The material we would hand a security reviewer, published here instead of held back for the call.
The working papers. Nothing gated.
These four documents exist because the hardest part of buying private AI is not the demo, it is the meeting afterwards. Someone has to explain to a colleague what was agreed, in words that survive a second reading. So the vocabulary is defined, the questions are answered in writing, and the instrument we use in discovery is published rather than sprung on you later.
Written for whoever has to answer for it.
Three people usually decide this together, and they need different things from the same set of facts. None of them is served by a brochure. Each of these pages is written so it can be forwarded without a covering note.
You carry the risk.
Start with the questionnaire: it is the shape of the conversation we will have. Then the FAQ's security section, written for a reviewer looking for the gap rather than the pitch.
You carry the delay.
Start with the FAQ, then the preparation page. The useful preparation is not technical: it is one or two processes where waiting or rework actually costs you something.
You will run it.
Start with the glossary, because the argument turns on precise words: admission, promotion, artifact hash, drift check. Then the FAQ on models and on ownership.
What is here.
Four documents, each maintained against the same claim discipline as the rest of the site: if we cannot point at the mechanism, the sentence comes out.
Glossary
Every term this site uses as though it were defined, actually defined: the boundary, single-tenant, admission, refused in words, standing exception, posture tier, one-way mirror. Each entry links to the page that carries the detail, so it doubles as a map of the site.
Frequently asked questions
The questions people actually ask, from the basics through data, security, models, cost, ownership and the gateway. The hard ones are here on purpose: what happens when the model is wrong, who is accountable, what happens if the founder is unavailable.
How to prepare for the assessment
Who to bring and why, what is worth gathering first, the agenda as it actually runs, and what you leave holding. With a checklist you can print, and the questions worth asking us in the first hour rather than the fourth month.
See the questions before the call.
A faithful summary of the instrument we complete with you during discovery. It records your residency choice with its real capability cost, and asks you to acknowledge in writing that we hold no third-party attestation. Your answers become your deployment's committed configuration.
Ten questions, ten pages.
If you arrived with one specific worry, this is the shortest path to the page that answers it. Every one of these has a page rather than a paragraph, because each is the kind of question that deserves the mechanism and not a reassurance.
- 01Where does our data go?The boundary as a defined term: what stays in your account at rest, and what crosses by design.→
- 02What does it cost to run?Your cloud bill, itemized: platform infrastructure, inference, and what we have actually seen.→
- 03What if you disappear?A founder-led practice says this plainly: what you hold, what keeps running, what another provider would need.→
- 04Are you certified?No. What we hold instead: a controls matrix with a verdict per row, and where your program still has work.→
- 05Can we see it?Our own deployment, running the same release the factory ships. Not a scripted tour.→
- 06Can we keep it in this country?Storage and inference are different questions with different answers, and pinning inference costs you models.→
- 07What happens if we stop paying?You keep the platform, the source and the data. What that really takes to run is on the page.→
- 08Which of the two do we need?The platform keeps the model inside your account. The gateway governs the assistant your people already use.→
- 09What will this not do?The limits in one place, written by us, so your reviewer does not have to go looking for them.→
- 10How does an engagement run?Assessment, deployment, operations, capability. Every step is a gate with a named decider.→
Reference, not evidence.
These pages explain. They do not attest.
Marketing reference material and audit evidence are different objects, and treating one as the other is how a security review goes wrong late.
- 01Reference, in plain language. These four define the vocabulary, answer the questions and publish the instrument. They are written to be forwarded and argued with, which is a different job from evidencing a control.
- 02The artifacts sit elsewhere. The controls matrix with its verdict per row, the resolved posture object and the standing exceptions are real artifacts, and they live in the evidence pack. Nothing on a resources page is a report from an auditor.
- 03Prices are the published ladder. Figures here match pricing exactly. Anything scoped per deliverable is scoped in writing rather than estimated on a page.
- EvidenceEvidence packControls matrix, posture object, data-flow description, shared responsibility
- LimitsWhat we do not claimThe list we maintain against ourselves
- Working notesPulseLonger arguments, written when something changes
- The productLive demoOur own deployment, open to look at
- A personContactDirect line to the person who built it. No queue
Your private AI, inside your control ·
Read the questionnaire first if you like. The assessment is the same conversation, with your environment in front of us.