Sunda Cloak adds hidden content to a Word, RTF or OpenDocument file that people never see but machines read: look-alike decoy facts placed beside the real ones, whole decoy paragraphs that some AI file-readers prefer over the real ones, and hidden notes that steer a summarizer toward “nothing to extract”. Nothing you wrote is changed or removed.
When that file is uploaded to an AI tool, the tool gets a noisy, unreliable read. A hidden reference link can tell you when a tool followed it. That makes it a deterrent against casual, one-click AI ingestion — not encryption, not DRM, not a guarantee, and never a substitute for a contract.
What it does, at a high level
Word, RTF and OpenDocument files have a hidden-text channel — formatting that tells the program “don't display this”. Humans never see it; most software that extracts text from a file does. Sunda Cloak uses that channel in four ways:
- Decoy facts beside the real ones. Every web address, email, number, date-like figure and proper name gets about a dozen plausible look-alikes placed next to it as hidden text (“$4.2 million” travels with “$3.7 million”, “$5.1 million” and so on). The real value is untouched, byte for byte. An extractor that reads hidden text now has to guess which one is real.
- Decoy paragraphs. Word documents can hold a “preferred” and a “fallback” version of the same content. Word shows the preferred version — your real text. Some widely used file-readers take the fallback, which is a plausible decoy. Those readers see mostly decoys and little of what you wrote.
- Hidden steering notes. Short hidden paragraphs that tell a summarizer the document is routine and that names, numbers and dates should not be extracted. Modern AI tools increasingly ignore notes like these, so we count this as a nudge, not a wall.
- Personal-detail decoys. On computers that can run it, an on-device model spots names, emails, phone numbers, addresses and account-like strings and gives them the same decoy treatment. On by default; nothing is masked or replaced. It helps, and it is not a complete defense.
Two optional extras: the tripwire, a per-copy hidden reference link that can tell you when an AI tool followed it, and — on computers with Chrome's built-in on-device model — more convincing, topic-aware decoys. Everything runs on your own computer; the document itself is never uploaded.
Hidden is not secret. Anyone who turns on “show hidden text” (or the formatting-marks button) in Word will see the decoys. That is one more reason to tell your client the file is protected rather than hope they never notice.
What defeats it
This is the part most tools in this category leave out. Sunda Cloak protects one path: the file itself, uploaded to a tool that extracts text from it. Everything that sidesteps that path sidesteps the protection.
Where it helps
- The report is attached or dragged into an AI chat as a file.
- “Summarize this” / “extract the methodology” one-click flows that read the file.
- Tools and pipelines whose file-readers ingest hidden text (common in chat-upload pipelines).
- Bulk ingestion into a knowledge base built on the same kind of reader.
- Tools that automatically follow links inside a file — that's what trips the tripwire.
What gets past it
- Copy-paste. Word leaves hidden text out of the clipboard; select-all → paste gives an AI your clean original.
- Screenshots, photos and OCR, and AI models that read the page as an image.
- PDF conversion. Word's PDF export drops hidden text, so the PDF is clean.
- Extractors that strip hidden text (several common Python libraries in their default mode) — they recover your original.
- AI built into the editor, such as Copilot reading the open document inside Word.
- A recipient who turns on “show hidden text” and deletes it, retypes the passage, or is simply determined and has time.
We don't pretend otherwise anywhere on this site. If a claim you read here or elsewhere ever seems stronger than this page, this page wins.
How strong is it, honestly?
It depends on the tool, so there is no single honest number. We test against two kinds of file-reader:
- Readers that ingest hidden text (the kind behind many chat-upload flows): in our own tests, the AI's recovery of the real facts dropped to near zero — it was answering from decoys.
- Readers that strip hidden text first: the AI recovers most of the original. The remaining effect is that facts arrive fragmented and less trustworthy, not absent.
Providers change their file pipelines without notice. We expect any given technique to last months, not years, and we update the extension as they move. Treat the strength you see today as a moving target, and treat the deterrent as exactly that.
What it's good for
The behaviour worth deterring is rarely a determined adversary. It is a client, a junior on their team, or a prospect dragging your report into a chat window and asking for “the same thing for our other region” or “turn this into a template we can reuse”. That is casual, one-click ingestion, and it is exactly what cloaking makes unreliable: the output is muddled, the facts don't line up, the exercise stops being free — and, if the tripwire is on, you may hear about it.
Think of it like a lock on a bike. It won't stop someone with bolt cutters; it makes the casual grab not worth the trouble, and it signals that you consider the thing yours. For work you sell by the document — research, strategy, methodology, copy, translations, proposals — that is usually the whole job.
When to send an uncloaked copy instead
- The client needs to translate, search, or index the document, or run it through accessibility tooling — hidden decoys make all of those worse.
- The document is something they are entitled to machine-read under your contract (data appendices, raw tables).
- You need real secrecy. Then the answer is a confidentiality agreement, access controls, or not sending it — not a cloaked file.
Telling your client has practical language for all of this, including when to offer both versions.
A deterrent, not a guarantee
- Nothing is encrypted, redacted or removed. A person with the file has your text.
- Copy-paste, screenshots, OCR, PDF export and hidden-text-stripping extractors bypass it.
- Protection strength varies by AI tool and changes as providers update their pipelines.
- The tripwire fires only when a tool actually follows the hidden link; silence proves nothing.
- In some documents the per-copy mark can shift a line or page break — proofread the cloaked copy like any deliverable.
- It is never a substitute for a contract, an NDA, or the decision not to send something.
Questions people ask before buying
No. Every word, number, name and date stays exactly as you wrote it. The protection only adds hidden content that people never see but machines read — decoy values next to the real ones, decoy paragraphs, and hidden steering notes. Your client reads the document you wrote.
Yes, and that bypasses the protection. Word leaves hidden text out of the clipboard, so a select-all, copy, paste into a chat window gives the AI your clean original text. Sunda Cloak protects the file-upload path — the report attached to a chat or dropped into an AI tool — not copy-paste, screenshots, OCR or PDF conversion.
No. It depends on how the tool reads files. Readers that ingest hidden text get mostly decoys; in our own tests their fact recovery dropped to near zero. Readers that strip hidden text recover the original, and the remaining effect is fragmented, less trustworthy facts. Providers change their pipelines, so a given technique lasts months, not years.
No. It is a deterrent that raises the cost of casual, one-click AI ingestion. A determined person with time — or a simple copy-paste — gets your text. It is never a substitute for a contract, a confidentiality agreement, or choosing not to send something. Here's a starting point for contract language.
No. It records the time an AI tool followed the hidden reference link inside a specific cloaked copy, plus basic network details. It does not identify a person or which AI product, it fires only if a tool actually follows the link, and many tools never follow links inside uploaded files — so a quiet tripwire is not proof nobody looked. More on what detection can and can't do.