Enterprise AI. Defined boundaries.

We design, build and operate AI systems inside a perimeter you control. The steady work runs on infrastructure you hold. Peak demand is rented, metered, and switched off when the peak passes.

Runs on your infrastructure
Steady, predictable, always on
  • Assistants over your own documents
  • Model weights you host and control
  • Retrieval index and embeddings
  • Encryption keys and identity
  • Prompt, access and audit logs
Rented when you need it
Bursty, occasional, metered
  • Evaluation and fine-tuning runs
  • Seasonal or launch peaks
  • Frontier models for narrow tasks

The split is written down, enforced in the network path, and reviewed as workloads change.

You hold the keys Credentials, certificates and encryption material stay under your administration, not ours.
Your material is not training data Base workloads run against models hosted inside your environment, so the documents behind an answer are never submitted to an outside provider that could train on them.
Licensed without royalties We deploy open-weight models under Apache 2.0 or MIT terms: commercial use with no per-token fee, no user cap and no revenue share.
Runbooks at handover Architecture, monitoring and recovery procedures are documented and yours to keep.

Keep the steady load. Rent the peak.

Most enterprise AI spend goes on renting capacity for work that runs at a flat, predictable load all year. That is the part worth owning. The rest is worth renting well, on terms written down in advance.

The steady load

The everyday workload: retrieval over your contracts, policies, incident history and drawings. It runs in colocation, a secure room, bare metal or an isolated cloud tenancy configured without training egress.

The peak

Evaluations, fine-tuning, a quarter-end surge. Rented deliberately, with the scope of data that crosses the boundary defined before the first call is made.

The split

Someone has to decide which workload sits on which side, document it, and enforce it in the architecture. That decision, and the engineering that holds it in place, is what we sell.

What we put inside the boundary

A production stack, not a proof of concept. You hold the keys, the logs and the runbooks at handover.

Document assistants

Question answering across contracts, personnel files, incident reports, drawings and operating procedures, with answers that cite the source document.

Retrieval and indexing

Ingestion, chunking, embeddings and refresh jobs, kept current as your document set changes.

Scoped agents

Task automation with explicit permissions, human approval on consequential steps, and an audit trail of what was called and why.

Model serving

Open-weight models sized to the hardware, with a gateway that routes each request according to the split you agreed.

Model licensing review

We check the licence attached to every model before it reaches production and default to Apache 2.0 and MIT terms, which carry an explicit patent grant and no usage restrictions. Where a vendor community licence is the better technical fit, you see its conditions in writing first.

Controls and evidence

Identity, network path, retention, logging and monitoring, documented so your auditors and your customers can see how the system behaves.

How an engagement runs

Four stages. Each one ends with something you own, and you can stop after any of them.

01

Assess

A half-day working session on one real workflow: the data it touches, who may see it, and the controls it needs. You leave with a written architecture and a fixed-scope build proposal.

02

Design

Models, retrieval, network path, identity, logging and the boundary itself, specified and reviewed before anything is racked.

03

Build

The stack goes into your environment. Handover includes runbooks, monitoring, a rollback path and the keys.

04

Operate

Patching, model updates, retrieval maintenance and light on-call under a monthly retainer, or a clean handover to your team and we step back.

Where we fit

Engagements run remotely, in English or Portuguese, wherever your infrastructure sits.

A good fit

  • Teams with at least one person or a managed provider running IT
  • Sensitive material already in the business: contracts, client and patient records, claims, incidents, drawings
  • Legal, healthcare, financial services, real estate, and data center and colocation operations
  • A regulator, a customer or a contract that asks where the processing happens

Not a fit

  • Training a foundation model from scratch
  • A chatbot on a fixed low budget with no data work behind it
  • Eighty-page tenders and twelve-month procurement cycles

If the honest answer is that a managed service already covers your case, we will say so on the first call.

Tell us what you want to run

Describe the workflow and where it would live. You get a reply from the person who would run the engagement, not a sequence.

Prefer email? Write to info@keepference.com.

Start a conversation

Sends to info@keepference.com. We use what you write to answer you, and nothing else.