Most firms treat this as a legal appendix. For an intelligence firm it's part of the product: the question you asked us is itself confidential, before any answer exists. Below is what we do, in plain terms — and at the end, what we deliberately don't claim.
Firms that promise to encrypt everything are describing a filing cabinet, not a method. The useful distinction is between material that is already public — where the processor is irrelevant — and material that is yours, where it is the only thing that matters.
Most of what we read is public by construction: news, registries, court filings, corporate records, imagery, official statements, what people say in the open. Who processes it changes nothing, because anyone can fetch it. Encrypting a press release would be theatre — and it would cost you the best available reasoning for no gain in safety.
Your identity, your addresses, the people you're responsible for, the question you asked — and the fact that you asked it at all. This is a far smaller volume and it carries all of the risk, so it's where the encryption, the separated keys, and the choice of where inference runs actually apply.
The split is the point. Because the public half needs no protection, we can put the best available reasoning against it without hesitating — and because the private half is small, we can afford to be uncompromising about it. Treating both the same way would mean doing one of them badly.
The two classes split here too. Reasoning over public material runs on commercial cloud models, because there is nothing to protect and the best available reasoning is worth having. Reasoning over your material is a separate decision with a separate answer, and there is no single right one — it depends on what you already have, what you're willing to stand up, and how much you're prepared to trust a contract. These five endpoints, plus the optional backup below, are live today — not a roadmap.
And the first two go further than inference. If you own the machine, the engine runs on it as well — storage, indexing and reasoning inside your perimeter, with no Aegilo-held copy of your material at all. Everything else on this page describes how we protect material we hold. Those two options describe not holding it.
Only the first two remove the third party — and they're the same answer, differing only in who buys the machine. The rest reduce it, distribute it, or bind it contractually; they do not eliminate it, and a page that let them sit here looking equivalent would be doing the thing this whole section exists to argue against. The backup is an addition to the first two rather than an option beside them. Which arrangement you're buying is agreed in writing before any work starts.
A page about honesty that overstated would refute itself. So, explicitly: we do not claim GDPR or FADP compliance — there is no DPA or DPIA in place yet. We do not publish retention schedules or key-rotation policy, we do not anonymise material before model calls, we do not operate multi-tenant role-based access control, and we hold no security certification. When those land, they'll be stated here with the same specificity as everything above.
And one that's easy to blur: where inference runs on a provider we don't control, we have not audited them. We rely on their contractual terms and their published architecture, exactly as everybody else does. Terms of that kind exclude training on your material outright, while still permitting short-term retention for abuse monitoring unless a zero-retention arrangement is specifically negotiated — which we do when the engagement calls for it, and don't pretend to hold in advance. If that distinction matters to your threat model, say so and we'll pick a different option from those above.
Ask for specifics before you engage — where material sits, who can reach it, what leaves the perimeter, and when it's destroyed. A firm that can't answer that shouldn't be holding your exposure.
Where Aegilo holds it, with a Swiss provider under Swiss jurisdiction. US hyperscalers were excluded for storing client material deliberately — cheaper egress is the wrong trade for a firm that sells confidentiality. If you run the engine on hardware you own, Aegilo holds no copy of your material at all, and the question does not arise.
No. Client-private material is encrypted under a key belonging to that client alone, and the key is held in a different control domain from the storage itself. A subpoena served on the storage provider yields ciphertext and a wrapped key that provider cannot unwrap.
Your key is destroyed, which renders every copy unreadable at once — including archives and append-only records. Deleting rows cannot make that promise honestly, because it cannot reach backups already written.
No. Client material cannot enter the shared corpus, the cache, or version control. That is a boundary in the architecture, checked as part of the build, not a policy someone has to remember.
Yes. For this work, who is a client is a target list. Identities never appear in storage paths, listings, logs, or backups — records carry opaque identifiers, and the human name is encrypted content like everything else.
Every model call passes through a single gate that records what class of material it carried and where it went. The most sensitive class refuses to run at all unless an endpoint you have approved is configured — the default is to fail, not to proceed.
No, and it shouldn't be. Most of what an analyst reads is already public — news, registries, court filings, corporate records, imagery — and who processes that changes nothing, because anyone can fetch it. The protections apply to client-private material: your identity, your addresses, the people you are responsible for, and the question you asked. That is a far smaller volume and it carries all of the risk.
Wherever your risk assessment says it should. Five endpoints are available, plus an optional backup: you run an open-weight model on hardware you already own; we specify, buy and commission that hardware for you if your opsec requires owned kit and you have none; you give us an endpoint and a token in your own cloud account, so it runs under your keys and your audit trail; we use a Swiss or European provider in the same jurisdiction as the storage; or we use a major model provider under commercial terms that exclude training on your material. Which one applies is agreed in writing before any work begins.
Yes — the whole platform, not only the model. If you own the machine we install the engine and an open-weight model on it, and storage, indexing and reasoning all run inside your perimeter, with no Aegilo-held copy of your material anywhere. You do not need to already own hardware: we can specify, procure and commission one sized to the work and hand it over as yours, then use it as an authorised user you can revoke. Off-site backup can be added, encrypted before anything leaves the machine and with the keys held by you. The honest trade is capability: open weights on affordable hardware sit behind the frontier models, and that should be a decision you make knowingly rather than discover afterwards.
We'd rather answer a hard question about custody now than have you discover the answer later.