The pipeline runs a local LLM (Ollama, gpt-oss:20b) entirely on-prem, so no customer data or part-number data leaves the client's network. Before any email reaches the model, a masking node tokenizes sender email, sender name, phone numbers, and the client's own staff identifiers — the model only ever sees placeholders, never a real address, while operational signal (part numbers, company names) stays intact because the classifier needs it.