Skip to content
Echnotek
Private AI Deployment

Your data never reaches a public LLM. Not once.

We do not send your documents, calls, contracts or customer records to OpenAI, Anthropic, Google or anyone else. We run open-weight models that we host and tune ourselves — and where you need it, inside your own cloud tenancy or on your own hardware.

For regulated work in Europe this is usually the deciding question. It is a commitment we put in the contract, not a claim on a website.

What we commit to
  • No third-party model calls. Ever.
  • Deployment inside your cloud or on-premise if you require it.
  • Your data is never used to train anything another client touches.
  • Full audit logs of what the model saw and what it returned.
  • Data residency in the region you name.
Why this matters

Most AI projects fail their own security review

The pilot works. Then legal asks where the data goes, and the answer is a US API with a sub-processor list nobody can enumerate. The project stops there — often after the budget is spent.

We build the other way round. The deployment constraint is the first question in discovery, so the thing we build is the thing you are allowed to run.

No third-party model calls

Open-weight models, hosted and tuned by us. Nothing is sent to an API you have not approved, and there is no hidden sub-processor behind the inference.

Runs where you say

Your AWS, Azure or GCP tenancy, or your own servers. You hold the infrastructure, the keys and the data at rest.

Auditable end to end

Every request and response logged, retained on your terms, and readable by your compliance team without asking us for an export.

Nothing trains on you

Fine-tuning happens on your data for your model only. No shared model is improved with anything you gave us.

Data residency you choose

EU-only if that is the requirement, including for logs, backups and the review interface.

Exit without hostage

Weights, prompts, pipelines and infrastructure code are documented and handed over. You can run it without us.

Deployment models

Three ways to run it

We host it privately

Dedicated, isolated infrastructure we operate in the region you specify. No shared inference, no multi-tenant model. The fastest route to production.

Best when you need it working quickly and your policy allows a named EU processor.
In your cloud
Most common

Deployed into your own AWS, Azure or GCP tenancy. Your VPC, your keys, your logs, your bill. We build and operate it there under your access controls.

Best when data cannot leave your estate but you do not want to run the models yourself.
On premise

Your own hardware, air-gapped if required. We size the GPUs, deploy the stack, and train your team to operate it.

Best when the workload is classified, or a regulator requires physical control.

The choice is made in discovery, with your security and legal teams in the room. It is not a pricing tier — it is a design constraint, and it changes what we build.

The difference

Against the usual approach

Where does our data go?
A public-API buildTo a model vendor's API, under their terms
With usNowhere outside the environment you approved
Who are the sub-processors?
A public-API buildA list that can change with notice
With usUs, and the cloud account you already own
Can we audit what the model saw?
A public-API buildOnly what the vendor exposes
With usEvery request and response, in your own logs
What happens if pricing or terms change?
A public-API buildYour unit economics change with them
With usThe weights are yours; the cost is infrastructure
Can it run without internet access?
A public-API buildNo
With usYes, air-gapped where that is the requirement

Public models are not wrong for every workload. Where your data is not sensitive and speed matters more than control, we will tell you so — and use them.

Where we've applied it

Two engagements

All case studies →
CRM software customer

A support agent that handles customer data without exporting it

Context
A CRM company in Europe whose support desk handles their customers' customer records — data they are contractually barred from sending to a third-party model.
What we built
A conversational support agent trained on their own product knowledge, running entirely on privately hosted open-weight models. Conversations, tickets and account data stay inside the approved environment, with full request logging for their compliance team.
Why it mattered
The privacy position was what made the project approvable at all. A public-API build would not have passed their own customer commitments.
Food testing lab customer

Lab results read and structured, inside the lab's own boundary

Context
Test results arrived as images and were retyped by hand into the lab system. The data is client-confidential and subject to accreditation requirements.
What we built
Automated reading of the images into structured, validated records, on models hosted privately — no test data or client identifier leaving the approved environment, with an audit trail per document.
Why it mattered
Accredited labs have to be able to show where every figure came from. Private deployment plus per-document logging gave them that.

Clients are anonymised until we have written permission to name them.

Compliance

Designed to the regulation from the first workshop

GDPR, the EU AI Act, ISO 27001 and SOC 2 shape the architecture rather than getting retrofitted before go-live. Data processing agreements, records of processing and risk classification are part of delivery, not a separate project.

GDPR

Lawful basis, minimisation and residency settled before any data moves.

EU AI Act

Risk classification, human oversight and documentation for the system you deploy.

ISO 27001

Access control, key management and change control on the deployed stack.

SOC 2

Evidence your auditors can use, produced by the system rather than assembled later.

How we work

Security first, then the build

  1. 01
    Constraints

    One session with your security, legal and data owners. What data is in scope, where it is allowed to sit, who must be able to audit it.

  2. 02
    Architecture

    Model selection, sizing and deployment target, written down and signed off before code. Your team reviews it as a document, not a demo.

  3. 03
    Build & deploy

    We build the agent or pipeline and deploy it into the approved environment, with the logging and access controls in from the start.

  4. 04
    Operate or hand over

    We run it, or we document it and train your team to. Either way you hold the weights, the code and the infrastructure.

Applies to

This is how we build everything

Private deployment is not a separate product line. It is available on every engagement, and it is the default wherever the data is sensitive.

Bring us the AI project your security review stopped.

A discovery session is a working conversation, not a demo. Bring your security lead — the deployment question is the one we want to start with.

Start with a conversation

Let’s talk now