Private AI Infrastructure

AI THAT STAYS
IN THE BUILDING.

Not a ChatGPT wrapper. Not a consultant with a monthly retainer. A private server that reads your business's documents where they live — and decides, file by file, what any AI is ever allowed to see.

By CabraVerde · Engineered to be yours

Register for updates See How It Works
Status:
In Plain English

AIS is a private AI server you install on your own network. It reads your documents, classifies every file for sensitivity, and gives each department an AI assistant that answers from your own archive — no training, fully auditable.

Designed to run with no cloud dependency for core work. The hardware is yours. The models run locally by default — anything going to cloud goes masked by default, and raw cloud happens only by explicit, logged override.

What it actually does

CONNECT. LEARN. ANSWER.

Connects to
  • Email — inboxes, sent items, attachments
  • Documents — PDFs, spreadsheets, internal files
  • Line-of-business systems — connectors in build
  • Wherever operational knowledge actually lives
Learns
  • Operational archive — searchable across years, not sessions
  • Per-department agents answering from your own documents — sources cited
  • An archive that gets sharper every week — each confirmed decision is written back to the engine
  • Audit trail — every classification, masking and routing decision logged
Answers
  • Fewer repeated questions
  • Faster onboarding — new starters search years of documents from day one
  • Less knowledge trapped in inboxes
  • An archive that grows more useful every month you feed it
The Problem With AI Advice

EVERY AI CONSULTANT IS SELLING YOU THE SAME THING.

A subscription. A wrapper around someone else's model. Your data processed on a server you'll never see, owned by a company you've never heard of.

AIS is hardware you own, software that answers from your own archive — not a generic version of your industry — and a routing engine that decides what any AI is allowed to see. Local by default.

01

Your data has left the building

Every prompt to a public AI API is your business intelligence — supplier terms, financials, HR — processed on someone else's infrastructure.

02

It doesn't know your business

Generic AI knows about businesses like yours. It doesn't know what Sarah in accounts quietly fixes every month-end, or the workaround Dave built that nobody wrote down.

03

Every session starts from zero

Cloud AI has no memory. The context you built last time is gone. Your institutional knowledge disappears the moment you close the tab.

04

The consultant isn't staying

They deliver a demo. Your team nods. Nobody owns what happens next. Three months later it's been quietly abandoned.

05

Your team won't trust it

Cloud AI runs on infrastructure owned by someone whose interests are not yours. Manager can audit every prompt. IT can pull the logs. So your team gives it the surface. Never the truth. Every other AI tool dies here.

System Architecture

FIVE LAYERS.
EACH DOES ONE JOB.

Hardware, core, agents, memory, dialogue. Strictly partitioned. Ownership explicit at every layer.

Layer
Function
Owner
The Box
Hardware on your premises · M4 Mac Mini default · yours from day one · air-gap capable
Customer
AIS · Core
Archival Intelligence Systems
Routing · retrieval · governance · provenance · audit · the brain inside The Box
AIS
Agents
Per-department specialists · run on local models · one role each · scoped to their enclosure · cloud work masked by default
Customer
Enclosure
Department context boundary
The context barrier · one enclosure per department or knowledge area · each agent's access ends at its enclosure boundary
Customer
Dialogue
The conversational interface · how you and your team talk to the system · optionally supplied as a consulting layer by CabraVerde
Optional

The line is clean. You own The Box, the agents that run on it, and the enclosures they work within. AIS routes, classifies, and keeps the audit. The consulting layer is optional — buy AIS standalone if you want to run it yourself.

The Dialogue Layer

HOW YOU TALK TO IT.

AIS is a system. People still need a way in. The dialogue layer is the conversational front-end that runs on top of AIS — installable as part of the standard deployment, or replaced by CabraVerde's consulting layer if you want a guided onboarding and a human in the loop.

Always

On. Local by default. Answering from your own indexed archive. Each agent scoped to the enclosure you assign it.

