Trust

Trust based on facts, not on promises.

Every vendor says their AI is trustworthy. We built Empisto so trust comes from its architecture and design. Your data never leaves your infrastructure. Access runs through your own login system, keys are kept in a separate vault, and your data has no path out.

verifiable · licence-based · no egress · open to audit

Our commitments

Three promises we can be held to.

01

Nothing leaves your infrastructure

Your data has no path out. The models, the retrieval index, and every app run inside your network, and air-gapped installs are supported.

02

The models run on your own machines

Nothing is rented from an outside AI service, so nobody is billing you per token. You buy a licence and support, and heavy use costs exactly the same as light use.

03

Open to independent audit

We invite outside auditors to check how we process data and how the system uses the network. That way trust rests on evidence, not on our word.

Compliance

Designed for regulated environments.

GDPR

Because data never leaves your control, personal data stays in line with legal requirements and data residency rules.

EU AI Act

On-premise deployment keeps the models, the data, and the records inside your boundary, which matches the transparency and oversight duties the Act introduces.

Client NDAs

Confidential client material is processed in place, so confidentiality is kept by design.

Data residency

Your data is where your infrastructure is, on your terms and under your oversight.

Access and keys

Who gets in, and where the keys are kept.

Two questions your IT people will ask first. The short answer: once sign-in is switched on, nobody sees anything inside Empisto without signing in.

People sign in the way they already do

Empisto uses the work account your people already have, through the login system you already run. Nobody gets another username and password to look after. When someone leaves and IT switches their account off, their access to Empisto ends at the same moment.

We never hold your staff passwords

There is no list of passwords here for anyone to steal. When someone signs in, your own login system vouches for them, and Empisto checks that the answer genuinely came from your system before letting anyone through.

Saying who you are is not enough

A claim on its own proves nothing here. Empisto accepts an identity only when it carries a valid stamp from your login system, and it checks that stamp every single time. A site with no internet connection can still check it, because everything needed to do so sits inside the building.

Keys live in a safe, not in the software

Database passwords, licence keys and the keys that reach your models are kept in a separate safe. They are handed out only when something needs one. None of them is written into Empisto’s own files, and none can be read back out from inside the product.

How we prove it

Read the details, or put us to the test.

The architecture paper explains where the data boundary sits and what a deployment looks like. If you would rather see Empisto running in your own environment, join us as a design partner.