How your data is held

You're telling us where your family lives. Nobody else gets to read it.

Most firms treat this as a legal appendix. For an intelligence firm it's part of the product: the question you asked us is itself confidential, before any answer exists. Below is what we do, in plain terms — and at the end, what we deliberately don't claim.

Two classes of material

Not everything we touch needs protecting. One part of it badly does.

Firms that promise to encrypt everything are describing a filing cabinet, not a method. The useful distinction is between material that is already public — where the processor is irrelevant — and material that is yours, where it is the only thing that matters.

PUBLIC MATERIAL

The world is already published.

Most of what we read is public by construction: news, registries, court filings, corporate records, imagery, official statements, what people say in the open. Who processes it changes nothing, because anyone can fetch it. Encrypting a press release would be theatre — and it would cost you the best available reasoning for no gain in safety.

YOUR MATERIAL · PII / PHI

You are not.

Your identity, your addresses, the people you're responsible for, the question you asked — and the fact that you asked it at all. This is a far smaller volume and it carries all of the risk, so it's where the encryption, the separated keys, and the choice of where inference runs actually apply.

The split is the point. Because the public half needs no protection, we can put the best available reasoning against it without hesitating — and because the private half is small, we can afford to be uncompromising about it. Treating both the same way would mean doing one of them badly.

Six commitments

What holds, and why it holds.

SWISS STORAGE Your material sits in Switzerland. Where we hold client data, it is stored with a Swiss provider under Swiss jurisdiction. US hyperscalers were excluded for storing client material on purpose — cheaper egress is the wrong trade for a firm that sells confidentiality. Two things are decided separately and set out further down this page: where inference runs, and whether we hold your material at all — run the engine on your own hardware and we don't.
KEYS HELD APART The people holding the data can't read it. Client-private material is encrypted under a key belonging to that client alone, and the key lives in a different control domain from the storage. A subpoena served on the storage provider yields ciphertext and a wrapped key that provider cannot unwrap. We deliberately refuse to put the master key in the storage provider's own key service — that recombines lock and key under one roof.
ERASURE IS ONE ACT Deletion that actually reaches the backups. Because each client has their own key, erasure is the destruction of that key — which renders every copy unreadable at once, including archives and append-only records. Deleting rows can't make that promise honestly. Export works the same way: your material, on request.
SEPARATED BY CONSTRUCTION Your case never joins the research corpus. Client material cannot enter the shared corpus, the cache, or version control. That isn't a policy someone remembers to follow — it's a boundary in the architecture, checked as part of the build. What we learn about the world is reusable; what we learn about you is not.
YOUR NAME ISN'T THE FILENAME The client list is itself sensitive. For this work, who is a client is a target list. So identities never appear in storage paths, listings, logs, or backups — records carry opaque identifiers, and the human name is encrypted content like everything else.
ONE GATE FOR AI Every model call is classified and recorded. Every call to an AI model passes through a single gate that records what class of material it carried and where it went. The most sensitive class refuses to run at all unless an endpoint you've approved is configured — the default is to fail, not to proceed.
Where it runs

By default we settle where it rests. You settle where it thinks.

The two classes split here too. Reasoning over public material runs on commercial cloud models, because there is nothing to protect and the best available reasoning is worth having. Reasoning over your material is a separate decision with a separate answer, and there is no single right one — it depends on what you already have, what you're willing to stand up, and how much you're prepared to trust a contract. These five endpoints, plus the optional backup below, are live today — not a roadmap.

And the first two go further than inference. If you own the machine, the engine runs on it as well — storage, indexing and reasoning inside your perimeter, with no Aegilo-held copy of your material at all. Everything else on this page describes how we protect material we hold. Those two options describe not holding it.

NOTHING LEAVES YOUR PERIMETER You own the machine. Everything runs on it. You stand up the hardware; we install the engine and an open-weight model on it, on your premises or on a machine you rent and control. Storage, indexing and reasoning all happen inside your perimeter. There is no Aegilo-held copy of your material anywhere — not encrypted so that we can't read it, simply not present. The trade is capability: open weights on affordable hardware sit behind the frontier, and you should choose that knowingly rather than discover it later.
WE BUILD IT FOR YOU Your opsec needs owned hardware. You don't have any. If nothing may leave your perimeter and there's no machine to run it on, we specify, procure and commission one — sized to the work, with the engine and an open-weight model installed, handed over as yours. You own the hardware, the weights and everything on it; we become an authorised user, and you can revoke that. It's the slowest to start and the only option with a visible capital cost up front, which is the honest price of removing every third party.
OPTIONAL · ENCRYPTED BACKUP One machine is a single point of failure. Running everything in your perimeter means a fire, a theft or a failed disk is your problem alone. If you'd rather not carry that, we can add off-site backup where everything is encrypted before it leaves the machine and you hold the keys — so the storage provider has ciphertext and nothing else, and we can't read it either. It's the one addition that doesn't weaken the arrangement, because the material is unreadable to everyone but you before it ever travels.
YOUR CLOUD, YOUR ACCOUNT You already have a perimeter. We work inside it. If you have a cloud relationship and a security posture built around it, give us an endpoint and a token. Inference runs in your account, in the region you choose, under your keys, inside your audit trail — and your own team can see exactly what was called and when, without taking our word for it.
SWISS OR EUROPEAN INFERENCE Jurisdiction matters, and you'd rather not run the machine. Inference against a Swiss or European provider, in the same jurisdiction as the storage and under the same law — including providers whose architecture keeps conversations zero-access encrypted and unlogged. No hardware for you to buy, no US legal exposure to reason about.
A MAJOR PROVIDER, UNDER CONTRACT Frontier reasoning, on written terms. The strongest available models, under terms agreed for your engagement: training on your material excluded, and retention bound where you need it bound. We put those terms in place when this is the option you've chosen, rather than carrying contracts speculatively for work nobody has asked for. Fastest to start and the best reasoning of the five — and the one where you are trusting a contract and an architecture you cannot inspect. We'd rather say that in the same breath than let it sit here looking equivalent to the others.

