Sovereign AI · Private cloud · High security

Artificial Intelligence, on your own infrastructure

We design, deploy and operate AI and private cloud platforms for organisations that cannot afford to let their data leave home. High security and maximum performance underpin every service.

  • Models running on your own hardware
  • Data that never leaves the EU
  • In-house engineering and operations
Why dataSource

Three commitments.
No small print.

We have spent years moving business-critical applications to the cloud. AI does not change the principle: technology is only useful when the data is protected and the system responds when it matters.

01

Real sovereignty, not a slogan

Your models and your data run where you decide: your own data centre, our private cloud in Spain, or a hybrid of both. No hidden dependencies, no telemetry to third parties, no contract surprises.

02

Security by design

Encryption in transit and at rest, network segmentation, least privilege and traceability of every access. Architecture driven by risk, not patched after the incident.

03

Performance we measure

Before and after. We analyse, compare alternatives and publish real figures for latency, throughput and cost per query. If it does not improve, we do not ship it.

Sovereign AI

Artificial intelligence that does not take your business elsewhere

Using generative AI should not mean shipping your contracts, your source code or your customers' data to a provider you do not control. We build the whole stack inside your perimeter.

  • Open models on your hardware

    Language and vision models deployed on your own or dedicated GPUs, with private inference and no per-token usage caps.

  • RAG over your own knowledge

    We index your documentation, ERP and repositories into an internal vector database so the model answers with your information and cites the source.

  • Agents wired into your systems

    Assistants that query Dynamics, your CRM or your databases with permissions inherited from the user and a full audit trail of every action.

  • Predictable, auditable cost

    Fixed infrastructure instead of unpredictable metered billing, with dashboards for usage, latency and real spend.

sovereign ai stack
05 Applications and assistants Chat · API · integrations
04 Orchestration and agents Flows · tools · policies
03 Inference engine LLM and embeddings on your GPU
02 Vector store and RAG Your knowledge, indexed
01 Data and storage Encrypted · inside your perimeter
Services

From consultancy to fully managed service

We can design the architecture, run the migration and stay on to operate it. Or step in only where you need us.

On-premise sovereign AI

GPU sizing, open model deployment, inference server, high availability and controlled version upgrades.

Corporate assistants and RAG

Conversational search over your internal documentation, with permission control, source citation and continuous quality evaluation.

Private and hybrid cloud

We move, scale or deploy almost any business application into a cloud environment without giving up control of the data.

Dynamics Cloud

Specialists in Dynamics AX, NAV and 365 on optimised infrastructure: service trials, migration and cost-contained rollout.

Performance tuning

Analysis and technology benchmarking to get the most out of critical applications: I/O, memory, network and database bottlenecks.

Managed security and operations

Hardening, segmentation, secure service publishing, backups, disaster recovery and monitoring with proactive alerting.

platform status
# platform status
gpu-node-01 inference up
gpu-node-02 inference up
vectordb rag / indexes up
ingress-tls sni passthrough up
backup last cycle ok

# data at rest
encryption AES-256
location Spain / EU
egress denied by default
Infrastructure

We design it, we deploy it and we run it ourselves

We do not resell someone else's cloud. We maintain our own platform: network, secure service publishing, monitoring, backups and on-call. When something breaks, you talk to the people who built it.

Linux Kubernetes Docker Proxmox / VMware Traefik TLS · SNI passthrough Zabbix Grafana Loki PostgreSQL Microsoft SQL Server MikroTik Windows Server Microsoft Dynamics
99.95%
Target service availability
100%
Data hosted in Spain and the EU
24/7
Platform monitoring
0
Data shared with third parties for training
How we work

Four steps, no smoke

Step 01

Assessment

We map the use case, the data behind it and the real legal and technical constraints.

Step 02

Proof of concept

A scoped pilot with your data and success metrics agreed up front. With an end date.

Step 03

Rollout

Final architecture, hardening, high availability, backups and documentation you keep.

Step 04

Operations

Monitoring, controlled upgrades, performance reviews and continuous evolution of the service.

Frequently asked

What people ask us before starting

Straight answers, including the uncomfortable ones. If your case is not a fit, we would rather tell you on the first call.

01 What exactly is sovereign AI?

It means running AI models on infrastructure you control — your own data centre, or a dedicated private cloud — instead of sending your data to someone else's service.

Sovereignty means three concrete, verifiable things:

  • You know which physical machine runs the model and what country it sits in.
  • You know where the data you feed it is stored and who can read it.
  • Nobody uses your information to train anything, because it never leaves your perimeter.

It is not a different technology. To a large extent these are the same models you already know, deployed differently. The difference is in the architecture and the contract, not in magic.

02 How is it different from using ChatGPT or Copilot at work?

In who holds the data and what you can verify. To be fair: the enterprise plans of the major providers do contractually commit to not training on your data, and they are legitimate options. The honest argument is not "they steal your data".

