SaaS & AI products
The token bill grows faster than MRR, an engineer answers first-line tickets and every enterprise deal stalls three weeks in the security questionnaire. Open models, a flat rate and inference in Europe or on your own infrastructure.
What each regulation in your sector requires, and which part of that the deployment solves.
A processor engages sub-processors only with the controller's authorisation and under the same obligations.
A European sub-processor in your annex, with inference in the EU or on your own infrastructure. Prompts and responses are never stored.
Article 50 transparency towards end users and obligations when integrating a general-purpose model.
Open models with published model cards and licences, plus an audit trail of every query to document what your product answered.
Switching between data processing service providers and effective portability of data and applications.
OpenAI-compatible API and open weights: your exit plan does not depend on us, and you export your data and indexes.
Risk management measures and incident reporting for digital service providers within scope.
An auditable EU provider, with access control per user and per team and a record of every query for your supply chain.
The same ones you already use, specific to your sector.
The first version of the feature shipped in two sprints, calling a third-party API. A year later, what reaches standup is always the same:
Token spend grows faster than MRR.
FinanceI have an engineer answering first-line tickets.
Support engineeringA deal has been stuck three weeks in the security questionnaire.
PresalesThe docs run two releases behind the product.
Technical writingThey swap the model underneath and my prompts stop working.
ProductMy sub-processor annex lists a provider outside the EU.
TechnologyA large customer will not sign if data leaves their cloud.
FounderOur record as a European sub-processor: what service we provide, where inference runs, what dependencies it has and what data is handled. With an on-premise deployment we are not in the chain at all, because the model runs on your infrastructure. Keeping the annex, the record of processing and the controller's authorisation stays with you.
No. The API is OpenAI-compatible: change the key and the base URL of the client you already use and the rest of the code stays put. What usually needs tuning are the prompts, because the open model you pick answers in its own style.
The rate is flat, so cost does not scale with request volume or prompt length. On a dedicated or on-premise deployment the ceiling is the capacity you have provisioned, and expanding it is planned ahead.
On European infrastructure we manage, or on-premise on your own or your customer's infrastructure. The API is the same in all three cases, so a customer with a sovereignty requirement is served by the same product code.
The deployment record: where inference runs, what data is handled, what dependencies there are, how access is controlled per user and per team and what is logged for every query. A good share of the rows repeats across customers, so the assistant drafts the answers from your previous ones and your team reviews. What your company signs, your company signs.
Yes, with the same key. There the query does go out to the model provider, so that part comes back into your sub-processor chain and has to be declared. For your users' data you work with the open models inside the perimeter.
Nobody on our side: prompts and responses are never stored or used to train models. Inside your team, access is controlled per user and per team, with a record of every query you can review and export.
The models are open and the API is OpenAI-compatible, so leaving comes down to pointing the client at another endpoint. You can take the weights with you and your data and indexes are exportable.
In the demo we go through your case: which models you need, where they run and what it takes to meet the regulation that applies to you.
We reply within one business day.