülich Supercomputing Centre, supported through the WestAI initiative. Our deepest thanks to FZ Jülich and the JSC team: this work is only possible because Europe's research infrastructure is open to projects like ours.

fz-juelich.de/jsc · westai.de

Open models we build on

The base encoder is mmBERT (Johns Hopkins CLSP, MIT) from the ModernBERT family. Training data is generated, cross-checked and evaluated by openly released models from the Qwen (Alibaba), Gemma (Google DeepMind), Mistral and NVIDIA Nemotron families — thank you for keeping frontier-quality open models available; this project runs no proprietary APIs at all.

mmBERT · MIT ModernBERT Qwen Gemma Mistral Nemotron

Open data

Ground truth is anchored in open data: GeoNames (CC-BY), Wikidata (CC0), the US SSA & Census name statistics (public domain), and national open-data sources including INSEE (France), INE (Spain), the Polish PESEL registry statistics, and Italian & German municipal open data. Open data is what makes honest, bias-aware ground truth possible.

GeoNames · CC-BY Wikidata · CC0 SSA / Census · PD INSEE · INE · PESEL

Open weights are a conviction, not a marketing angle. We fully support the Open Weights and American AI Leadership open letter published in July 2026 by an NVIDIA-led coalition of 50+ organizations: models whose weights anyone can download, inspect and run on their own infrastructure are defensive assets — for security, for competition, for trust. The ShinrAI encryption models are our contribution from Europe: open, inspectable privacy infrastructure you can run yourself.

Follow the programme: huggingface.co/innovius · @InnoviusAI · ShinrAI technology