Skip to content

Sovereign AI consultancy

Own your intelligence. Not a licence to it.

We build AI systems that run on hardware you already own, or in a cloud tenant registered in your name. Local models, tuned on your own material, for firms in technology, finance, law and supply chain. The file never leaves the building.

14-day diagnostic · written brief · risks · deployment price

Runs on

  • Llama
  • Mistral
  • Qwen
  • DeepSeek
  • Gemma
  • Phi
  • vLLM
  • Ollama
  • llama.cpp
  • NVIDIA
  • Hugging Face
  • Kubernetes

The premise

Everything useful a firm knows is already written down.

The model goes to the file.

Everything useful a firm knows is already written down — in packs, mail and working papers. When that material cannot leave the building, the model must go to the file. We draw the boundary once, and the work happens inside it.

The offer · 14 days

Two weeks inside the practice. You leave with a brief and a price.

No installation, no procurement, no platform commitment. Two weeks of access to the process that hurts, and a written answer at the end of it.

See how the two weeks run
  1. 01Where the material actually livesMapped
  2. 02What must remain a human signatureListed
  3. 03The runtime, and where it sitsNamed
  4. 04Risks we found, in plain languageWritten
  5. 05Price to install, price to keep runningQuoted

If a sample file is required to write an honest brief, it is listed, time-boxed, and destroyed on the last day. The destruction is written down. Nothing is installed until you say so.

Production-grade AI without the production-grade exposure.

Built for firms that cannot send their files away.

The data never leaves

EgressNoneCorpusIn place
YOUR BOUNDARYMODELVENDOR API
The model is brought to the material. The material holds still.

No third-party API. No shared tenancy.

Packs, matters, mail and working papers stay in the room they are already in. There is no copy of your corpus anywhere we can reach, because there is nowhere for it to go. The model is brought to the material, and the material holds still.

Your hardware, or your tenant

CustodyClientOperator accessWhile engaged
  • On-premiseHardware you already ownA GPU host in the office or the firm's own rack. Nothing to procure but the model.
  • Private tenantA cloud account in your nameYour subscription, your keys, your invoice. We hold operator access only while engaged.
  • Air-gappedNo route out at allFor matters where the network is the risk. Updates arrive by hand, signed and logged.
ResidencyIn-countryIn-regionIn-buildingIn-room
You can end the arrangement without moving a single file.

Their keys, their bill, their jurisdiction.

On machines the practice already owns, on-premise in the office, air-gapped in a secure room, or in a cloud tenant registered in the client's own name. We design and operate it. You hold it, and you can end the arrangement without moving a single file.

Tuned on your own material

vault-eu-01 — local

$ vesh run finetune --corpus /vault/matters --base qwen2.5-14b --egress deny

  • Corpus mounted read-only12,481 documents
  • Egress policy verifiedno route to internet
  • Tokenised in place41.3M tokens
  • epoch 1/3loss 1.42
  • epoch 2/3loss 1.06
  • epoch 3/3loss 0.88
  • Adapter written/vault/models/house-14b
  • Nothing left the boundary0 bytes egress
Trained in place. Never uploaded.

An answer in the language of the house.

Small models fitted to the document types you actually handle, trained in place and never uploaded. The answer arrives in your firm's register and points at the page it came from, so a reviewer can check it in seconds rather than reading it twice.

Auditable and measurable

TraceCompleteEgressNone

Question

What indemnity cap applies to the Meridian supply agreement?

Answer

Liability is capped at 125% of fees paid in the preceding twelve months, excluding wilful default.

  • Meridian_MSA_2024.pdfcl. 11.4, p. 23
  • Meridian_Side_Letter.pdfpara 3, p. 2
  • Amendment_No2_signed.pdfcl. 2.1, p. 1
Retrieved from
vault-eu-01 (on-premise)
Model
house-14b · local adapter
Egress
none
Signed off by
awaiting reviewer
You can prove what it saw, what it said, and who signed it.

Every answer points at a file and a page.

Request logs, retrieval traces and per-answer citations, all held inside your boundary. You can prove what the system saw, what it said, and who signed it off — which is the difference between a tool a regulated firm can adopt and one it cannot.

Practice areas

Domain depth, not a general-purpose chatbot.

The same runtime underneath, fitted to the document types each practice actually handles. We work primarily in technology, and in the regulated functions where the file cannot travel.

Engineering organisations

Ten years of decisions locked in a repository nobody is allowed to paste anywhere.

  • Code intelligence on private repositories

    Ask questions across a codebase that cannot leave the network. Retrieval runs against your own index, on your own hardware, with no source in flight.

  • Incident review

    Postmortems assembled from logs, tickets and chat inside the perimeter, with each claim pointing back at the artefact it came from.

  • Institutional memory

    The design decisions of people who have left, made answerable again — including the reasoning that never made it into a document.

  • Specification to test

    Draft coverage from the specification in your house idiom, for your engineers to review and own.

Security

Stable, secure and compliant.

Regulated work has a vocabulary, and a deployment that cannot answer to it is not a deployment. Because the system runs inside your perimeter, it inherits the controls you already hold rather than adding a processor for your auditor to assess.

Met by construction

  • HIPAA

    Protected health information

    PHI never transits a third party. There is no business associate agreement to negotiate, because there is no vendor in the data path to sign one.

  • GDPR

    Personal data and residency

    Processing stays in the territory you name. No international transfer, no adequacy question, and no sub-processor list to keep current.

  • SOC 2

    Security, availability, confidentiality

    Request logs, retrieval traces and access records are produced inside your boundary, in the form your Type II evidence already takes.

  • ISO 27001

    Information security management

    The runtime slots into the management system you already operate: your asset register, your access reviews, your change control.

Vesh AI does not host your data. The system is installed inside your compliance boundary and operated under your policies, which is why these regimes are met by controls you already hold rather than by a certificate of ours. Where you need evidence of our own practices during an engagement, we put it in writing.

Illustrative missions

Our engineering. Your practice.

Five places where the same sovereign stack can earn its keep. These are representative applications, not a client list.

Start

Tell us what the next painful week looks like.

A briefing is a conversation, not a pitch. Bring the process that costs you your evenings, and we will tell you plainly whether this helps — and if it does not, what would.