Your register says one number. Your files say another.
We measure that distance with software we wrote ourselves, running on your own company's machine. The same scan counts the passwords sitting in plain text on those machines, the other number nobody has looked at. Nothing of yours leaves the computer, and you can check that before you send us anything at all.
The company declares 3 databases holding personal data.
Its computers turn up 61 files with national ID numbers.
Illustrative figures. That distance is what we measure, and until someone measures it nobody knows how big theirs is.
A questionnaire asks. We count.
Almost every company reviewing its compliance with Chile's Law 21.719 ends up in the same place: a record of processing activities assembled through meetings, where each department declares what data it believes it handles. That is what the law asks for. It is not what sits on the computers.
We went through the Chilean market before building anything. Free diagnostics are everywhere, and almost all of them resolve into a fifteen to thirty minute form that returns a risk level and a roadmap. It is well made. It helps organise the conversation. But it answers with what the company believes, because the company is the one filling in the form.
None of them opens a file.
Law 21.719 comes into full force on 1 December 2026, with fines up to 20,000 UTM. Enforcement runs on operational evidence, not on statements of intent.
CatastroIA
A single executable. No installer, no administrator rights. It detects nine kinds of personal data: Chilean RUT, Brazilian CPF, Mexican CURP, Spanish DNI and NIE, credit cards, emails, phone numbers and IP addresses.
It also counts six kinds of credential stored in plain text: passwords, Wi-Fi network keys, connection strings, private keys, API tokens and saved remote desktop credentials. To find them it reads Word documents, configuration files and remote connection files, on top of the spreadsheets and plain text it always read.
Those six are counted separately from personal data. A password is not a fact about a person, and folding it into the inventory inflates the figure the company then declares to the regulator.
Identity documents are validated against their check digit and cards against Luhn plus a real issuer prefix, so a number that merely looks like a RUT never enters the count. We would rather give you a lower figure you can trust than a higher one you cannot.
It reads about 8 MB per second, so 28 MB of documents are scanned in a little over three seconds. The figure is measured on those files and on a 15 MB spreadsheet full of Chilean national ID numbers. It counts column by column, identifying each column by its position and never by its header, because the header is already file content.
{
"version_esquema": "3",
"herramienta": "catastroia 0.12.0",
"carpeta_analizada": "C:\\Users\\...\\Documents",
"resumen": {
"archivos_examinados": 4218,
"archivos_con_hallazgos": 61,
"archivos_omitidos": 7,
"cobertura_pct": 94,
"totales_por_tipo": {
"RUT": 12480,
"Email": 3117,
"Phone": 902
},
"totales_credenciales": {
"Plaintext password": 47,
"Wi-Fi network key": 3
}
}
}
That is everything that leaves the machine. Counts, paths, sheet names and column positions. Passwords are counted, never stored: not one of the 47 is in the file.
That it never talks to the internet is something you check.
Unplug the computer from the internet and run it anyway. It works exactly the same. Nobody can fake that, and you need to know nothing technical to do it.
On our side, before the program goes out we check that it carries nothing inside capable of connecting. That is hygiene, not proof. The proof is the cable.
There is also a test that seeds twenty-seven fake values across the fifteen types, scans, and confirms none of them reached the output. Not whole, not in fragments.
What it cannot see
Names, addresses and company names loose in free text have no check digit, so they are not counted. A good share of a small company's personal data lives exactly there. We count structured data, and calling that "all your personal data" would be a lie that collapses in the first demonstration. We also do not read databases or biometric access control systems.
Passwords work much the same way. A short letters-only password, something like MineraNorte, never enters the count: below twenty characters we require a digit or a symbol, because at that length there is no way to tell a real password from an ordinary word. We would rather miss that one than invent ten.
Este archivo contiene solo cantidades, rutas, nombres de hoja y
posiciones de columna. No contiene ningún dato personal encontrado, ningún encabezado de
columna ni ningún fragmento del contenido de sus archivos. Puede abrirlo y verificarlo usted
mismo antes de enviarlo.
In English: this file holds only counts, paths, sheet names and column positions. It contains no personal data found, no column header and no fragment of your files' contents. You can open it and verify it yourself before sending it.
Open it in a text editor before you send it to us. If you find a single value of yours in there, we want to hear about it the same day.
Three steps, and the first one is free.
-
An hour of conversation
Five questions about what data you believe your company handles. They come before the scan. Half the finding is that distance.
-
A live scan
We run CatastroIA on your machine while we talk, sharing your screen. You see the result at the same moment we do, and if you decide not to continue, you keep the number anyway. Nothing gets installed.
-
The full diagnostic, from 15 UF
A report covering both laws, 21.719 on personal data and 21.663 on cybersecurity. Remote: you send the exports you want reviewed and we also examine your public surface. Nobody travels and nothing is installed on your internal network.