Never

Generic. Trained on someone else's business. Sent to the cloud raw by default. The same instance in two different deployments.

The line

The dialogue layer is optional. The Box, the Core, the agents, and the enclosures are not. Buy AIS standalone if you'd rather provide the dialogue layer yourself, or take CabraVerde's version if you want it managed end to end.

How It Works

EVERY FILE JUDGED
AT THE DOOR.

Most AI tools ingest first and ask privacy questions later. AIS reads your archive where it lives, decides what any AI is allowed to see — file by file — and writes every decision down.

01

AIS EATS YOUR ARCHIVE

PDFs, email exports, spreadsheets, scans, photos, voice notes — detected by what they actually are, not what the file extension says. Bring it as you've got it.

AIS · CORE

Classifies every file — 40+ document types, label-driven sensitivity rules — and routes it. Credentials: never visible to any model. Legal: never leaves raw — local or masked only. PII: local-only unless the owner decides.

02

LOCAL. SCOPED. DEPARTMENTAL.

Each department gets its own agent — running on local models — answering only from its own enclosure. One department's AI cannot see another's. Access ends at the boundary.

The Door

PRIVACY DECIDED AT INGESTION

Before any file reaches any model, it's classified and routed. Local by default. Anything going to cloud goes masked by default. Raw cloud only by explicit, logged override.

The Mask

DETERMINISTIC PII MASKING

Cloud-eligible content has names, numbers and identifiers stripped before it moves — verified at 0 leaks across 13 audited runs on our test corpus. Not a model's opinion. A testable function.

95,680 reference entities pre-loaded — your staff, clients and company names caught by exact match before any ML model sees them. After masking runs, a visible-risk scanner checks what survived and flags near-misses before anything moves.

The Record

EVERYTHING ON THE RECORD

Every classification, masking and routing decision is logged — source hash, output hash, policy version, purpose. Append-only. "The model thought it was fine" is never the answer.

Why This Is Different

CLOUD AI ANSWERS
QUESTIONS. AIS KEEPS THE RECORD.

Cloud AI answers from a model someone else trained and a context that vanishes when the tab closes. AIS answers from your own archive — classified, routed and indexed on your own hardware, with every handling decision on the record.

Cloud AI / SaaS
Data processed on someone else's servers
Ingests everything, asks privacy questions later
Generic knowledge about businesses like yours
No record of what was sent, where, or why
One bucket — the salary record and the sales flyer get the same treatment
You rent it. You don't own it.
AIS
Runs on your network. Local by default.
Every handling decision logged — source hash, output hash, policy version
Reads the kind of file it is — not the extension. 40+ document types
Credentials never visible to any model. Legal never leaves raw.
PII masking verified: 128/128 tests, 0 leaks across 13 audited runs
UK-specific hard floors — NI numbers, NHS numbers, sort codes, UTR — no policy can disable them
Uncertain files queue for human sign-off before any cloud send
Hardware you own. IP that stays yours.
The Thesis

FIVE FAILURE MODES.

Every AI-for-business tool fails at one of these. Most fail at all five.

01

Zombie Context

Old facts that should have died. The chatbot quotes a policy three quarters out of date.

02

Stale Belief

Confident answers from outdated data. "Your supplier terms are X." They were. Two years ago.

03

Flat History

Speculation reads identical to fact. "I was thinking about doing X" looks the same as "we did X."

04

AI For Everything

LLM used where a database would have worked. The chatbot hallucinates what a SQL query would have answered correctly.

05

Missing Context

The system doesn't know what it doesn't know. Answers anyway. Confidently. Wrongly.

The fix is information architecture
· Built on-site · Not larger context windows
The Engineering Moat

WHATEVER YOU'VE GOT,
AIS HANDLES IT.

Every other AI tool says: "Clean your data first. Format it like this. Tag it like that." AIS says: bring it as you've got it. The ingestion layer is the thing nobody else has built — and it's the reason the rest of the system works.

