Skip to content

Now deploying private AI for healthcare, legal, and finance teams across the EU

SRI

For teams blocked from using cloud AI

Use AI on your data. Keep it inside your company.

We deploy private AI systems on your own hardware or a dedicated machine only you can reach. No third-party API, no data egress, no vendor holding your documents.

  • Open weights, no vendor lock
  • Audit log in your own stack
  • Runs with the network cable out
your network

$ _

model: online · host: your-rack-01

Typical pilot to production
0 weeks

Typical pilot to production

Bytes leaving your network
0

Bytes leaving your network

Infrastructure you control
0%

Infrastructure you control

The difference

AI runs inside your network.

Your data never leaves.

Cloud AI

Sensitive data sent to third-party APIs

With SRI

AI deployed on infrastructure you control

External data egress: None

Built for teams in

HealthcareLegalFinancePublic SectorInsuranceManufacturingLogisticsEnergyHealthcareLegalFinancePublic SectorInsuranceManufacturingLogisticsEnergy

The wall everyone hits

Every team wants AI. Half of them are not allowed to use it.

The blocker is almost never the model. It is that using it means uploading the exact documents you are contractually and legally required to keep in house.

01

Legal says no

Client files, patient records, and contracts cannot be processed by a third party without a chain of agreements nobody wants to sign.

02

Security says no

A cloud API means an outbound path for your most sensitive data, with retention and training terms you do not control.

03

So people do it anyway

Shadow AI on personal accounts is the outcome of saying no without offering an alternative. That is the real risk you are carrying today.

What we actually do

We run the AI. You keep the data.

You buy a machine, or we rent you a dedicated one. We install the model, wire it to your documents, and manage it over an SSH channel you control. Your team gets a search bar and a chat box. Nothing leaves your network.

FIG.1

01

Unsorted internal documents scanned and returned as a ranked shortlist of use casesWHAT YOU HAVEcontractsticketsemailwikiWORTH BUILDING FIRST1. doc search2. contract review3. ticket triage+ hardware sized, data flow written

We work out what to run

One call, then a spec instead of a slide deck.

We look at the work your team actually does and which parts are blocked today. You get back a shortlist of use cases worth building, the model that fits them, and the exact hardware it needs, priced.

  • 1.1 Use cases ranked by value and by how hard they are to approve
  • 1.2 Model and hardware sized for your volume, not for a benchmark
  • 1.3 A written data flow your security team can sign off on

FIG.2

02

Two setups: hardware in your rack, or a dedicated GPU we rent for you, both managed over SSHSRItwo engineerssshOPTION A / YOUR RACKyour boxyou buy itwe configure itOPTION B / OUR HOSTINGgpu, eusingle tenantlive in daysmodel · retrieval · internal API installed on both

We set the machine up

Your hardware, or a dedicated GPU we rent for you.

Buy a box and keep it in your own rack, or let us put a single-tenant GPU in an EU data centre in your name. Either way we install the model, the document search, and the internal API, and we manage it remotely over SSH.

  • 2.1 Your hardware: you own it, we configure it, access on a channel you control
  • 2.2 Our hosting: dedicated GPU, EU region, live in days instead of a quarter
  • 2.3 Model, retrieval, and internal API wired to SharePoint, ERP, or your own systems

FIG.3

03

Queries circulate inside your perimeter while outbound calls are stopped at the boundaryYOUR PERIMETERmodelon your hostOUTSIDEmodel vendorcloud apiunreachableby design

Nothing leaves the network

No third-party API anywhere in the request path.

Inference happens on your machine. There is no call out to a model provider, so there is no processor agreement, no transfer, and no retention question. Every query is logged inside your own perimeter.

  • 3.1 Zero outbound calls during inference, verifiable on your own firewall
  • 3.2 Role-based access and a full audit trail of every question asked
  • 3.3 Air-gapped option with no route in or out at all

FIG.4

04

A continuous health pulse with maintenance events we handle without your team noticingUPTIMEmonitored by usWHAT WE DO WHILE YOU WORKpatch appliedmodel swappedcapacity raised

We keep it running

Monitoring, patches, and model upgrades on one monthly fee.

AI systems are not set and forget. We watch performance, apply updates, and swap in better open models as they ship. When something breaks, the alert goes to us and not to your service desk.

