Self-Hosted AI Agents

Your documents, your customers, your data — none of it leaves your infrastructure.

Every managed AI platform sends your business data to someone else's servers to be processed. Contracts, patient records, financials, customer conversations. We build agents that run on hardware you control — your cloud region, your premises, or fully air-gapped.

Saudi PDPLUAE PDPLDIFCHIPAAGDPR

Deployed in your account · Full source handover · 7+ yrs building production AI

Should you buy this?

Three reasons to own the stack. Only three.

The law requires it — data-residency rules mean customer or patient data can't be processed abroad

Volume changed the math — past ~100,000 interactions a month, owning costs less than renting

A client contract forbids third-party processing — their compliance obligations are now yours

If none of those is you, don't buy this. Below that volume and without a data rule, the managed track does the same job for a fraction of the cost. Start there, prove it works, and we migrate you when it makes sense — your agents and integrations carry over. Managed track →

Two options

Choose by what your rules actually require.

Everything is identical — same agents, same integrations, same ownership, same handover. One question decides your tier: may an AI provider process your data at all, once identifiers are removed?

Air-gapped deployment

Shielded

No

Isolated

Yes

Compute requirement

Shielded

Standard compute

Isolated

GPU capacity

Build time

Shielded

8–10 weeks

Isolated

10–14 weeks

Both tiers include the full integration suite

Included in both tiers

At this tier, the full integration suite is included rather than quoted per module.

  • Extra CRM & tool integrations
  • Additional channels
  • Payment processing
  • Custom backend & API connectors
  • Multi-language support
  • Human-in-the-loop approvals
  • Custom analytics & reporting
  • Monitoring & observability
ShieldedIsolated
Reasoning model runsProvider APIYour hardware
What leaves your perimeterDe-identified text onlyNothing
Documents & knowledge baseYour cloudYour cloud
Agent logic & workflowsYour cloudYour cloud
Logs, records, conversationsYour cloudYour cloud
CRM & business systemsYour systemsYour systems
PII de-identification layerIncludedNot needed — nothing leaves
Third-party outages affect youYesNo
Model choiceAny frontier providerOpen-weight models

If you're unsure, you're probably Shielded. We'll say so at scoping rather than sell you the larger build. Isolated exists for requirements that are genuinely absolute.

What the PII shield does on Shielded+

Names, dates of birth, national ID and passport numbers · phone numbers, emails, addresses · card numbers, IBANs, account numbers · medical record and patient identifiers · your own patterns — all tokenised before text leaves your perimeter, and restored locally so the output stays useful.

You also get: a redaction log for every run · detection rules tuned to your vocabulary · a measured accuracy report on your own real data before go-live.

Proof

We've shipped this, not just scoped it.

An on-premise AI document review system for forensic reports — running entirely inside the client's environment, no cloud dependency read the case study →

A fully local voice pipeline — speech recognition, reasoning model and voice, all on the client's own hardware

What we won't claim

Compliance certification.

We build the technical capability that makes data residency achievable — where data flows, where it's stored, what's logged — and hand your compliance specialist the architecture documentation they need. Certifying it against HIPAA, PDPL or GDPR is their work, not ours. Be wary of any vendor who tells you otherwise.

Why it's safe to say yes

Nothing here asks you to commit blind.

Technical discovery comes first, and stands alone — architecture, data-flow map, infrastructure and GPU sizing, deployment plan and cost model. Priced separately, credited in full against the build. The documents are yours whether or not you proceed

See it working before you provision anything — we demonstrate your hardest workflow in our own environment first

Success is a number in the contract — agreed at discovery, tested against your real data

Milestone-based delivery — payments tied to deliverables you can inspect

Revoke our access anytime — we work through a scoped service account that deploys and monitors this system only, never your wider environment. Revoke it and the system keeps running

Deployed into your cloud or hardware, in whatever region you require. We host nothing — you hold the account, the infrastructure and the source

You'll need: a cloud account or hardware in your region · someone who can approve infrastructure provisioning · (Shielded) your own provider accounts · infrastructure budget, sized and quoted at scoping. Isolated needs GPU capacity; Shielded runs on standard compute.

Your security review, procurement process and compliance approvals set the real timeline. We plan around them and tell you at scoping which milestones depend on your side.

Questions

Common questions

How is this priced?+

A fixed build fee plus a monthly retainer for engineering, agreed after scoping. You pay your cloud provider — and, on Shielded, your AI provider — directly, at cost. We never mark up usage.

Are open models good enough for real work?+

For document processing, extraction, classification, support answers and structured decisions — yes, and we'll prove it on your data at discovery. Models are selected against your accuracy, latency and hardware constraints, and we demonstrate real output on your own use case before you commit — not a benchmark chart. For tasks where a frontier model is genuinely required, we'll tell you, and Shielded is the honest answer instead.

Can we start managed and move later?+

Yes — the right sequence for most businesses. Your agents, workflows and integrations carry over. Managed track →

What if you disappear?+

You hold the account, the infrastructure and the full source. Revoke our service account and nothing stops. That's the architecture, not a promise.

Own the stack. Own the data. Own the economics.

Bring your volume, your jurisdiction and your constraints. We'll tell you which tier fits — including when the answer is “neither, yet.”