The real differences are these:

  • Verifiability. With a contractual promise you trust; with your own infrastructure you check.
  • Data location. With a global provider data may be processed outside the EEA under safeguards; on-premise it does not leave.
  • Predictable cost. Fixed infrastructure instead of metered billing that scales without warning.
  • Continuity. No price changes, no models retired, no usage terms rewritten mid-project.

If your use case does not touch sensitive information and the volume is low, a cloud service is probably the better deal. We will say so.

03 Do open models perform as well as the large commercial ones?

It depends on the task, and here is the honest answer: for most business uses, yes; for the most demanding ones, not yet.

Today's open models handle document data extraction, classification, summarisation, drafting and question answering over internal documentation perfectly well. On complex multi-step reasoning, hard programming or long agentic tasks, frontier commercial models are still ahead.

The useful question is not which is better in the abstract but which is good enough for your specific task — and that is not settled by reading benchmarks. It is measured with your own documents and your own definition of a correct answer. That is exactly what the proof of concept is for.

04 What hardware do I need? Do I have to buy GPUs?

The variable that matters is GPU memory (VRAM), not raw compute. The model has to fit entirely in memory to run fast.

As an order of magnitude, quantised to 4 bits:

  • A 7–8 billion parameter model fits in about 6 GB of VRAM.
  • A 30–35 billion one, around 20 GB.
  • A 70 billion one, from 40 GB upwards.

On top of that you need memory for each concurrent conversation, which is what usually gets forgotten when sizing: an assistant for five people is not the same as one for five hundred.

And no, you do not always have to buy. You can start with rented dedicated GPU in European infrastructure, measure real usage for a few months, and decide with data in hand rather than a forecast.

05 Is it more expensive than paying per API call?

They are two different cost structures: an API is variable and grows with usage; your own infrastructure is fixed and does not care how hard you push it.

Hence the rule of thumb: owning infrastructure pays off when the GPU is busy. A GPU idle ninety per cent of the time is expensive however you look at it. An assistant used daily by a hundred people is a different story.

Before buying anything, the right exercise is to measure one real month of volume — how many queries, of what size — and compare that variable cost against the fixed cost of the equivalent hardware. We run that calculation in the initial assessment, and if the answer says the API suits you better, we will tell you.

06 What does European regulation require?

Two frameworks worth keeping apart.

GDPR. If personal data goes into the prompts, the AI provider acts as a processor and the Article 28 contract is required. If it also processes data outside the European Economic Area, you need safeguards for the transfer. Keeping the model inside your own perimeter simplifies the analysis, because there is neither a transfer nor an external processor.

EU AI Act (Regulation 2024/1689). It imposes obligations according to the risk level of the use, phased in over time. Most internal business uses — document assistants, classification, drafting — fall under minimal or limited risk, where the main requirement is transparency. Uses affecting people, such as recruitment or credit scoring, do fall into stricter categories.

This is general orientation, not legal advice: the specific classification depends on your case.

07 Can I connect AI to my ERP without leaking information?

Yes, and the key is a design principle: the assistant must never have more permissions than the person asking.

The common mistake is wiring the model in with an administrator account "so it can see everything". That turns the assistant into a way for anyone to read what they should not, without breaking any security at all — simply by asking.

The correct architecture inherits the user's identity:

  • Every query runs with the permissions of whoever asked.
  • The search index records what each profile may access, and filters before answering.
  • Every action is logged: who asked what, and which data was used to answer.

On Microsoft Dynamics — AX, NAV or 365 — this is familiar ground for us: we have been operating those platforms for years.

08 What if the model makes something up?

It will, sooner or later. Anyone who tells you otherwise is selling you something. What you can do is make sure that when it happens, it shows.

  • Always cite the source. If every answer links the document and paragraph it came from, checking it takes ten seconds.
  • Narrow the scope. An assistant that only answers about your documentation is wrong far less often than one with opinions about everything.
  • Human review where there are consequences. Not needed to draft a text; needed to decide about a person or sign off a number.
  • Measure continuously. A set of questions with known answers, run on every update, catches regressions before your users do.

An assistant that cites its sources is a tool. One that answers without showing where it got it from is a liability.

Company

Systems engineers, not middlemen

dataSource was built around a simple idea: high security and maximum performance should be the foundation of any service, not an add-on billed separately.

We started by taking business-critical applications — Microsoft Dynamics among them — into cloud environments where they ran faster and safer. Today we apply the same standard to artificial intelligence: useful power, kept in-house, with the data under control.

Technology independence

We recommend whatever actually solves your problem, whether or not you are a customer of the vendor behind it.

One technical contact

You always talk to the engineer who knows your platform, not to a level-1 desk opening a ticket.

Commitment to your data

GDPR-compliant processing, a known data location, and no use of your information to train models.

Contact

Tell us what you need to protect and what you need to speed up

You will get an honest technical assessment back: if your case does not need AI, we will say so.

Sales enquiries

Answered within 24 working hours.

Customer support

Direct line to the engineering team assigned to your platform.

Location

Spain · Services delivered across the EU

Next step

Shall we run a proof of concept?

A scoped pilot, with your data, on your infrastructure and with metrics agreed beforehand. No commitment to continue.