  • 4.1 Uptime and latency monitoring, with alerts routed to us first
  • 4.2 Model upgrades and capacity planning as usage spreads across teams
  • 4.3 A direct line to the two engineers who built your deployment

The decision on one page

Same capability. Different threat model.

This is the table your security officer will build anyway. Here it is up front.

Cloud AI compared with a private deployment by SRI Systems
CriterionCloud AISRI
Where inference runsVendor infrastructure, region of their choosingHardware you own or rent in your own name
Who holds your documentsA third party, under their retention policyYou. The index never leaves your disk
Processor agreement neededYes, plus transfer assessmentNo third-party processor in the request path
Works with no internetNoYes, on-premise and air-gapped
Audit log locationVendor console, exportable at bestYour own log stack, queryable like any other service
Model choiceWhatever the vendor ships and deprecatesOpen weights you pin, upgrade, or roll back
Cost shapePer token, unbounded, scales with successFixed hardware or fixed monthly, flat under load
If the relationship endsAccess stops, data export on their termsThe system keeps running. You already own it

How it works

From first call to production in about four weeks.

A fixed, boring sequence. You always know what happens next and what your security team needs to look at.

  1. 0145 min

    Discovery call

    We look at the work your team actually does and which parts are blocked today. If local AI is the wrong answer for you, we say so on this call.

  2. 02Week 1

    Architecture and sizing

    Model selection, hardware sizing, integration points, and a written data-flow diagram your security team can review and sign off.

  3. 03Weeks 2 to 3

    Pilot deployment

    We deploy on your hardware or a dedicated machine, wire it to a real document set, and put it in front of a small group of real users.

  4. 04Week 4

    Rollout and handover

    Access control, audit logging, monitoring, runbooks, and training. Your IT team can operate it. We stay on for support if you want us to.

Deployment options

Three ways to run it. All of them stay yours.

The right one depends on how strict your data rules are and whether you would rather own hardware or rent it.

01
A server in your own rack, reached over an SSH channel you controlYOUR BUILDINGyou own itsshno internetrequired

On-premise

A machine in your own rack or office.

Best for: Strictest data rules, offline sites, long horizons

  • Runs on hardware you buy and own outright
  • Works with no internet connection at all
  • We manage it over a VPN or SSH channel you control
  • Predictable cost after the hardware is paid for
02Most chosen
A single-tenant GPU in an EU data centre, rented in your nameEU DATA CENTREsingle tenantyourteam

Private cloud

Dedicated GPU hosting in an EU data centre.

Best for: Fast start, heavier models, no hardware purchase

  • Single-tenant GPU, not a shared inference API
  • EU region of your choosing, contract in your name
  • Scale up or down as usage grows
  • Live in days rather than after a procurement cycle
03
An isolated machine with no network route in or outNO ROUTE IN OR OUTupdates byhand, on site

Air-gapped

No network path in or out. At all.

Best for: Classified, clinical, or regulator-facing environments

  • Models and updates delivered on physical media
  • No telemetry, no licence check, no phone home
  • Full audit trail of every change we make
  • On-site deployment and training

Governance

The questions an auditor opens with.

We are not your compliance officer. We build the architecture that makes these answers short.

GDPR

Who processes personal data, and where?

You do, on your own infrastructure. No third-party processor and no international transfer to assess.

EU AI Act

Can you document and control the system you deploy?

Model version, weights, prompts, and retrieval sources are all pinned and versioned in your repository.

Sector rules

Does patient or client data stay in the estate?

It never leaves. Air-gapped deployment removes the network path entirely, not just the policy.

Continuity

What happens if the supplier disappears?

Open weights, open components, documented configuration, and your team holds the runbooks.

What it actually gets you

The same tools your competitors use. Without the paperwork.

Search everything you own

Ask a question in plain language and get an answer with citations from your contracts, policies, and archives.

Draft and review faster

First-pass drafting, summarising, and clause comparison on documents that were never allowed near a cloud tool.

Triage the queue

Classify and route tickets, mail, and forms automatically, with a human check where it matters.

Keep the audit trail

Every prompt and answer logged inside your network, attributable to a user, retained on your terms.

What it costs

Three line items. No per-token surprise.

The reason cloud AI budgets explode is that the bill scales with adoption. This does not. You pay to have it built, you pay for the machine, and you pay a flat fee to keep it running.

