Skip to content

For IT managers and administrators

This is how the system is built.

This page describes the architecture of an on-premise AI system the way your IT team will want to examine it: data flow, hardware, models, permissions, sources, network, updates, remote service, backup, resilience and model change. Without marketing, without components we don't supply. Whatever isn't covered here is covered in the technical description, which you can request.

01 · Data flow

From request to answer, without leaving your premises.

Every request passes through six stages. All six are on the system in your network.

  1. Request

    An employee asks a question or hands over a document, via browser or app on the company network.

  2. Identity and permissions

    The system determines who is asking and which sources are released for that person. The basis is your existing permission structure.

  3. Knowledge index

    The relevant passages are retrieved from the released sources. The documents themselves stay in your file stores.

  4. Model

    An open model suited to the task formulates the answer. It runs on the hardware on your premises.

  5. Answer with sources

    The answer names the documents it is drawn from, so that it can be checked.

  6. Log

    Who asked what and when is logged locally. The log stays in your system.

No outside connection is needed for this process. Connections to cloud services such as Microsoft 365 naturally use their own connection; whether and which ones you connect is up to you.

02 to 10 · Components

Nine areas your IT team will examine.

For each area, we state how the system is built and what you decide yourself. Where something depends on the package or on your environment, we say so.

02 · Hardware

Three classes, one principle: sized for the task.

Compact system as a quiet desktop or tower computer in the office, server class as a rack or tower server in the server room, or a server pair that is redundant by design. The determining factors are graphics memory, RAM, storage and the number of concurrent users. We check existing hardware in the hardware check; if it is suitable, the hardware share of the package is dropped.

You decideLocation, form factor, your own or supplied hardware
Stated in the quotationThe specific equipment. We don't name components we don't supply.

03 · Models

Several open models, interchangeable, with no training on your data.

For text, technical language, images and code, one tested open model from AI research in each case. Which model answers is handled by the system; your employees see one interface. Models can be swapped with an update without anything changing for the users (see model change). Your questions and documents are not used for training, neither by us nor by a model provider.

You decideWhich capabilities are active, when updates are installed
Stated in the quotationThe models in use, with version. We don't name them on the website because they change with updates.

04 · Permissions

The AI adopts your permission structure; it does not replace it.

Permissions apply by user, group and source and are connected to your existing directory. A question is answered only from sources the person asking is released for. Anyone who may not open a personnel file gets no answer from it either. We set up roles and access areas together with you; how fine-grained the structure is, you decide.

You decideRoles, access areas, exceptions
EvidenceJoint test with your real cases before handover

05 · Knowledge sources

Documents stay where they are. The index is on the system.

File server, NAS and network drives are included in every package. Microsoft 365, Google Workspace, e-mail, Nextcloud, Confluence as well as ERP, CRM, DMS, accounting and databases can be added as connections, via open standards such as MCP, APIs and OpenAPI. Every connection only receives the permissions you grant for it: read access in every connection; write access for defined actions (draft, issue, entry, hand-over) only where the interface provides for it and you approve it, within a scope approved specifically for that purpose. A new document is available once it has been indexed; a removed document is removed from the index. No second file store is created.

You decideWhich file stores and systems are connected, with which permissions, and whether a connection may only read or also carry out defined actions
Depends onPackage (number of access areas and connections) and the interface of the respective system, see configurator

06 · Network

By default, reachable only from your network.

The system sits on your premises and is used via browser or app on the company network. Nothing is opened to the outside that you don't open yourself. AI processing needs no internet connection; a connection is used only for updates and, if booked, for the remote service, in each case after your approval. Whether the interface should also be reachable from outside, for example via your VPN, is for your IT team to decide.

You decideNetwork segment, reachability, time windows for outside connections
PrerequisiteA place with power and network, access for the system to the connected file stores

07 · Updates

We provide them. You decide when they are installed.

We provide model and software updates for twelve months, after that optionally as an extension. Installation takes one of two routes: your IT team installs the update as a package, or we take care of it in the remote service after your approval. In both cases, only the update comes in; none of your data is transferred. What an update brings, you learn beforehand in the customer portal.

