SaaS & AI products

AI features inside your product, without your customers' data leaving Europe.

The token bill grows faster than MRR, an engineer answers first-line tickets and every enterprise deal stalls three weeks in the security questionnaire. Open models, a flat rate and inference in Europe or on your own infrastructure.

The rules that apply to you, point by point

What each regulation in your sector requires, and which part of that the deployment solves.

GDPR

Regulation (EU) 2016/679, art. 28
What it requires

A processor engages sub-processors only with the controller's authorisation and under the same obligations.

How we solve it

A European sub-processor in your annex, with inference in the EU or on your own infrastructure. Prompts and responses are never stored.

AI Act

Regulation (EU) 2024/1689
What it requires

Article 50 transparency towards end users and obligations when integrating a general-purpose model.

How we solve it

Open models with published model cards and licences, plus an audit trail of every query to document what your product answered.

Data Act

Regulation (EU) 2023/2854
What it requires

Switching between data processing service providers and effective portability of data and applications.

How we solve it

OpenAI-compatible API and open weights: your exit plan does not depend on us, and you export your data and indexes.

NIS2

Directive (EU) 2022/2555
What it requires

Risk management measures and incident reporting for digital service providers within scope.

How we solve it

An auditable EU provider, with access control per user and per team and a record of every query for your supply chain.

Your most common use cases

The same ones you already use, specific to your sector.

See all use cases

Your product already has AI in it.
And a cost line that grows with every new user.

The first version of the feature shipped in two sprints, calling a third-party API. A year later, what reaches standup is always the same:

What happens today

Token spend grows faster than MRR.

Finance

I have an engineer answering first-line tickets.

Support engineering

A deal has been stuck three weeks in the security questionnaire.

Presales

The docs run two releases behind the product.

Technical writing

They swap the model underneath and my prompts stop working.

Product

My sub-processor annex lists a provider outside the EU.

Technology

A large customer will not sign if data leaves their cloud.

Founder

With Inferana

Flat rate: usage of the feature multiplies and the cost line stays where you put it in the budget.
A first-line assistant inside your product answers from your documentation, and the engineer only picks up what escalates.
Deployment record, an audit trail of every query and access control per user and per team, ready for the questionnaire.
The assistant answers from the documentation you have published, and the questions it cannot answer point at the gap.
Open weights and a pinned version: the model serving your product changes the day you decide it does.
A European sub-processor in your annex, with inference in the EU and no prompts or responses stored.
On-premise deployment on that customer's infrastructure, with the same API and the same product code.

Sector FAQs

Our record as a European sub-processor: what service we provide, where inference runs, what dependencies it has and what data is handled. With an on-premise deployment we are not in the chain at all, because the model runs on your infrastructure. Keeping the annex, the record of processing and the controller's authorisation stays with you.

No. The API is OpenAI-compatible: change the key and the base URL of the client you already use and the rest of the code stays put. What usually needs tuning are the prompts, because the open model you pick answers in its own style.

The rate is flat, so cost does not scale with request volume or prompt length. On a dedicated or on-premise deployment the ceiling is the capacity you have provisioned, and expanding it is planned ahead.

On European infrastructure we manage, or on-premise on your own or your customer's infrastructure. The API is the same in all three cases, so a customer with a sovereignty requirement is served by the same product code.

The deployment record: where inference runs, what data is handled, what dependencies there are, how access is controlled per user and per team and what is logged for every query. A good share of the rows repeats across customers, so the assistant drafts the answers from your previous ones and your team reviews. What your company signs, your company signs.

Yes, with the same key. There the query does go out to the model provider, so that part comes back into your sub-processor chain and has to be declared. For your users' data you work with the open models inside the perimeter.

Nobody on our side: prompts and responses are never stored or used to train models. Inside your team, access is controlled per user and per team, with a record of every query you can review and export.

The models are open and the API is OpenAI-compatible, so leaving comes down to pointing the client at another endpoint. You can take the weights with you and your data and indexes are exportable.

Tell us what you want to deploy and we will show you where Inferana fits.

In the demo we go through your case: which models you need, where they run and what it takes to meet the regulation that applies to you.

We reply within one business day.