Healthcare · Legal · Public sector · Finance
AI you can put in front of a supervisory authority
In a regulated organisation the question is never just "does it work?" It's "can we prove where the data went, who could see it, and that it never left our control?" We build AI systems with that question answered first.
The dominant way to add AI today is to send your text to an external API and hope the contract holds. For an organisation processing patient records, case files, citizen data, or financial books, "hope the contract holds" is not a control. Our approach removes the transfer entirely: the model runs inside your environment, so protected data is processed where it already lawfully sits.
Boundary control by design, not by policy
A clause in a data-processing agreement tells an auditor what is supposed to happen. An architecture where the data physically cannot leave tells them what does happen. We design for the second.
The data never crosses the perimeter
Inference runs on infrastructure you operate — on-premises or in a sovereign environment you designate. There is no outbound call carrying personal data to a third-country processor, because there is no third-party processor in the loop.
Auditable from prompt to output
Every request, the data it touched, and who invoked it can be logged within your own systems. When a supervisory authority or internal audit asks for the record, you have it — not a vendor in another jurisdiction.
Air-gapped where the mandate requires it
For the most sensitive workloads we deploy fully offline — no internet egress at all. The system is useful and the network boundary is absolute.
Mapped to the frameworks you actually answer to
We speak to your obligations directly, not in the abstract:
- GDPR — Article 32 & data minimisation
- Keeping processing inside your boundary materially supports the "appropriate technical measures" expected under Art. 32, removes the third-country transfer problem (Chapter V) at the root, and makes data-minimisation provable rather than promised.
- NIS2 — supply-chain & incident posture
- Self-hosted inference shrinks your third-party attack surface and keeps security monitoring, access control, and incident evidence under your own roof — squarely in line with NIS2 risk-management and reporting duties.
- Sectoral & national rules
- Patientdatalagen for care, secrecy duties for public bodies, and Bokföringslagen's seven-year retention and integrity requirements for financial records — we design retention, access, and logging to fit each, with your DPO and legal team in the room.
How an engagement runs
We expect to work alongside your security, legal, and compliance functions from day one — not present them with a finished system to bless after the fact. We start with a data-flow and risk assessment, agree the boundary, and build to it. Nothing reaches production without a documented basis your auditors can follow.
Bring your toughest compliance question.
Talk to us