The part that is actually hard

AI helps most with the work you cannot safely send it.

Running a model privately is becoming ordinary. Running one safely across a whole organisation is not.

A controlled work environment with access permissions and data kept within it — not a glowing server room.

Apple, Microsoft and the open-model ecosystem are all making private inference ordinary, and we expect that to continue. We are not going to win a hardware race and we are not going to pretend to be in one.

What does not commoditise is everything around the model: which records a request may read, who is permitted to ask, how long anything is retained, the human review step on every output, and the workflow the answer lands in. That is the part we build.

Two things are worth knowing before you decide a laptop can do this instead.

Context. Apple's on-device model works within a 4,096-token window shared between what you put in and what comes back; Private Cloud Compute raises that to 32,000, also shared. Those sizes suit a document. They do not suit a two-year case history read in one pass — which is the task that saves your team the most time. That does not mean it cannot be done on your own hardware: retrieval, chunking or a larger-context local model will get you there. It means somebody has to design the retrieval, the permissions, the retention and the review step. The model is one component of the problem, not the whole of it.

One person is not an organisation. Microsoft Foundry Local is documented as built for a single user on their own device, with multi-user workloads pointed at a server runtime. A device-local model gives one member of staff a private assistant. It does not give your organisation shared, governed, auditable access to its own records — with roles, retention and an audit trail your board can inspect.

We run our own on-premises AI server so you do not have to. If you would rather run it on your own hardware, or on the devices your team already owns, we will help you do that instead — and we will tell you honestly which of the three fits your governance requirements.

We built our own AI server on-premises so sensitive chats, case data and meeting summaries can be processed within our controlled environment, reducing the need to send sensitive information to external AI services and lowering certain data-exposure risks that could put vulnerable or sensitive communities at risk.

Three routes, by how much control you need.

These are a path, not a lock-in. Many customers start on the subscription and move to customer-owned infrastructure as their governance tightens — and we price that transition transparently.

Route 1 is Trellistry Operations · Private AI — module six of the platform. Routes 2 and 3 are Trellistry Private AI Services: standalone capability-building and dedicated deployments sold without an Operations subscription, so a buyer of a dedicated deployment is not buying a platform licence.

1. Subscribe

A governed environment we run, with your policies applied.

Who operates it
We do
Where content is processed
Our controlled environment. Not sent to external AI services. Metadata only — no content logs.
Best when
You want governed AI for sensitive work now, without standing up infrastructure or in-house expertise.
What we deliver
Access with your roles and retention applied, allowances, admin controls, onboarding and training.
Commitment
Monthly subscription, from S$79/month.

2. Learn to run your own

Build your own capability — server, workstation, or the devices you already own.

Who operates it
Your team, after we hand over
Where content is processed
On your chosen hardware, within your control
Best when
You want the capability in-house permanently and have someone technical to own it.
What we deliver
The design work around the model: data-flow mapping, access control, retrieval setup, retention, the review step, update and incident procedures — we build the first environment with you, document it, and hand over operations.
Commitment
Fixed-scope training engagement, from S$3,500.

3. We build and run it for you

Customer-owned infrastructure, for organisations whose governance requires it.

Who operates it
We do, under your control
Where content is processed
On infrastructure you own
Best when
Your governance requires the infrastructure on-site and owned by you, but you don't want to run it yourself.
What we deliver
Architecture design, hardware specification and procurement, installation, access-control configuration, workflow integration, documented retention and backup, staff training, ongoing maintenance and security support.
Commitment
Project fee from S$25,000, quoted to scope, plus S$800–1,500/month maintenance.

What you can do with it today.

Secure meeting minutes

Authorised recording → draft minutes, decisions, action items.

Case-note summarisation

Summarise case notes and draft handover documents when staff change.

Draft communications

Draft from approved internal material — newsletters, updates, reports.

Policy and handbook search

Search your own policies, handbooks and internal documents in natural language.

Translation

Translate resources between languages without exposing content externally.

Spreadsheet reconciliation

Reconcile and merge spreadsheets, generate timetabling drafts and reports.

Every AI output is a draft for human review, never an authoritative record.

A calm, controlled work environment — the setting where sensitive material is processed, kept within the room.

What matters, not the model of the month.

