All resources

Heightened security in AI projects: when the standard setup is not enough

20 April 20265 min readSecurityComplianceOn-prem

For projects with especially sensitive data, we have two escalation tiers: routing Anthropic through the client's own cloud tenant, or local on-prem models. Here is how each tier works.

Most projects are well covered by our standard setup: European data storage, encryption at rest and in transit, role-based access, and audit trails. But some projects need more. Especially regulated sectors or projects with very sensitive personal data need extra layers. We offer two escalation tiers.

Tier 1: Anthropic via the client's own cloud tenant

Anthropic is available as a managed service on AWS Bedrock, Google Vertex AI, and Azure. That means model calls can be routed through the client's own cloud tenant instead of Anthropic's direct API. The result is that processing and audit trails stay inside the client's perimeter.

We pick the provider based on the client's existing stack. If the client already runs AWS as primary cloud, we use Bedrock. Microsoft shops use Azure. Google shops Vertex. Functionally the Anthropic models are the same. Control and audit properties are extended.

Tier 2: Local on-prem models

For clients with explicit on-prem requirements or particularly high security demands, we deploy local open models (typically from the Llama or Mistral families) in the client's own infrastructure. No model calls leave the client's physical perimeter.

This is a premium delivery. It comes with higher setup cost, ongoing model infrastructure maintenance, and somewhat lower model quality than top commercial models. It is worth it when regulatory or commercial requirements demand it, not as a default.

Which tier fits where

Most projects need neither. The standard setup with European servers and the Anthropic API meets the bar for most mid-market businesses. Heightened measures are evaluated when data includes financial, health, or other particularly sensitive information, or when sector regulation explicitly requires it.

Cost and delivery

Both tiers are delivered as adaptations on the Own model. Price is set by scope, infrastructure setup, and ongoing operations. The Discovery phase maps whether this is necessary for your project.

More info

The details on security measures, providers, and DPAs live on /trust.