ContactBook free analysis
Secure AI · the pillar

Private, on-premise AI for regulated firms — your data stays on hardware you own.

Built, installed, and maintained in your office. Owned by you. No per-seat fees, no cloud.

On-premiseYou own itThe 14-day guarantee
The problem

Staff using ChatGPT with client data is a compliance event.

It doesn't announce itself. A note pasted into a browser tab is a disclosure to a third party under HIPAA, a confidentiality question under Rule 1.6, and an unlogged transfer of non-public information under GLBA. The firm usually finds out during a risk assessment, an audit, or an exam.

The questionConsumer cloud AIBAA / enterprise cloudHandistack on-prem
Where client data goesBad: The vendor's cloudQualified: The vendor's cloud, contract-boundGood: Stays on hardware you own
Trained on your contentBad: Yes, unless you opt outQualified: No — by contractGood: Never. No upstream to train
Retention of prompts & filesBad: Vendor policy, human review possibleQualified: Configurable, vendor-controlledGood: Your policy, your disks
BAA / DPA in placeBad: Not availableGood: AvailableGood: Not needed — no third party
Audit trail you controlBad: NoneQualified: Vendor consoleGood: Your log store and SIEM
Cost shapeQualified: $20–30 per seat / moBad: $60+ per seat / moGood: One-time build, one flat retainer
Works with the internet downBad: NoBad: NoGood: Yes
The solution

A private AI trained on your files, used through a simple chat window.

Your staff don't need to learn a platform. They ask a question; the answer comes back with the document it came from. The difference is where the thinking happens.

Ask your own files

Every document the firm already holds, searchable in plain language, with the source named in the answer.

Draft from your own work

Letters, notes, memos and summaries drafted from your material, in your voice — not the open internet's.

Summarize what nobody has time to read

Intake packets, transcripts, credit files, 200-message email chains — reduced to a page a human can act on.

How you own it

One price to own it. One retainer to keep it running.

The one-time price covers the hardware and the install. The system is yours from day one — if you ever part ways with us, it keeps running.

One room
$12,000 – $24,000
+ $1,000–$2,500/mo
Whole floor
$32,000 – $56,000
+ $2,500–$5,000/mo
Every floor
Custom
monthly quoted with the build
14
days, money back
Every dollar — hardware included. Signed into the build agreement, not a footnote.
Compliance controls

What ships with every system — and what it doesn't cover.

Encryption at rest
Full-disk encryption on every drive in the appliance. Keys held by you.
TLS in transit
TLS 1.3 between the chat client and the appliance. Nothing crosses your perimeter.
SSO + MFA
Binds to the identity provider you already run — Entra, Okta or Google Workspace.
Audit logging
Every prompt, document read and answer written to your log store. Retention is your policy.
Data never leaves
No outbound inference calls. Prompts, files, embeddings and outputs stay on the box you own.
Documented for your file
Control narrative, network diagram and configuration handed over as a PDF for your compliance binder.
On-premise is not, by itself, a compliance programKeeping inference in the building removes third-party-disclosure risk — the largest single item. You still need written policy, staff training and a current risk assessment. We hand over the technical control documentation; your counsel or compliance officer owns the program.
FAQ

The questions firms actually ask.

Answered here and in Answers, at length.

What is on-premise AI?
A model that runs on a server you own, inside your building. Prompts, documents and answers stay on that machine — there is no vendor cloud in the path, and no account that can be terminated.
Is a private model as good as ChatGPT?
For general knowledge, frontier cloud models are still ahead. For answering questions about your own documents — which is what regulated firms actually need — an open-weight model with a well-built retrieval pipeline is at parity, because the value sits in the files, not the weights.
What hardware does this take?
One appliance, sized to the work you want it doing. It needs a rack space or a closet shelf, a 20-amp circuit and a network port — nothing structural, and we bring everything else.
Does it work if the internet goes down?
Yes. Inference is local, so the AI keeps working when your connection doesn't — which is not true of any cloud tool.
What happens when better models come out?
We swap them in under the maintenance plan. The hardware you own runs whatever the best open-weight model is that year.
Is on-premise AI enough for compliance?
It removes the third-party-disclosure risk, which is the single largest item. It is not by itself a complete compliance program — you still need policy, training and a current risk assessment. We document the technical controls; your counsel or compliance officer owns the program.
Serving the Suncoast

Sarasota, Bradenton, Lakewood Ranch, Venice & the Suncoast.

Local means the engineer who built your system is the one who shows up. Book the free analysis and we'll tell you what a private AI is worth in your firm — or that it isn't, yet.