Full-precision inference, long context sufficient to read a whole case history or spreadsheet in one pass, our own hardware, and no external API calls. The specific models change as better ones ship; the guarantees do not.

Current infrastructure details — models, precision and hardware — are set out on our security page, verified and dated.

Five questions to ask any AI vendor.

These convert a privacy conviction into something checkable. Ask any provider; here are our answers.

QuestionOur answer
Where was it processed?On our own on-premises server, within our controlled environment.
Was anything retained, and for how long?Content is processed and discarded. Usage metadata (timestamps, token counts) is retained for billing. No content logs.
Was it used for training?No. Your content is never used to train any model.
Is anything stored for retrieval?Only if you configure RAG (retrieval) with your own documents — and that data stays within your environment.
Could it end up in a future model version?No. We do not train models on customer data.

Subscription tiers.

Every tier carries defined allowances — transcription hours, model class, monthly credits, concurrent users, storage, support level. We don't offer unlimited anything, and the reason is honest: it protects capacity for everyone sharing the infrastructure.

Essentials

Up to 5 users

S$79/mo

Team

Up to 20 users

S$179/mo

Ministry Partner

Up to 50 users

S$399/mo

Enterprise / Denominational

50+ users

from S$799/mo

AI here never replaces pastoral judgement, safeguarding decisions, counselling or spiritual discernment. It removes the coordination around that work, never the judgement at its centre.

This is documented, not speculative.

Our privacy argument rests on citable public reporting, not assertion. Presented soberly — this is evidence, not fear-mongering.

1. Retention windows are a real exposure, even with good providers.

Mainstream providers publish no-default-training commitments for business and API data, and eligible customers can request zero-data-retention controls. But standard abuse-monitoring processes may still retain inputs for up to 30 days unless those controls are approved. If a breach occurs during that window, or if someone with access during that window acts maliciously, the content is still exposed.

2. Provider bugs have exposed user data.

OpenAI disclosed a March 2023 software bug in which some ChatGPT users could see other users' conversation titles, and in a limited nine-hour window some Plus subscribers' names, email addresses, billing addresses and partial payment card information could have been exposed.

Source: OpenAI incident write-up

3. Regulators treat chatbot inputs as a breach risk.

The Dutch Data Protection Authority has warned that entering personal data into AI chatbots can itself constitute or cause a personal data breach, citing notified cases including an employee of a medical practice entering patient medical data and a telecoms employee entering a customer address file.

Source: Dutch DPA advisory

4. The AI supply chain itself is a target.

In March 2026 a supply-chain compromise of LiteLLM — a widely used open-source AI gateway — resulted in a reconstructed exposure dataset covering more than 2,500 organisations and roughly 434,000 CI/CD pipelines, including cloud credentials, SSH keys and AI provider API keys. The malicious packages were live for around 40 minutes. Singapore-linked entities, including listed companies and financial-sector firms, appear in the reconstructed dataset as potential exposure requiring investigation, not confirmed compromise.

Sources: The Hacker News · SecurityWeek · Protos Labs (Singapore assessment)

5. Model memorisation is demonstrated, not hypothetical.

Peer-reviewed research has shown that language models can memorise and reproduce training data verbatim, including personally identifying information. Carlini and colleagues demonstrated extraction of verbatim training examples from language models; later work demonstrated substantially larger-scale extraction against several model families including a production version of ChatGPT, showing that alignment alone does not eliminate memorisation. It would be wrong to describe model-mediated leakage of personal information as merely hypothetical.

None of this means AI is unusable. It means the question "where was this processed, and who could see it" has to have an answer. That is what we exist to give you.

The Trellistry Operations guarantee.

Try it for three months. If it isn't working, we fix it free — or refund your subscription in full and hand back a clean export of your data. No lock-in.

And it should cost you less than the alternative. Before you start, we agree a baseline with you: what your team currently spends on administration, in hours or in dollars, whichever you'd rather be measured on. If that baseline hasn't fallen after three months, the same refund applies.

Applies to the Trellistry Operations subscription. Professional services are covered against the scope agreed in writing for that engagement. Kingsfold memberships and subscriptions are separate products and are not covered. Donors, investors and supporters interested in Kingsfold are welcome to contact us.

Ready to use AI on the work that matters most?

Book a free 30-minute consultation. We'll help you understand which delivery model fits your governance needs.

Book a free 30-minute consultation