Your data never reaches a public LLM. Not once.
We do not send your documents, calls, contracts or customer records to OpenAI, Anthropic, Google or anyone else. We run open-weight models that we host and tune ourselves — and where you need it, inside your own cloud tenancy or on your own hardware.
For regulated work in Europe this is usually the deciding question. It is a commitment we put in the contract, not a claim on a website.
- No third-party model calls. Ever.
- Deployment inside your cloud or on-premise if you require it.
- Your data is never used to train anything another client touches.
- Full audit logs of what the model saw and what it returned.
- Data residency in the region you name.
Most AI projects fail their own security review
The pilot works. Then legal asks where the data goes, and the answer is a US API with a sub-processor list nobody can enumerate. The project stops there — often after the budget is spent.
We build the other way round. The deployment constraint is the first question in discovery, so the thing we build is the thing you are allowed to run.
Open-weight models, hosted and tuned by us. Nothing is sent to an API you have not approved, and there is no hidden sub-processor behind the inference.
Your AWS, Azure or GCP tenancy, or your own servers. You hold the infrastructure, the keys and the data at rest.
Every request and response logged, retained on your terms, and readable by your compliance team without asking us for an export.
Fine-tuning happens on your data for your model only. No shared model is improved with anything you gave us.
EU-only if that is the requirement, including for logs, backups and the review interface.
Weights, prompts, pipelines and infrastructure code are documented and handed over. You can run it without us.
Three ways to run it
Dedicated, isolated infrastructure we operate in the region you specify. No shared inference, no multi-tenant model. The fastest route to production.
Deployed into your own AWS, Azure or GCP tenancy. Your VPC, your keys, your logs, your bill. We build and operate it there under your access controls.
Your own hardware, air-gapped if required. We size the GPUs, deploy the stack, and train your team to operate it.
The choice is made in discovery, with your security and legal teams in the room. It is not a pricing tier — it is a design constraint, and it changes what we build.
Against the usual approach
Public models are not wrong for every workload. Where your data is not sensitive and speed matters more than control, we will tell you so — and use them.
Two engagements
A support agent that handles customer data without exporting it
- Context
- A CRM company in Europe whose support desk handles their customers' customer records — data they are contractually barred from sending to a third-party model.
- What we built
- A conversational support agent trained on their own product knowledge, running entirely on privately hosted open-weight models. Conversations, tickets and account data stay inside the approved environment, with full request logging for their compliance team.
- Why it mattered
- The privacy position was what made the project approvable at all. A public-API build would not have passed their own customer commitments.
Lab results read and structured, inside the lab's own boundary
- Context
- Test results arrived as images and were retyped by hand into the lab system. The data is client-confidential and subject to accreditation requirements.
- What we built
- Automated reading of the images into structured, validated records, on models hosted privately — no test data or client identifier leaving the approved environment, with an audit trail per document.
- Why it mattered
- Accredited labs have to be able to show where every figure came from. Private deployment plus per-document logging gave them that.
Clients are anonymised until we have written permission to name them.
Designed to the regulation from the first workshop
GDPR, the EU AI Act, ISO 27001 and SOC 2 shape the architecture rather than getting retrofitted before go-live. Data processing agreements, records of processing and risk classification are part of delivery, not a separate project.
Lawful basis, minimisation and residency settled before any data moves.
Risk classification, human oversight and documentation for the system you deploy.
Access control, key management and change control on the deployed stack.
Evidence your auditors can use, produced by the system rather than assembled later.
Security first, then the build
- 01Constraints
One session with your security, legal and data owners. What data is in scope, where it is allowed to sit, who must be able to audit it.
- 02Architecture
Model selection, sizing and deployment target, written down and signed off before code. Your team reviews it as a document, not a demo.
- 03Build & deploy
We build the agent or pipeline and deploy it into the approved environment, with the logging and access controls in from the start.
- 04Operate or hand over
We run it, or we document it and train your team to. Either way you hold the weights, the code and the infrastructure.
This is how we build everything
Private deployment is not a separate product line. It is available on every engagement, and it is the default wherever the data is sensitive.
Bring us the AI project your security review stopped.
A discovery session is a working conversation, not a demo. Bring your security lead — the deployment question is the one we want to start with.