Use case & data assessment
Which use cases, which data, which confidentiality requirements — and what that means for architecture.
AI
Many organizations want AI to work with internal documents, but cannot send confidential information to public AI services. We help you plan and secure private AI setups — from self-hosted models to controlled knowledge access — and govern them properly.
Which use cases, which data, which confidentiality requirements — and what that means for architecture.
Self-hosted models, private cloud or European providers — compared by control, effort and capability.
Retrieval over your knowledge that respects existing permissions and data classification.
Who may use which AI function on which knowledge — integrated with your identity management.
Assessment of risks such as prompt injection, data leakage and model misuse, with appropriate controls.
Logging, monitoring, responsibilities and documentation — so the AI setup is auditable.
Start with concrete tasks the AI should help with — and the data involved.
Confidentiality, data residency, regulatory and performance requirements.
Choose deployment and components that fit — as simple as possible.
Access control, isolation, logging and AI-specific safeguards.
Integrate into ISMS, AI governance and employee guidance.
European where possible. Open where practical. Integrated with what already works.
Private AI is about control: over data, access and dependencies. We favour open models, self-hosting and European providers where they meet your requirements — and say clearly when they do not.
Realistic expectations
Self-hosted AI involves trade-offs in capability, hardware and operating effort. We help you decide where private AI makes sense and where a well-governed external service is the better choice. We do not operate a managed AI hosting service; we help you plan, secure and integrate your setup.
Private AI means using AI models in an environment you control — so that prompts, documents and results are not processed by a public AI service in an uncontrolled way. This can be a self-hosted model, a dedicated private-cloud deployment or a contractually and technically restricted service.
Self-hosted AI means running AI models — for example open-weight large language models — on infrastructure you operate or control. Data does not leave that environment. The trade-off is operating effort and, depending on the model, capability.
Retrieval-augmented generation (RAG) lets an AI model answer questions using your own documents. “Secure” RAG adds the controls that make this safe in an organization: respecting permissions, classification, logging and protection against manipulated content.
Get an overview of AI use, set clear rules, assess risks and prepare for the EU AI Act and ISO/IEC 42001 — without creating another silo.
Build a working ISMS and prepare for ISO/IEC 27001 certification — together with your team and on top of the tools you already use.
When a gap is identified, we help you find the most appropriate measure: existing technology, process, open source or a suitable vendor.
Related in the FeldmannCyber App: ISMS AI Assistant
What AI governance means, what ISO/IEC 42001 is, what the EU AI Act requires after the 2026 Digital Omnibus amendment, and how both connect to an existing ISMS.
Tell us about your use cases and data. We will help you find a sensible architecture.