Deployment & Security
Our default deployment starts with hardware we supply, installed on your site, on your network, where your digital teammates actually do their work — inside the compliance setup and security policies you already operate under. From there the platform stays provider-agnostic: mix locally hosted models on your on-prem hardware with private cloud and enterprise model APIs, and choose which providers ever see your data, task by task.
When the work is sensitive, the workforce runs where you say it runs.
Each role runs in a private environment for one organisation only. Deploy on-premises or on private cloud. There is no cross-customer sharing of resources, activity history, or operational context.
On-Prem Hardware
We supply the hardware. Your teammates work on your site.
Setup includes dedicated on-prem hardware — currently a compact GB10 unit built for serious model workloads — installed on your premises and joined to your network. It is not a gateway or a cache: it is where the work happens.
Your network, your compliance
Because the workforce runs on a box inside your building, it inherits the compliance setup and security policies you already have. No new data-processing perimeter to defend — your existing controls apply.
Local specialists for heavy lifting
The hardware is powerful enough to run specialised models on site. Data ingestion, document ingestion, and other high-volume work run locally — without spending frontier-model tokens on it.
Mix local and cloud, task by task
Sensitive work stays on your on-prem hardware and never leaves your premises. Less-sensitive tasks can run against Claude or any cloud model you approve. You get both, and you decide which is which.
How Engagements Are Structured
One setup fee. One monthly fee. An expert on your side throughout.
The structure is deliberately simple: setup covers the hardware and your first team, and the monthly fee scales with the workforce you actually run — with a human expert included throughout.
Hardware, installation, and your first team
- + The hardware itself — supplied, not sold separately
- + Installation and configuration on your site and network
- + Building the initial team of digital teammates for your organisation
Scales with the teammates you run
- + The monthly fee scales with how many digital teammates you are using
- + Includes a forward-deployed engineer dedicated to your deployment
- + Ongoing monitoring, optimisation, and support are part of the fee
An expert who works alongside your workforce — and does real work too.
Every engagement includes a forward-deployed engineer: an expert in running the platform who helps you orchestrate your digital teammates, keeps the system optimised and monitored, and acts as your first line of support. They are not just an operator — they can implement software and systems for you directly, working as an expert member of your extended team.
Infrastructure Options
Choose control, speed, and cost deliberately.
Every digital teammate can be deployed three ways. Supplied on-prem hardware is the default — and the tiers combine: on-prem hardware for sensitive work, cloud models for the rest.
Supplied On-Prem Hardware
As part of setup we supply dedicated, workstation-class hardware — currently a GB10 unit — that you host on site. That is where your digital teammates actually do their work.
Healthcare, financial services, government, and any organisation where the most sensitive work must stay inside the perimeter — without giving up frontier models for everything else.
Private Cloud GPUs
Dedicated GPU infrastructure in a private environment we configure and manage, without shared public endpoints.
Organisations that need tighter residency, isolation, and procurement controls without running hardware themselves.
Cloud APIs
Enterprise-grade model providers for teams that need the fastest path to production on lower-sensitivity workloads.
Teams whose data classification allows third-party processing under enterprise agreements and who want to start quickly.
Security Architecture
Built for teams that have to defend their controls.
Every layer is structured for environments where data classification, auditability, and access control are not negotiable.
On-Premises and Private Cloud as Standard
Run the workforce on your own hardware or dedicated private cloud infrastructure. Higher-control deployment is built into the offer, not sold as an afterthought.
Data Sovereignty
Choose exactly where your data resides. On-premises, specific cloud regions, or within national borders. You control data residency at every layer.
No Customer Data Reuse
Your data is not used to improve another customer deployment, shared across environments, or pooled into a common memory layer.
Isolated Storage
All data processed by your digital teammate is stored in an isolated environment. Complete separation between customer data at every layer.
Full Audit Logs
Every action taken by your digital teammate is logged and traceable. Complete transparency into what was done and when.
Dedicated to One Organisation
Each role is provisioned for one organisation only, with no cross-customer sharing of resources, data, or operational context.
Compliance
Designed to survive procurement and compliance review.
Our deployment models align with established regulatory frameworks, and we provide the documentation and controls mapping your audit team will ask for.
SOC2 Type II
Our infrastructure and operational controls are designed to meet SOC2 Type II requirements. We provide controls mapping documentation and evidence packages for your audit team.
ISO 27001
Deployment models align with ISO 27001 control objectives for information security management. ISMS documentation and control alignment reports available on request.
GDPR
Full data residency controls allow you to keep data within specific geographic jurisdictions. DPA terms, right-to-erasure support, and data processing records included.
HIPAA
On-premises and private cloud deployments support HIPAA-compliant handling of PHI. Business Associate Agreements available. Encryption at rest and in transit enforced.
Security Controls
Operational controls, not just positioning.
The day-to-day controls your security team will want to see — infrastructure, access, logging, data handling, credentials, and review.
Infrastructure Controls
- + On-premises hardware security with physical access controls
- + Private cloud isolation — dedicated instances, no shared tenancy
- + Network segmentation for sensitive environments
- + Geographic data residency enforcement at the infrastructure layer
- + Encrypted storage and encrypted data transmission across all deployment models
Access Controls
- + Each digital teammate operates under scoped credentials — limited to the systems and repositories you approve
- + Permissions defined per tool and per action (read, write, execute)
- + No lateral access between customers or between teammates within the same organisation
- + SSO integration supported — teammates can authenticate through your identity provider
Audit Logging
- + Every action is logged with timestamp, tool, input, and output
- + Logs available via dashboard export; API access and SIEM forwarding available on request
- + Configurable retention periods agreed during onboarding
Data Handling
- + Data processed in-session is not persisted beyond task completion unless explicitly configured
- + No cross-customer data sharing, aggregation, or model training
- + Data deletion available on request — timelines agreed per customer
- + Encryption at rest and in transit using industry-standard protocols
Authentication & Credentials
- + Customer-managed credentials supported — bring your own API keys and service accounts
- + Secrets stored in isolated vaults, never in plaintext or logs
- + Credential rotation supported and recommended on a regular cadence
- + MFA enforced for all operator and administrative access
Security Review Process
- + Security questionnaire and DPA available on request before onboarding
- + Penetration testing programme in place — results available under NDA
- + Dedicated security contact for incident reporting and escalation
- + Custom security review process available for regulated industries
How Data Moves
A controlled path from system to output.
On the on-premises and private-cloud tiers, here is how data moves: you decide what is connected, what can be accessed, and which actions require approval before anything high-risk happens.
Connect Approved Tools
Only the systems you approve are connected. Access starts from your existing permissions model.
Process in Your Infrastructure
Your digital teammate runs on the on-prem hardware on your site or in your private cloud — isolated and dedicated to your organisation only.
Log and Review Actions
Every action is logged for traceability, and sensitive operations can require human approval.
No cross-customer data flow. No shared memory. Full traceability. On the on-premises and private-cloud tiers, everything stays inside your perimeter.
Industries
Structured for sectors where shortcuts create risk.
We work with regulated organisations that need delivery capacity without compromising security posture, residency, or oversight.
Healthcare
Financial Services
Government
Plan your secure deployment.
Tell us about your compliance requirements, data classification, and preferred operating model. We will recommend the deployment path that fits.