The question is not “which model”, it is “where does your data run”.
Hosting in the European Union, deployment on your own hardware, or a hybrid architecture depending on each corpus's sensitivity. Operating costs are quantified at scoping, capped and monitored.
- EU by default
- On-premise available
- Costs capped
Three decisions deferred until they block everything
They get made badly at the end of a project, under pressure from the security committee.
Where the data is
The question reaches the security committee three weeks before go-live. The answer determines the architecture, so it should have been asked at scoping.
What it will cost in use
The pilot costs little. Production at scale sometimes costs ten times more, and nobody quantified it before committing.
What happens if the vendor changes
A model changes price, terms or availability. An architecture tied to a single vendor then has no exit.
The options, and what they imply
There is no universal right answer. There is one answer per corpus, depending on its sensitivity and volume.
SaaS hosted in the EU
Our infrastructure, in the European Union. Fast to start, monitoring and updates included.
Your cloud
Deployed in your own cloud environment, under your contract and governance.
On-premise
On your hardware, on your premises, including without an internet connection where the corpus requires it.
Self-hosted models
Open models running on your infrastructure, when no data may reach a third-party service.
Hybrid architecture
Sensitive corpora handled internally, the rest on external services. The boundary is defined with you.
GPU sizing
Assessment of the hardware genuinely required for your volume and latency — often less than what is sold.
SaaS or on-premise: what actually changes
The choice is made on corpus sensitivity and your capacity to operate, not on a matter of principle.
| On-premise / private cloud | SaaS hosted in the EU | |
|---|---|---|
| Where the data sits | Your servers, your premises, under your exclusive control | Our infrastructure, in the European Union |
| Time to go live | Longer: hardware, network and security to prepare | A few days |
| Cost | Upfront investment, then controlled operating cost | Subscription, no hardware investment |
| Operations | Your teams, or us under a managed-service contract | Included: monitoring, backups, updates |
| Offline operation | Possible, including with no external connection at all | No |
| When to choose it | Regulated corpus, sensitive personal data, contractual constraint | Fast start, non-sensitive corpus, no operations team |
Our principles
Each has a direct consequence on what the system will cost you, and on your freedom to change your mind.
- EU by default
- No transfer outside the European Union without your explicit agreement, written into the contract.
- No single vendor
- The architecture allows the model to be changed without rewriting the system.
- Capped costs
- Volume, frequency and cost limits per run, set at scoping and monitored.
- No training on your data
- Your data never trains a model, whatever the deployment mode.
- Reversibility
- You can take over or change supplier: you own the custom code.
- Measured sizing
- Hardware is sized on real measurements, not on a comfort margin sold in advance.
What the infrastructure scoping produces
- An architecture recommendation per corpus, according to its sensitivity
- The hardware sizing genuinely required, measured rather than estimated
- Costing of operating expenses, with the proposed caps
- A map of data flows and any transfers
- The reversibility plan: how to change model or supplier
- The documentation the security committee needs
Frequently asked questions
In the European Union. No transfer outside the EU without your explicit agreement, written into the contract.
Yes, with self-hosted models on your hardware. That is the standard case on the most sensitive corpora.
It depends on volume and expected latency, and it is often less than you will be offered elsewhere. We size on real measurements, at scoping.
Volume, frequency and cost caps per run, set at scoping and monitored in production. That is contractual, not declarative.
No. The architecture allows the model to be changed without rewriting the system — a design decision, made up front.
Yes, under contract, including on your own hardware. That is often the right answer when you want on-premise without having the team to run it.
What this solution does not do
On-premise is not always the right choice. Without a team able to operate the infrastructure, it produces a system nobody updates, which is a more serious security risk than well-managed external hosting. We also do not oversell hardware: in many cases the real requirement is far below what you will be offered elsewhere, and we measure before recommending.
Is your data allowed to leave?
That question determines the whole architecture. Better answered at the diagnostic than at the security committee, three weeks before go-live.