You decideTiming, route (package or remote service), approval
IncludedTwelve months in every package

08 · Remote service

Access only after approval, every session logged.

Without remote service, we have no access to your system. With remote service, access exists only within the scope you define: for a single session or permanently, with a log of every session in your system. We work on the system, not with exports; maintenance needs no copy of your data. For the remote service, we conclude a data processing agreement with you. What is monitored is utilisation, storage and models.

You decideWhether at all, to what extent, when
ContractuallyData processing agreement, German law

09 · Backup

Configuration and index are backed up. You back up your documents as before.

The system's configuration and knowledge index are backed up in such a way that they can be restored on a replacement device. Your documents remain in your file stores and run through your existing backup; the system holds no second copy that you would have to back up in addition. The system's storage media are encrypted. Where the system's backup is written to is agreed with your IT team during setup.

You decideBackup target, retention, deletion
No copiesDataFlowFacts holds no copies of your data

10 · Resilience

One system or two. We tell you what that means in the event of a failure.

With AI Compact and AI Team, the AI runs on one system. If it fails, the AI is down until the device is repaired or replaced; your documents are not affected. Configuration and index are restored on the replacement device. AI Enterprise is redundant by design: two systems, and the failure of one can be absorbed by the other. We don't promise uninterrupted operation; that would not be honest for any system.

You decideWhether redundancy is needed, in the configurator or in conversation
Depends onPackage and hardware class

11 · Model change

What happens when a better model is released.

The system is built in layers. The model is the layer that changes most often; your source data is the layer that never needs to change. That is why you replace the model, not your data basis.

  1. Source data stays

    Your documents remain in your file stores and in your systems. A model change does not touch them; no copy and no second file store is created.

  2. Knowledge integration

    The knowledge index, roles, access areas and connections remain in place. Technically, a model change can require a new indexing run across the approved sources; it runs on your system.

  3. AI model interchangeable

    The new model is provided as an update and installed after your approval, as a package by your IT team or in the remote service. For your employees, the interface does not change.

  4. Answer stays local

    With the new model too, processing runs on the hardware on your premises, with the same permissions and the same logging. What an update brings, you learn beforehand in the customer portal.

What this means for your planning

You are not buying a specific model but a system that can deploy suitable open models for your tasks. Hardware and company knowledge are the investment that stays; the model is the component that evolves. Model updates are included for twelve months, after that optionally as an update service or in the remote service. If you change hardware class, we transfer the configuration and knowledge sources to the new system. We do not guarantee a change without any effort at all: whether a new indexing run is needed and how long it takes depends on the model and on the volume of your sources, and is stated in advance in the customer portal.

Preparation

What your IT team provides before setup.

We take care of the setup, remotely or on site. To keep it moving quickly, five things from your side help. A copy of your data is not one of them.

  • A place with power and network: a shelf space for the compact system, a rack slot for the server class.
  • Network access for the system to the file stores that are to be connected, with the permissions intended for this.
  • Your permission structure: who belongs to which role, which folders belong to which access area, and which directory manages this.
  • A decision on outside connections: updates as a package or via remote service, and whether there is a time window for this at all.
  • Ten real questions from everyday work, which we use together before handover to check that answers and permissions are correct.

Context

What this page does not claim.

An architecture description is not proof of security. That's why we state three things explicitly.

No certificates we don't hold

We don't advertise ISO or BSI certifications we cannot present. What we can present is stated in the technical description.

No blanket compliance

The system is designed for data-protection-compliant operation. The assessment depends on your processing and your configuration and belongs with your data protection officer. We provide the facts for it: Security & data sovereignty.

No figures without measurement

Response times, throughput and concurrent users depend on hardware, models and sources. We state orders of magnitude in the quotation and measure in the joint test, not on the website.

The detailed description for your records.

Data flow, components, permissions, logging, updates and remote service in detail, to pass on to your data protection officer and IT team. We send it to you on request and answer follow-up questions from the engineering team.