Private AI · Switzerland & Liechtenstein


Private AI that arrives with proof.

Proved before procurement and delivered with the records needed to operate, audit, change, recover and exit. Your archive stays under the custody boundary you choose.

Run the private fit check Inspect the evidence

01Custody mapped02Workload frozen03Answers inspectable04Exit recoverable

The differentiator

Five objects replace five promises.

Open synthetic specimens →
01

Custody Map

Every data, model, administrator and support path.

02

Benchmark Contract

Quality and capacity gates before purchase.

03

Answer Packet

Sources, claims, authorization and runtime.

04

Change Receipt

Reason, regression, approval and rollback.

05

Recovery & Exit

Restore proof and a client-owned rebuild path.

Find the right starting class

Three constraints are enough for a first planning range. The recommendation runs locally and is replaced by measured architecture work before procurement.

Planning tool

No selection leaves your browser. No cookie, analytics event or external API.

Your planning result

Choose the custody, user count and hardest workload.

Indicative CHF bands are dated and non-binding. See inclusions and exclusions →

4custody models
12source-tracked model candidates
7benchmark scenarios
0external runtime requests

The problem, stated quietly

Banks, family offices, trustees, law firms, and clinics hold decades of confidential material: correspondence, contracts, board packs, estate files, client records. Modern AI could make this archive answerable — but not at the price of placing it in uncontrolled external systems.

ANULUM builds the alternative: AI infrastructure that runs where you decide, indexes what you approve, answers with citations from your own documents, and writes an audit trail you can show to whoever holds you accountable.

What we deliver

Local or Swiss-hosted model serving

Language models run on your hardware or on dedicated Swiss infrastructure — never on shared external APIs by default.

Confidential document ingestion

Controlled intake of PDFs, office files, scans, and correspondence, with source hashing and sensitivity classes.

Source-grounded retrieval

Every answer cites the documents it came from. If the archive does not support an answer, the system says so.

Audit logs and version evidence

Prompts, responses, model versions, and index states are recorded — exportable for compliance review.

Evaluation before reliance

Groundedness, refusal behaviour, prompt-injection resistance, and access control are tested before your team relies on the system.

Operation and support

Patching, monitored backups, controlled model updates, and incident response under a defined support agreement.

Deployment on your terms

Four custody models, selected during the architecture review:

01

Air-gapped

No internet path at all. Offline updates. For the most sensitive archives.

02

On-premises

Runs in your building on your network, with controlled maintenance windows.

03

Swiss-hosted dedicated

Single-tenant hardware in a certified Swiss data centre when you cannot host it yourself.

04

Hybrid, policy-gated

Local by default; external models only for approved, non-sensitive tasks — with routing logs.

Compare the deployment models →

Who it is for

Family offices

Institutional memory across generations — without exposing the family archive.

Family offices →

Trustees & fiduciaries

Source-grounded retrieval across trust deeds, registers, minutes, and client files.

Trustees & fiduciaries →

Private banking

Controlled internal AI over policies, research, and regulated knowledge.

Private banking →

Law firms

Find the clause, cite the source, keep the file in the house.

Legal →

Private clinics

Confidential assistance for clinical documents and correspondence.

Private clinics →

Research & board offices

Private literature, strategy papers, and board material — searchable, citable, local.

Start with a review →

How an engagement works

  1. Confidential architecture review1–2 weeks, fixed scope We map the archive, the risk boundary, the deployment mode, and the operating cost — before you buy anything.
  2. Proof node2–6 weeks A limited, sanitised part of the archive runs on real infrastructure. You see citations, refusals, and audit logs on your own material. Then you decide: stop, expand, or productionise.
  3. Production system and managed operation6–16 weeks, then ongoing Warrantied hardware, hardened deployment, user roles, backups, evaluation pack, training — and a support contract that keeps it dependable.

Start with the review

Inspect the practice before you engage it

Evidence

Engineering experience

See the public software and systems disciplines behind our private-AI work, with the boundary between public evidence and client delivery stated clearly.

Inspect the engineering →
Method

Ten-gate lifecycle

Follow every stage from confidential discovery and proof node through acceptance, controlled change and an exportable exit.

Follow the lifecycle →
Clarity

Practical questions

Get direct answers on data custody, model replacement, concurrency, air-gap updates, compliance boundaries, pricing and ownership.

Read questions and answers →

Dense systems produce heat. We design where it goes.

For larger GPU deployments, ANULUM can design liquid-cooling and heat-recovery paths so part of the thermal energy supports building heat or hot-water preheating — engineered with licensed HVAC partners, after a site survey, with measured assumptions.

Optional heat recovery →

Expanded programme · 29 July 2026

Three clearer ways to move forward.

Browse all resources →
Now scopeable

Kimi K3 Sovereign Evaluation

Licence, workload, rack feasibility and a measured stop or proceed packet—without a borrowed performance promise.

Open the evaluation →
Commercial clarity

Engagement ladder

Compare discovery, review, pilot, production, operation and exit as separately accepted decisions.

Compare engagements →
Public boundary

Trust Centre

Inspect current controls, shared responsibility, precise data-location questions and explicit non-claims.

Inspect the Trust Centre →

Named accountability

Founder-led from first decision to recovery drill.

Miroslav Šotek leads ANULUM’s architecture and engineering work in Marbach SG. Public research identity and code history stay inspectable; confidential client environments stay private.

ORCID 0009-0009-3560-0851 · GitHub · About the practice →

Start without disclosing the archive.

The browser-local Fit Check creates your first decision record. Nothing is sent; a paid review follows only when justified.

Run the private fit check