The Founding Principle

Compute and storage shall never leave the client's premises.

This sentence is the single non-negotiable constraint from which every architectural decision at E-Y follows. It is not a feature we added. It is the reason the company exists.

When we say "zero egress," we mean it at the network layer. Outbound connections from the AI cluster are blocked at the firewall, blocked at the host layer, and blocked at the application layer. No model calls home. No telemetry pipeline ships data. No auto-update reaches an external server. The only network traffic that leaves the cluster is anonymised health metrics to our monitoring endpoint — and even that is opt-out.

Five Layers of Protection

Defence in depth. Sovereignty by design.

Security is not a single wall. It is a series of concentric boundaries, each independently sufficient, collectively unbreachable.

01

Physical Perimeter

The hardware is in your building, behind your doors, under your camera system, inside your access-control regime. We do not co-locate. We do not host. The silicon is yours, in your room, under your physical sovereignty. Data centre colocation obliges you to trust a third party's physical security — we eliminate that trust dependency entirely.

02

Network Isolation

The AI cluster operates on a dedicated VLAN or physically separate network. Inbound access is restricted to authenticated users on your internal network. Outbound traffic — all of it — is denied by default at the firewall. We verify this with active penetration testing during deployment: we attempt to exfiltrate data and we fail, because the paths do not exist.

03

Encrypted Storage

All data at rest — documents, embeddings, model weights, vector indices, configurations — is encrypted with AES-256. Keys are managed on your premises, in your key management system. We can integrate with your existing HSM or deploy a dedicated one. We never hold your encryption keys unless you explicitly ask us to.

04

Model Provenance & Open Weights

We deploy open-weights models (Llama, Mistral, Qwen, and others) that can be fully inspected, audited, and run without any external dependency. No proprietary model APIs. No hidden telemetry inside model binaries. We verify model checksums before deployment and give you the ability to inspect the exact model files running on your infrastructure.

05

Audit & Verification

Every deployment includes a zero-egress verification report: network flow logs showing zero outbound connections, a penetration test report, and an architecture diagram signed by our engineering team. You can re-run the verification at any time. The security model is not something we claim — it is something we prove, and you can independently confirm.

Data Sovereignty

Your data. Your jurisdiction. Your rules.

When data leaves your premises, it crosses jurisdictional boundaries. A cloud provider in Ireland, a model API in California, a backup in Singapore — each hop changes the legal regime that governs your data. For family offices bound by Swiss banking secrecy, for advocates bound by attorney-client privilege, for medical professionals bound by patient confidentiality statutes — a single hop can create irreversible legal exposure.

On-premise deployment eliminates this entirely. Your data exists only under your jurisdiction. It is never subject to a foreign government's subpoena, a cloud provider's terms change, or an upstream model vendor's data retention policy. Sovereignty is not a legal argument you make after the fact — it is a physical fact established by architecture.

"The only way to guarantee that data never leaves your premises is to make it physically impossible for it to do so. Everything else is a promise. We deal in architecture."

E-Y Engineering Principles

Swiss Data Protection

Switzerland's data protection framework (revDSG) and its status outside the EU makes on-premise deployment a natural fit. Data that never leaves Swiss soil is not subject to GDPR transfer mechanisms, Schrems II concerns, or third-country adequacy debates.

We design E-Y deployments to comply with Swiss data protection law by default — and to be compatible with EU GDPR when your client base requires it.

Why Not Cloud?

The on-premise difference.

Cloud AI is convenient. It is also a rental of trust. Here is what changes when the compute belongs to you.

Cloud / API-based AI

  • ✗ Your data leaves your premises with every request
  • ✗ Model prompts transit the public internet
  • ✗ Data is subject to provider's jurisdiction
  • ✗ Terms of service can change without notice
  • ✗ Vendor may retain or train on your data
  • ✗ No control over model updates or behaviour
  • ✗ Ongoing per-token or per-request costs

E-Y On-Premise AI

  • ✓ Your data never leaves your premises — architecturally
  • ✓ Prompts processed entirely on your network
  • ✓ Data stays under your jurisdiction's laws
  • ✓ You own the infrastructure; terms cannot change
  • ✓ No data retention by any third party
  • ✓ Full control over model selection and updates
  • ✓ Fixed cost. No per-use metering. No surprise bills.
Questions We Expect

Addressing the obvious concerns.

If there is zero egress, how do you provide support and updates?

Support is remote but read-only: our monitoring receives anonymised health metrics (GPU temperature, utilisation, uptime, request latency). No data content, no prompts, no model outputs. For software and model updates we follow a strict order of preference: first, a dedicated, temporary, authenticated and audited inbound channel, opened only during a scheduled maintenance window and closed immediately after; second, an on-premise proxy inside your network through which signed update packages are staged under your control; third, encrypted physical media (SSD) shipped under contract.

What if we need to scale beyond the initial deployment?

The architecture is designed to scale horizontally. Additional GPU nodes can be added to the cluster without re-architecting the network or the software stack. We size the initial deployment for your current needs and design the physical and logical topology to accommodate growth. Scaling is a procurement event, not a migration.

We do not have a server room. Can you still help?

Yes. We can help you design and provision a dedicated, secure infrastructure room — or, for smaller deployments, we offer compact GPU appliances (rack-mount or tower) that operate in standard office environments with appropriate cooling. We assess this during the audit phase and recommend the right form factor for your space and power constraints.

Can our existing IT team manage the system?

Yes. We provide comprehensive training and documentation. The day-to-day operation is designed to be manageable by a competent IT team without specialised AI expertise. For deeper maintenance — model updates, performance tuning, security audits — we remain available under the ongoing stewardship agreement.

How do you handle model updates in an air-gapped environment?

Our first choice is a dedicated, temporary, inbound-only channel — authenticated, audited, opened during a scheduled maintenance window, and closed immediately after. Where policy forbids any inbound connection, updates are staged through an on-premise proxy under your control. For fully air-gapped environments, we ship encrypted SSDs under contract. In every case, all updates are checksum-verified, signed by our engineering team, and applied with your IT team present. The update process is documented and repeatable.

Continue

Read about the company behind the architecture.

Learn about our Swiss engineering heritage, our NVIDIA certification, and our experience serving family offices and financial establishments.