Security and compliance first
Open-source AI,built secure from day one
Security and compliance are where we start, not a review at the end. We build on trusted open-source platforms, host them inside your environment, and design every system against SOC 2, ISO 27001 and ISO 42001 controls, so your data stays yours and your auditors have the evidence they need.
What sovereign means in a build.
Not a slogan on a slide. Four things that are true of the system on the day it goes live, and that your security team can check.
Data stays in your jurisdiction
Inference pinned to the region you choose, or run on hardware you own. Prompts, documents and outputs never cross a border you did not approve.
Open-source, self-hosted platforms
Proven open-source platforms run in your own environment. Code your team can inspect, and no single vendor who can change the terms under you.
You hold the keys
Your tenancy, your credentials, your encryption. We build inside your environment and hand it over, so nothing depends on us staying in the loop.
A human signs off
Agents read and draft. Anything that changes a system waits for a person to approve it, and every read and every action is logged.
The open-source platforms we build on.
Mature, widely used and fully inspectable. We deploy them in your cloud or on your hardware, lock them down to your access policies, and connect them to the models you approve.

Open WebUI
A private, ChatGPT-style workspace your team signs in to, running on your own servers against the models you approve.
Dify
Visual builder for agents and AI workflows, self-hosted so every prompt, tool and log stays inside your perimeter.
RAGFlow
Retrieval over your own documents with cited answers, so staff can check the source behind every response.
LangChain
The open framework we use to wire models to your systems, with every tool call scoped, logged and reviewable.
Built to the standards your auditors ask for.
We run SOC 2, ISO 27001 and ISO 42001 on one control set, inside Sentry AI first, then in the systems we build for you. All three are in progress for Sentry AI; we mark each certified only once it is independently confirmed.
SOC 2 Type II
The control set enterprise procurement asks for first. We run our own programme against it and build client systems that evidence the same controls: access, change management, logging, vendor review.
In progressISO/IEC 27001
Our ISMS is established and its controls are being evidenced now, on the same control set as SOC 2. It is the standard banks across Australia, NZ and Asia ask for by name.
In progressISO/IEC 42001
The first certifiable standard for governing AI. We are taking Sentry AI through it ourselves, and it is the framework we use to inventory, risk-rate and oversee every AI system we build for clients.
In progressProven where the data is most sensitive.
Patient records and customer accounts. Two production builds in regulated industries, both still running.

Sovereign Claude across 15 healthcare practices
Every inference pinned to Australia on AWS, from reception to the board, for a network serving 180,000+ patients.

9 in 10 inbound calls automated for a finance firm
A verified voice agent for an Auckland debt-recovery firm, answering from live account data, with CrowdStrike integrated to protect the systems it runs on.
Need AI that stays inside the lines?
Tell us where your data has to live and who has to sign off. We will show you what we can build inside those limits.
Book a call