Features · what the layer actually controls

Everything R2 does, in one list

The work your team gets done, and the controls that make it allowable. Grouped the way a buyer evaluates it: what people do with it, what protects it, what governs it, and where it runs.

What your team actually does with it

Email and correspondence

Summarise a long thread, draft the reply in your own tone, translate an inbound message, and check a response before it goes out. In Outlook and Gmail, without the message leaving your control.

Documents and contracts

Draft, rewrite, shorten, expand, compare versions and summarise a document you have been sent. In Word and Google Docs, on privileged material, without it entering a training set.

Spreadsheets and analysis

Build a formula from a description, clean an imported column, explain a sheet someone else built, and describe what a dataset shows. In Excel and Sheets, on data that cannot be uploaded anywhere.

Decks and internal comms

Turn an outline into slides, tighten existing copy, and structure meeting notes as you take them. In PowerPoint, Slides and OneNote.

Meetings and channels

Catch up on a Teams thread, extract the decisions and the owners, and draft the follow-up in the channel.

Anything else in the browser

The extension carries the same layer into your CRM, ticketing system, internal tools and any web app your team lives in.

Model access

Every major model

GPT, Claude, Gemini, Grok, Llama, DeepSeek R1 and open-weight models you host yourself.

Switch per task

Pick the model that suits the job. The policy set, the logging and the encryption do not change when you switch.

Model permissions

Decide which groups may use which models. Restrict a model by department, by data class or by deployment mode.

Private and self-hosted models

Run open-weight models on your own infrastructure and reach them through the same interface as the commercial ones.

AI routing

Route requests by policy rather than by user choice, so sensitive data classes only ever reach approved destinations.

One subscription

One bill and one access list instead of a seat per model and a personal login per employee.

Protection

Encryption on the device

Prompts are encrypted where they are typed. Nothing readable crosses the network.

SDNP routing

Traffic is scrambled, split, mixed and repeatedly encrypted, then routed across independent nodes. No single node holds a complete message.

Last Mile Protection

A second patented layer covers the final leg between the node network and the user's device.

PII and PHI handling

Detection and handling rules applied before anything leaves the perimeter, configured to your data classes.

No retention by default

R2 stores no user-generated content as standard. Content is discarded when the add-in closes.

Tenant isolation

Your environment is separated from every other customer's, in every deployment mode.

Governance and evidence

Single sign-on and roles

Sign in with Microsoft, Google, Apple and other providers. Permissions map to your directory, so joiners and leavers are handled where you already handle them.

Policy engine

Rules by group, data class, model and deployment mode, enforced before the request leaves.

Audit trail

Who asked what, of which model, when, and as much of the exchange as your regulator requires.

Evidence export

Produce the record for an auditor or an examiner without reconstructing it from memory.

Evidence in your environment

The audit record sits inside your deployment, not with us. R2 stores no user content of its own.

Human accountability

Every interaction is attributable to a person inside your organisation, even though it is not attributable to you at the model.

Deployment and operations

Routed

We operate the node network and the connection to commercial models. Nothing for you to host.

Self-hosted

Open-weight models on your own infrastructure. Nothing leaves your network.

Your cloud

R2 in your tenant: AWS GovCloud, Azure Government, private VPC or air-gapped. Your keys, your region, your logs.

Bring your own keys

Enterprise deployments can use your own encryption keys.

Data residency

Deploy in any region, so the environment sits where your regulator expects it.

Nothing to deploy

Install and sign in. Custom and private environments are configured with our team on Enterprise.