Services · 01 - Flagship
AI that survives a security review.
Who this is for.
Regulated organisations that need AI in production, not another pilot that stalls at infosec. Banks. Insurers. NHS-facing teams. Public-sector buyers. Professional services firms whose clients won’t accept their data being processed in someone else’s tenant.
If a security questionnaire has ever ended a procurement, this is the engagement that prevents it next time.
What you get.
A working application on your infrastructure, with:
Tenant data isolated at the database
PostgreSQL row-level security, with a cross-tenant test suite proving it table by table.
Every AI interaction logged and governed
Which persona, which model version, which prompt, which output, which user, when.
Documented architecture
Security model, data flow, model and persona governance, audit trail design.
The Assurance Pack
A structured evidence bundle that answers the questions enterprise security and public-sector assessments actually ask.
The source code, in your repository
No proprietary runtime, no captive SaaS.
We can operate it for you under Managed Run afterwards, or hand it over to your team cleanly with a runbook and an evaluation harness.
Why it’s different.
Isolation is enforced by PostgreSQL row-level security, one layer below the application, where a single bug in application code can’t quietly leak data across customers. We prove it with a cross-tenant test suite that runs against every table, on every change.
That single architectural choice changes the conversation with infosec, with procurement, and with the auditor. It’s why the engagement is called “Governed AI Delivery” rather than “AI build”. The governance is the deliverable, not an afterthought.
Why it passes a security review →How we deliver fast.
Three things, working together.
A hardened foundation underneath every project.
We start every engagement on top of Prototypical, our application foundation. It deploys into your own environment and supports multi-tenancy inside it where the application calls for it. Database-enforced isolation, audit backbone, durable job queue, provider-agnostic AI gateway: all there on day one. We build the parts that are actually about your problem, not the foundations beneath them.
Senior engineers with AI-assisted development.
Our engineers are senior, and they pair with frontier coding assistants every day. A working prototype in the first week. Production code in weeks, without the failure modes of foundations rushed under time pressure.
Governance designed in, not bolted on.
The audit log, the evaluation harness, the persona governance, the isolation tests: all scaffolded from the first commit. By the time you reach the security review, the answers already exist.
A typical engagement.
A typical stack.
The shape varies by problem. A common configuration:
A modern web framework - the Prototypical default - or the front-end your team already runs, where that fits better.
TypeScript or Python services, containerised, deployed on Azure, AWS, GCP or your own data centre.
PostgreSQL with row-level security and pgvector for retrieval; object storage for unstructured content.
Anthropic, Azure OpenAI, Google Vertex; open-weights options where cost, latency or sovereignty demand it.
OpenWeave for long-running, resumable agent work; lighter orchestration for simpler flows.
Persona Factory for governed, versioned personas, served over the Model Context Protocol.
Engagement shape.
Prototype Sprint (2-4 weeks) or Design & Build (6-14 weeks).
Working application in production on your infrastructure; cross-tenant test suite; Assurance Pack; source code yours.
Product lead + designer + senior full-stack + AI engineer + DevOps.
Managed Run, capability transfer, or expansion to further applications.
What are you trying to put into production?
If you can describe the problem and the constraint, we can scope a prototype in two weeks.