01

Assessment

Workflow review, model and hardware sizing, integration plan, and the written data flow your security team signs off on. Credited against the deployment if you go ahead.

Fixed fee, one off

02

Deployment

Everything installed, wired to your documents and systems, access control and audit logging in place, runbooks handed to your IT team. Quoted before you commit.

Fixed fee, one off

03

The machine

Buy the hardware and own it outright, or rent the same shape from us as a single-tenant GPU in an EU data centre. We tell you honestly which is cheaper for your volume.

Your capex, or our monthly

04

Support

Monitoring, patching, model upgrades, and capacity planning. Flat under load, because the cost of an extra thousand queries on hardware you already own is zero.

Flat monthly

Both fixed fees are quoted after the discovery call and before you commit to anything. There is no per-seat licence and nothing that expires.

Who is behind it

Two engineers with fourteen and ten years of shipping infrastructure.

We are early as a private AI company and we are not going to pretend otherwise. What is not early is the pair building it. Both names below are public, and so is the work.

KK

Kevin Karsopawiro

Co-founder, Lead Engineer

14 years

Founder of tegra.io. Directed engineering at Satoshi, senior roles at Chaincode Labs and Injective Labs.

Low-latency systems, decentralised platforms, cloud-native infrastructure

JK

Justin Karsopawiro

Founder, Engineer

10 years

Founded Webvork in 2017 and runs operations. Previously at Blinqx and Tradecast.

Real-time applications, data-heavy platforms, retrieval and integrations

What we will not claim

Read our background
  • No customer logos on this page, because we are not going to borrow credibility we have not earned yet.
  • No case studies with anonymous job titles attached. If we cannot name it, we will not quote it.
  • No benchmark numbers we did not measure on your hardware, with your documents.
GDPR / NEN 7510
Healthcare
Privilege
Legal
DORA
Finance
Data residency
Public Sector
Insurance
Manufacturing
Logistics
Energy
Accountancy
Pharma

For your security team

You are probably not the person who has to approve this.

Whoever has to sign it off will want the architecture, the data flow, and the governance answers in one place they can read without you in the room. This page is that document. Print it to PDF and send it on.

Questions

What your security team will ask.

01

Does any of our data leave our network?

No. The model runs on hardware you control, and inference happens locally. There is no outbound call to a model provider. In an air-gapped deployment there is no outbound path at all, and we document the full data flow so your security team can verify it rather than take our word for it.

02

Are local models good enough compared to the big cloud ones?

For the work most companies want, document search, summarising, drafting, classification, and internal Q&A, open models running on modest hardware are already strong enough to be useful every day. We test candidate models on your own documents during the pilot, so you judge quality on your work rather than on a benchmark.

03

What hardware do we need?

It depends on model size and how many people use it at once. A small team assistant can run on a single workstation-class machine. Heavier workloads want a dedicated GPU server. We size it during the assessment and tell you honestly when renting a private GPU is cheaper than buying.

04

How does this help with GDPR, NEN 7510, or DORA?

Keeping processing inside your own infrastructure removes the third-party processor, the international transfer, and the retention question in one move. We are not your compliance officer, but we give you the architecture documentation and audit logging your compliance officer needs to sign off.

05

What does it cost?

There are two parts: a fixed-price engagement to design and deploy the system, and a running cost that is either hardware you own or a monthly private GPU. We quote both after the discovery call, before you commit to anything.

06

What if we want to stop working with you?

You keep everything. The system runs on your infrastructure with open models and documented configuration, and your IT team gets the runbooks during handover. There is no licence to expire and nothing that stops working when we stop.

07

Do you replace our IT team?

No. We do the part they have not spent the last two years on, model selection, retrieval, deployment, and tuning, and we hand it over in a shape they can operate. Most of our work is alongside an internal team, not instead of one.

08

How quickly can we see something real?

A working pilot on your own documents usually takes two to three weeks after the architecture is agreed. The discovery call itself takes 45 minutes and costs nothing.

Next step

Tell us what your team is not allowed to do yet.

A 45-minute call. We look at your workflows, your data rules, and whether local AI is worth it for you. If it is not, we will tell you that instead of selling you a project.

Not ready for a call? Send the security brief to whoever has to approve it, or just reply to an email. All three work.

Work with us

Join SRI

We are not hiring right now, and we would rather say that than run a careers page full of roles that do not exist. If you build the kind of systems we build, introduce yourself anyway.