Real sovereignty, not a slogan
Your models and your data run where you decide: your own data centre, our private cloud in Spain, or a hybrid of both. No hidden dependencies, no telemetry to third parties, no contract surprises.
We design, deploy and operate AI and private cloud platforms for organisations that cannot afford to let their data leave home. High security and maximum performance underpin every service.
We have spent years moving business-critical applications to the cloud. AI does not change the principle: technology is only useful when the data is protected and the system responds when it matters.
Your models and your data run where you decide: your own data centre, our private cloud in Spain, or a hybrid of both. No hidden dependencies, no telemetry to third parties, no contract surprises.
Encryption in transit and at rest, network segmentation, least privilege and traceability of every access. Architecture driven by risk, not patched after the incident.
Before and after. We analyse, compare alternatives and publish real figures for latency, throughput and cost per query. If it does not improve, we do not ship it.
Using generative AI should not mean shipping your contracts, your source code or your customers' data to a provider you do not control. We build the whole stack inside your perimeter.
Language and vision models deployed on your own or dedicated GPUs, with private inference and no per-token usage caps.
We index your documentation, ERP and repositories into an internal vector database so the model answers with your information and cites the source.
Assistants that query Dynamics, your CRM or your databases with permissions inherited from the user and a full audit trail of every action.
Fixed infrastructure instead of unpredictable metered billing, with dashboards for usage, latency and real spend.
We can design the architecture, run the migration and stay on to operate it. Or step in only where you need us.
GPU sizing, open model deployment, inference server, high availability and controlled version upgrades.
Conversational search over your internal documentation, with permission control, source citation and continuous quality evaluation.
We move, scale or deploy almost any business application into a cloud environment without giving up control of the data.
Specialists in Dynamics AX, NAV and 365 on optimised infrastructure: service trials, migration and cost-contained rollout.
Analysis and technology benchmarking to get the most out of critical applications: I/O, memory, network and database bottlenecks.
Hardening, segmentation, secure service publishing, backups, disaster recovery and monitoring with proactive alerting.
We do not resell someone else's cloud. We maintain our own platform: network, secure service publishing, monitoring, backups and on-call. When something breaks, you talk to the people who built it.
We map the use case, the data behind it and the real legal and technical constraints.
A scoped pilot with your data and success metrics agreed up front. With an end date.
Final architecture, hardening, high availability, backups and documentation you keep.
Monitoring, controlled upgrades, performance reviews and continuous evolution of the service.
Straight answers, including the uncomfortable ones. If your case is not a fit, we would rather tell you on the first call.
It means running AI models on infrastructure you control — your own data centre, or a dedicated private cloud — instead of sending your data to someone else's service.
Sovereignty means three concrete, verifiable things:
It is not a different technology. To a large extent these are the same models you already know, deployed differently. The difference is in the architecture and the contract, not in magic.
In who holds the data and what you can verify. To be fair: the enterprise plans of the major providers do contractually commit to not training on your data, and they are legitimate options. The honest argument is not "they steal your data".
The real differences are these:
If your use case does not touch sensitive information and the volume is low, a cloud service is probably the better deal. We will say so.
It depends on the task, and here is the honest answer: for most business uses, yes; for the most demanding ones, not yet.
Today's open models handle document data extraction, classification, summarisation, drafting and question answering over internal documentation perfectly well. On complex multi-step reasoning, hard programming or long agentic tasks, frontier commercial models are still ahead.
The useful question is not which is better in the abstract but which is good enough for your specific task — and that is not settled by reading benchmarks. It is measured with your own documents and your own definition of a correct answer. That is exactly what the proof of concept is for.
The variable that matters is GPU memory (VRAM), not raw compute. The model has to fit entirely in memory to run fast.
As an order of magnitude, quantised to 4 bits:
On top of that you need memory for each concurrent conversation, which is what usually gets forgotten when sizing: an assistant for five people is not the same as one for five hundred.
And no, you do not always have to buy. You can start with rented dedicated GPU in European infrastructure, measure real usage for a few months, and decide with data in hand rather than a forecast.
They are two different cost structures: an API is variable and grows with usage; your own infrastructure is fixed and does not care how hard you push it.
Hence the rule of thumb: owning infrastructure pays off when the GPU is busy. A GPU idle ninety per cent of the time is expensive however you look at it. An assistant used daily by a hundred people is a different story.
Before buying anything, the right exercise is to measure one real month of volume — how many queries, of what size — and compare that variable cost against the fixed cost of the equivalent hardware. We run that calculation in the initial assessment, and if the answer says the API suits you better, we will tell you.
Two frameworks worth keeping apart.
GDPR. If personal data goes into the prompts, the AI provider acts as a processor and the Article 28 contract is required. If it also processes data outside the European Economic Area, you need safeguards for the transfer. Keeping the model inside your own perimeter simplifies the analysis, because there is neither a transfer nor an external processor.
EU AI Act (Regulation 2024/1689). It imposes obligations according to the risk level of the use, phased in over time. Most internal business uses — document assistants, classification, drafting — fall under minimal or limited risk, where the main requirement is transparency. Uses affecting people, such as recruitment or credit scoring, do fall into stricter categories.
This is general orientation, not legal advice: the specific classification depends on your case.
Yes, and the key is a design principle: the assistant must never have more permissions than the person asking.
The common mistake is wiring the model in with an administrator account "so it can see everything". That turns the assistant into a way for anyone to read what they should not, without breaking any security at all — simply by asking.
The correct architecture inherits the user's identity:
On Microsoft Dynamics — AX, NAV or 365 — this is familiar ground for us: we have been operating those platforms for years.
It will, sooner or later. Anyone who tells you otherwise is selling you something. What you can do is make sure that when it happens, it shows.
An assistant that cites its sources is a tool. One that answers without showing where it got it from is a liability.
dataSource was built around a simple idea: high security and maximum performance should be the foundation of any service, not an add-on billed separately.
We started by taking business-critical applications — Microsoft Dynamics among them — into cloud environments where they ran faster and safer. Today we apply the same standard to artificial intelligence: useful power, kept in-house, with the data under control.
We recommend whatever actually solves your problem, whether or not you are a customer of the vendor behind it.
You always talk to the engineer who knows your platform, not to a level-1 desk opening a ticket.
GDPR-compliant processing, a known data location, and no use of your information to train models.
You will get an honest technical assessment back: if your case does not need AI, we will say so.
Answered within 24 working hours.
Direct line to the engineering team assigned to your platform.
Spain · Services delivered across the EU
A scoped pilot, with your data, on your infrastructure and with metrics agreed beforehand. No commitment to continue.