Any media type

PDFs. Word. Excel. Email exports. Calendars. Scans. Photos of receipts. Voice notes. Video. ZIPs — including encrypted ZIPs and WhatsApp backup archives, extracted and pipelined in full. Bring it as you've got it — detection runs on content, not extensions.

Any content type

Invoice or contract? Meeting note or marketing draft? Customer history or supplier complaint? AIS reads the kind of thing it is — not just the file extension. Routes it. Indexes it. Connects it to everything else it knows.

Privacy understood at ingestion — not after

Every other AI tool ingests first and asks privacy questions later. AIS reverses it. The ingestion layer knows the difference between a sales pipeline, a salary record, and a legal file — and routes each by rule. It decides at the door — not in the cloud. Sending a file to a cloud model is a permission in AIS, not a default. Default-deny, every grant logged. Before anything cloud-eligible moves, deterministic PII masking runs — 0 leaks across 13 audited runs on our test corpus.

The Agents

WHERE THEY ACTUALLY HELP.

One agent per department — concrete applications in the places where time actually gets wasted. Not theoretical use cases from a vendor brochure. Each agent answers from your own documents, not a generic version of your industry.

🧾

Invoice & AP Processing

Invoices read, data extracted, discrepancies flagged. Your AP team keeps the judgement calls.

Finance
📧

Email Archive Search

Your exported inboxes read, classified and made searchable — years of correspondence answering questions instead of sitting in folders.

Operations
📋

Compliance & Policy

Answers HR policy, compliance, and procedure queries — drawn only from your actual documents, with the source documents shown.

HR · Legal
🗂️

Document Governance

Every file classified for sensitivity at the door — credentials, legal, PII, client data each routed by rule. The audit trail comes free.

All Departments
🔍

Duplicate & Version Control

Five copies of every contract in three shared drives — found, matched at content level, and reduced to one canonical version.

Operations
🧠

Staff Knowledge Base

The knowledge that lives in one person's head and walks out the door when they leave. Captured and searchable.

All Departments
The Hardware

A BOX YOU CAN HOLD.

Not a cloud subscription. A physical server on your network, running local AI around the clock.

The AIS Series 01 runs a local large language model on an Apple M4 chip. Routine work runs on local models by default.

When a task justifies frontier-level reasoning, cloud-eligible content goes masked by default — raw cloud only by explicit, logged override. Privacy by default. Power when it matters.

Software updates are tested on our own production unit first — you get them once they've survived us.

Scales with you. The M4 handles most SMEs comfortably. Larger deployments run on bigger on-site hardware. Same software, bigger box. We scope this before you order.

AIS · Series 01 · Specification
Hardware
Apple Mac Mini M4
AI Layer
Local LLM (Ollama) · Always on
Frontier
Claude · On demand · Masked by default
Network
Your LAN · Core work runs locally
Access
Browser-based · Any device
Data
Local by default · Cloud = masked
Updates
Staged releases
Setup
Guided setup
Pricing

BUILD YOUR AIS.
PAY FOR WHAT YOU USE.

Hardware at cost. A flat monthly base. Add the departments you need — and nothing else. No tier creep. No hidden fees. Every number on the table before you commit.

The Base
£299
/ month · always included
Every AIS deployment, regardless of size
The Box managed remotely, around the clock
Local LLM, always on
Portal access from any browser
All updates and improvements included
Remote management and support
Register for updates
The Hardware
At cost
one-off · no markup
M4 from £899 · M4 Pro from £1,299
Sourced, configured, and shipped
We don't profit on the hardware
Plug in. Talk to it. Done.
Larger deployments scoped individually
CabraVerde-assisted for enterprise
Register for updates

Example deployment

20-person business · 4 agents (Finance, Ops, HR, Email Triage) = £299 + £396 = £695/month + £899 hardware (one-off)

Hardware at cost — no markup · Cloud-based LLM costs managed by us · Agents added or removed at any time · No lock-in

AIS in Production

THE ENGINE IS
ALREADY RUNNING.