The report opens with a one-page executive summary, which is the only part the person signing will read: where the company stands, what it is risking, and the three things to do first, in order. On-site work is quoted separately, and the report always states what was left unassessed.
What to compare it against
Of the Chilean firms in this field we surveyed, two out of three publish no price at all and quote through a form. Among those that do, an annual internal audit for a company of up to fifty people is offered at 50 UF, an external data protection officer at 25 to 85 UF a month, and a penetration test from 25 UF. The cheapest diagnostic we found is $38.000 CLP for a video call with a checklist.
Ours starts at 15 UF and covers both laws. It is the only one on that list that opens a file.
Prices published by the providers themselves, verified in August 2026.
If your company is small, we start somewhere else.
Most of the companies that write to us are not looking for an audit. They write because they do not show up on Google, because orders go in a paper notebook, or because a large client has started asking for paperwork nobody asked for before. We do that work too, and the state funds a good part of it.
The data conversation still arrives, a little later, once we know what is actually sitting on the computers.
The rule reaches the supplier, not only the mining company.
Chile has on the order of 8,700 companies supplying the mining industry. APRIMIN, the large trade body, gathers 121 of them: the ones billing over four million dollars a year. Everything the cybersecurity market sells points at that end. The other eight thousand and change are left out.
Picture a twenty-person contractor in Calama. It keeps the list of its workers' ID numbers and uploads it to the mining company's accreditation platform every time it enters the site. That makes it a data processor under Law 21.719, and if it moves that data outside the instructions it was given, it answers as a controller, with obligations of its own toward its own people.
The standard answer is ISO 27001 certification. In Chile that starts at ten million pesos with a very tight scope, and realistically runs between forty-three and seventy-nine million in the first year. That contractor does not have that money. That is the entire point of EscudoIA.
The sharpest exposure in this sector is biometric data, and we cannot see it.
The fingerprints and faces held by access control gates and fatigue monitoring systems become sensitive data on 1 December 2026. They live inside those systems, not in a spreadsheet, and they have no check digit. CatastroIA does not reach them, and we are not going to pretend it does.
Second: we looked, and we found no documented case of a mining company demanding 21.719 compliance evidence from a supplier. What puts you under pressure is the deadline and your own liability. When somebody shows us the first real case, we will say so.
Chuquicamata photograph by Diego Delso, CC BY-SA 4.0, via Wikimedia Commons.
The same argument, one layer down.
We do not resell other people's tools. We write the engine we use, and we are designing the silicon that comes after it.
It is an inference processor meant to run an 8 billion parameter model at 30 tokens per second. That figure is not arbitrary: below 30 you feel you are waiting, above it you feel you are talking. All of it on a machine the user bought and keeps in their office. The logic is the scanner's, one layer down: the data does not leave because the model does not leave either.
This is ongoing research, in RTL, with the decisions documented as they are taken. It is not for sale. We mention it because it explains where the things we do sell come from.
- Model
- 8B at INT4
- Speed
- 30 tokens per second
- Memory
- LPDDR6, 225 GB/s real
- Design node
- ASAP7, predictive 7 nm
The memory bandwidth was not picked: it falls out of dividing the model by the speed. One block goes to real silicon through Tiny Tapeout. The whole die does not fit, and never will.
Felipe Carvajal Brown
M.Sc. in Numerical Simulation in Engineering from the Universidad Politécnica de Madrid. Lives in Santiago. He wrote the engine EscudoIA uses, line by line, and he is the one who will be on the call. There is no sales layer in between and no account executive will be handling you.
Vulnerability research
He hunts for flaws in public disclosure programmes, always with the system owner's authorisation. In Chile he reports through the citizen channel run by ANCI and the government CSIRT, and he wrote his own reconnaissance tooling in Python to do it.
How that tooling works
Twenty-five modules: subdomain enumeration, dangling CNAME takeover, exposed API specifications, secrets leaked in JavaScript, source maps published by mistake, CVE correlation, GraphQL, Host header handling and dependency confusion, among others.
What matters most for a client is not what it finds but what it refuses to do. Every programme carries its own scope list, rate limits and permitted vulnerability classes, and the scope checker rejects any host outside them. Without explicit confirmation it prints the authorisation warning and exits without scanning anything.
We do not publish which organisations we have reviewed. A finding gets told once the system owner has fixed it and decided it can be told, not before.
- Reconnaissance modules
- 25
- Programmes configured
- 27
- Automated tests
- 954
- Reporting channels
- 3
M.Sc. in Numerical Simulation in Engineering, Universidad Politécnica de Madrid.
ORCID 0000-0002-8300-7587
An hour, free, with nothing attached.
The five questions and, if you want it, the live scan on your own machine. It runs over video with screen sharing, and nothing needs installing.
Book a time Message on WhatsApp
If you would rather write first, fcarvajalbrown@gmail.com.