Security & data residency

The whole point is that your data never becomes someone else's input. Here is exactly what touches what.

Deployment model

Most restrictive

Air-gapped

Container image delivered on media or via your artifact registry. No outbound connections exist in the image. Verified with a network-isolated test before hand-off.

Typical

On-prem, connected

Runs in your datacenter or office server. Optional outbound only for your own monitoring stack. Updates pulled by you, on your schedule.

Flexible

Your cloud tenant

Your AWS/GCP/Azure/Yandex/VK/Selectel account, your VPC, your keys. We never hold credentials past the engagement.

Where data goes during the build

PhaseOption A, standardOption B, fully private
Data preparation & labelingOur engineers may use commercial AI tooling on anonymized / synthetic / non-sensitive samples, under zero-retention terms, from an account you controlAll tooling is open-weights and runs inside your environment; nothing leaves
Model trainingIn your environment or on a training server we rent in a region you approve, with data encrypted at rest and wiped after delivery, your choice, in the contract
Inference (production)Always local. No telemetry, no callbacks, no license server.

Option B may cost a little accuracy on some tasks and is the default for healthcare, defense-adjacent and Russian-market clients.

Compliance context

We are engineers, not lawyers, but this is why clients come to us.

EU: GDPR and AI Act

Local processing removes the cross-border transfer question entirely. AI Act obligations for general-purpose models apply from Aug 2025; high-risk obligations are being phased in (currently slated for late 2027). A narrow, documented, locally evaluated model is far easier to put through a conformity assessment than an opaque third-party API.

US: HIPAA, GLBA, SOC 2

With inference on-prem there is no third party in the data path, so no BAA is needed for production. Audit trail, access control and logging stay in your existing controls.

Russia: 152-ФЗ and upcoming AI rules

Personal data must be stored and processed in-country; fines for leaks now reach a percentage of revenue. Draft AI legislation (published 2026) targets restrictions on foreign "cross-border" AI services. A model that runs inside your contour, with an open-weights base, sidesteps both.

Enterprise reality

Cisco's 2025 privacy benchmark: 64% of organizations worry about sharing sensitive information with generative AI tools; roughly half admit employees already do. Removing the API removes the shadow-AI problem for that workflow.

Supply-chain hygiene

Have a security questionnaire?

Send it. Answering it is usually the fastest first step.

Start a pilot →