AIS itself is in private build. But CabraVerde's production stack runs on it — the systems below are live today, powered by the engine you'll own soon. The proof that the engine works is that we already run on it.

Live

The Portal

Cloudflare-tunnelled, login-protected with 2FA, any device. Mobile-usable. Watchdog and session persistence layered in.

Built · delivery paused

Inbound Pipeline

Contact form → automated company research (Companies House, web) → pre-call brief → branded 24-hour demo portal, assembled automatically. Outbound delivery deliberately switched off until we open.

Live

Branded Demo Portals

Per-prospect, auto-generated. Logo, colours, department agents, 24-hour access. Six business environments running today — our own production workspace plus five complete synthetic demo companies.

Live

Email Integration

Outlook wired in — inbox, read, compose, send from inside the portal.

Live

Eval Panel

5-person sequential expert debate on any business question. Build List and departments wired in.

Live

Operator Terminal

Operator-grade Claude Code access via WebSocket PTY, inside the authenticated portal.

Live

Tier Routing

Every file in the archive carries its tier — local, masked, cloud-eligible, pending review, or blocked. Visible at a glance. Logged on every change.

Live

Guided Setup

A structured conversation, not a form. The system reads your documents, proposes the agents you need, and assembles your archive — no configuration wizard.

Live

Audit Chain

Every handling decision logged with source hash, output hash and policy version. Append-only. Verified across five synthetic businesses.

In Build

WHAT WE'RE BUILDING NEXT.

Public. Sequenced. No surprises.

The onboarding portal that builds itself

Owner fills the form → lands on a branded page → guided interface → picks departments → adds people → watches the system assemble. The page IS their portal.

Owner intake — two pictures of the business

Private staff intake alongside owner intake — AIS holds both pictures without attribution: what the owner thinks is happening, and what the floor actually reports.

Orchestrators — address the whole group at once

Address any configuration of agents as one: @orchestrator-Finance gathers every finance agent; a custom orchestrator can mix departments. Orchestration made familiar.

Idea provenance with consent

Trace the conversation, the moment, the person whose idea became the £40k saving.

Connectors — CRM, ERP, ticketing

Live wiring into the systems where operational knowledge already lives. Currently: documents, email exports, and media; line-of-business connectors are next.

We're here to save you money,
not cost you it.
If we can't do that, you don't need us.

Every release is verified against our canary corpus — five synthetic businesses, four difficulty tiers — before your data ever touches it. If the numbers don't work for your business, we'll tell you — before you spend a penny.

Origin

CLEAN-ROOM PROVENANCE.

R&D source
Author's own data only. 4,233 ChatGPT exports. Personal email. Personal files.
Stack
RAG · NER (Presidio + spaCy) · embeddings (nomic-embed-text) · MinHash + LSH for deduplication. Novel configuration of publicly-available techniques.
No prior-employer code, data, processes, or methodology is used in AIS.
Owner
Green Goat Goodies Ltd · Companies House 15747972 · UK-registered. IP held by the company.
Complex Deployment?

CABRAVERDE HANDLES THE HARD CASES.

Enterprise scale, multi-site complexity, or want a human in the room for initial setup — CabraVerde provides hands-on implementation and consulting for organisations that need more than the self-serve path.

Visit CabraVerde →
Status

ENGINE IN PRIVATE BUILD.

Public release: TBC.

No live commercial contact. We don't sell what we can't deliver.

Register below — we'll write to you when we open.

📍Harrogate, North Yorkshire, UK

What you can do now. Visit CabraVerde for the consulting-layer story, the brand, and the founder note. Or register below for AIS-direct early access.

No mailing list. No spam. We write only when there's news worth sharing.

REGISTERED.

We'll be in touch when AIS opens for orders.