Only the first two remove the third party — and they're the same answer, differing only in who buys the machine. The rest reduce it, distribute it, or bind it contractually; they do not eliminate it, and a page that let them sit here looking equivalent would be doing the thing this whole section exists to argue against. The backup is an addition to the first two rather than an option beside them. Which arrangement you're buying is agreed in writing before any work starts.

What we don't claim

The list a vendor usually leaves out.

A page about honesty that overstated would refute itself. So, explicitly: we do not claim GDPR or FADP compliance — there is no DPA or DPIA in place yet. We do not publish retention schedules or key-rotation policy, we do not anonymise material before model calls, we do not operate multi-tenant role-based access control, and we hold no security certification. When those land, they'll be stated here with the same specificity as everything above.

And one that's easy to blur: where inference runs on a provider we don't control, we have not audited them. We rely on their contractual terms and their published architecture, exactly as everybody else does. Terms of that kind exclude training on your material outright, while still permitting short-term retention for abuse monitoring unless a zero-retention arrangement is specifically negotiated — which we do when the engagement calls for it, and don't pretend to hold in advance. If that distinction matters to your threat model, say so and we'll pick a different option from those above.

Ask for specifics before you engage — where material sits, who can reach it, what leaves the perimeter, and when it's destroyed. A firm that can't answer that shouldn't be holding your exposure.

Common questions

Asked before every engagement.

Where is Aegilo client data stored?

Where Aegilo holds it, with a Swiss provider under Swiss jurisdiction. US hyperscalers were excluded for storing client material deliberately — cheaper egress is the wrong trade for a firm that sells confidentiality. If you run the engine on hardware you own, Aegilo holds no copy of your material at all, and the question does not arise.

Can Aegilo's storage provider read your material?

No. Client-private material is encrypted under a key belonging to that client alone, and the key is held in a different control domain from the storage itself. A subpoena served on the storage provider yields ciphertext and a wrapped key that provider cannot unwrap.

What happens when you ask for your data to be deleted?

Your key is destroyed, which renders every copy unreadable at once — including archives and append-only records. Deleting rows cannot make that promise honestly, because it cannot reach backups already written.

Does your case get used to improve the research corpus?

No. Client material cannot enter the shared corpus, the cache, or version control. That is a boundary in the architecture, checked as part of the build, not a policy someone has to remember.

Is the client list itself protected?

Yes. For this work, who is a client is a target list. Identities never appear in storage paths, listings, logs, or backups — records carry opaque identifiers, and the human name is encrypted content like everything else.

What happens when client material reaches an AI model?

Every model call passes through a single gate that records what class of material it carried and where it went. The most sensitive class refuses to run at all unless an endpoint you have approved is configured — the default is to fail, not to proceed.

Is all of Aegilo's data treated the same way?

No, and it shouldn't be. Most of what an analyst reads is already public — news, registries, court filings, corporate records, imagery — and who processes that changes nothing, because anyone can fetch it. The protections apply to client-private material: your identity, your addresses, the people you are responsible for, and the question you asked. That is a far smaller volume and it carries all of the risk.

Where does AI inference run on private client material?

Wherever your risk assessment says it should. Five endpoints are available, plus an optional backup: you run an open-weight model on hardware you already own; we specify, buy and commission that hardware for you if your opsec requires owned kit and you have none; you give us an endpoint and a token in your own cloud account, so it runs under your keys and your audit trail; we use a Swiss or European provider in the same jurisdiction as the storage; or we use a major model provider under commercial terms that exclude training on your material. Which one applies is agreed in writing before any work begins.

Can Aegilo run entirely inside a client's own infrastructure?

Yes — the whole platform, not only the model. If you own the machine we install the engine and an open-weight model on it, and storage, indexing and reasoning all run inside your perimeter, with no Aegilo-held copy of your material anywhere. You do not need to already own hardware: we can specify, procure and commission one sized to the work and hand it over as yours, then use it as an authorised user you can revoke. Off-site backup can be added, encrypted before anything leaves the machine and with the keys held by you. The honest trade is capability: open weights on affordable hardware sit behind the frontier models, and that should be a decision you make knowingly rather than discover afterwards.

Ready when you are

Still want to ask us something specific?

Start a conversation

We'd rather answer a hard question about custody now than have you discover the answer later.