Your Data. Your Infrastructure.
Your Rules.
I build AI systems that run on your own servers, in your cloud account or with no external connection at all. Your clients will open their test results and SCADA logs only to a supplier they trust; that is step 3 of the approach, and this page is what the trust rests on. Your compliance team signs off, not mine.
Deployment Options
Every option does the same job. The difference is where the boundary sits.
On-Premises
Full deployment inside your data centre. No external network calls, complete physical and logical control.
VPC / Private Cloud
Deployed in your AWS, Azure, or GCP environment — your account, your keys, network-level isolation.
Air-Gapped
No external connection at all: local models through Ollama, able to sit on a SCADA or OT network.
Hybrid
On-prem processing with selective cloud services — you define what stays local and what can cross the boundary.
This site runs on Cloudflare Workers, D1 and R2; that is my choice for my platform, not a requirement for yours. Client deployments run on whatever you specify: AWS, Azure, GCP, bare metal or your own on-prem stack.
Data & Models
Where your data lives and which models read it are both your decision, and both are written down.
Audit, Compliance & Source Code
Every system I build logs what it did and who asked it to. Each request carries a timestamp and a hash of its input and output; the log is append-only, permission changes go into it as well, and a GDPR data-subject request can be answered from the application rather than from a database export nobody wants to run. None of that makes a system ‘compliant’. Compliance is a finding your auditor reaches about your deployment; what I can promise is that the evidence already exists, so an audit under SOX or NERC CIP finds the trail rather than a reconstruction of one.
Where the code runs decides which certifications apply, and none of them transfers to the application by itself. Cloudflare publishes SOC 2 Type II and ISO 27001 reports for the infrastructure this site uses; a deployment inside your AWS, Azure or GCP account inherits that provider's attestations instead. The application supports the controls, the platform certifies the substrate, and your compliance team joins the two. I design to the IEEE and IEC standards that govern the equipment in the room, and the drawings name them.
You receive the source for everything I build: no compiled binaries, no obfuscation, nothing your security team must take on my word. The repository can go into escrow if business continuity requires it, and any maintenance agreement is optional. Walk away when you like, or stay because it works.
Need a Security Overview for Your Team?
Book a call and I will walk your security and compliance team through the architecture, the data handling and the deployment options before any of your clients' data moves.