Isolation by the database.
Tenant data is separated by PostgreSQL row-level security, enforced one layer below the application, where a single coding mistake can’t quietly defeat it. We ship a cross-tenant test suite that proves it, table by table.
Production-grade AI · Built to a regulated standard
We design and build AI applications that go into production: tenant data isolated by the database, every model and persona versioned and evaluated, no egress you didn’t configure. Then we hand you the code, and hand your reviewer the isolation report that shows it.
It leaks data across tenants, can’t say which model decided what, runs on someone else’s cloud, and stalls the moment it meets a security questionnaire.
We build the opposite, and the difference is structural rather than cosmetic. Ask any vendor for their cross-tenant isolation report; ours regenerates on demand, against every deployment, including yours.
Why it passes a security review →The four things we get right
These decide whether the project survives infosec, the auditor, and the second year of production.
Tenant data is separated by PostgreSQL row-level security, enforced one layer below the application, where a single coding mistake can’t quietly defeat it. We ship a cross-tenant test suite that proves it, table by table.
It runs on your infrastructure. Your data, your prompts, your audit logs never have to leave your control. Built for data-residency and sovereignty requirements, not retrofitted for them. And self-hosted doesn’t mean self-operated. If you’d rather not run it yourself, our managed service operates it for you, under an SLA.
We don’t prompt and pray. Every model and every AI persona is versioned, tested against a defined evaluation set, and logged. You can show which version of what behaviour was live on any given day.
You get the source, on your servers, with the architecture documented. No lock-in to a SaaS you can’t audit and can’t leave.
What we do
Most engagements pull from two or three of the offerings below.
We design and ship an AI application that survives a security review. Self-hostable, multi-tenant capable, governed, and auditable from the first commit.
More on Governed AI Delivery → 02 - ProductisedPre-built AI workbenches for specific regulated workflows, branded to you, with the starting line months ahead of a blank-page build. Currently: Credit-Risk Review, KYC & AML Review and Bid & Tender Management.
More on Vertical Workbenches → 03 - AssuranceIndependent evidence that your AI system isolates data, governs its models, and can be audited. Packaged for procurement and your board.
More on Assurance & Governance → 04 - PersonasWe turn your domain expertise into governed, versioned AI personas that are tested, compiled, and served to whatever runs them.
More on Persona & Knowledge → 05 - EnablementLicense our platform and have your own team building on the same foundation, with our architects alongside.
More on Platform Enablement → 06 - OngoingWe operate the systems we (or others) have built, under an SLA: monitoring, evaluations, updates, and a continuous improvement backlog.
More on Managed Run →The platform underneath
The foundation for AI applications that have to behave.
The application foundation that deploys in your cloud, with multi-tenancy built in where you need it.
/personasVersion-controlled, evaluation-tested AI personas.
The governed persona engine: authored, versioned, evaluated, and served to anything that speaks MCP.
/runtimeAgents that survive a restart.
The durable runtime for long-running, resumable agent work: checkpoints, claim queues, persistent memory.
“Which model wrote this, and under what policy?”
In our systems, that’s a query.
How we engage
Working code early, production on a named date, and you own everything we leave behind.
Security & assurance
Every regulated buyer has the same five questions about an AI system. We wrote the long-form answer to each, in the language a security reviewer would use and free of marketing.
Questions
Regulated organisations that need AI in production and can’t accept a SaaS where one customer might see another’s data, where data leaves their cloud, or where they can’t audit what changed and when.
That’s the default. We can run a managed instance for you under a managed-run agreement if you prefer, but the architecture is built for your servers first.
Every AI persona - the way an assistant or agent should behave - is version-controlled, tested against an evaluation set before it goes live, and logged when it acts. You can show, at any point, what was live and what it did.
Yes. Source in your repos. Architecture documented. No proprietary runtime you can’t leave.
We’ll tell you straight whether we’re the right team.