Running a model privately is becoming ordinary. Running one safely across a whole organisation is not.
Apple, Microsoft and the open-model ecosystem are all making private inference ordinary, and we expect that to continue. We are not going to win a hardware race and we are not going to pretend to be in one.
What does not commoditise is everything around the model: which records a request may read, who is permitted to ask, how long anything is retained, the human review step on every output, and the workflow the answer lands in. That is the part we build.
Two things are worth knowing before you decide a laptop can do this instead.
Context. Apple's on-device model works within a 4,096-token window shared between what you put in and what comes back; Private Cloud Compute raises that to 32,000, also shared. Those sizes suit a document. They do not suit a two-year case history read in one pass — which is the task that saves your team the most time. That does not mean it cannot be done on your own hardware: retrieval, chunking or a larger-context local model will get you there. It means somebody has to design the retrieval, the permissions, the retention and the review step. The model is one component of the problem, not the whole of it.
One person is not an organisation. Microsoft Foundry Local is documented as built for a single user on their own device, with multi-user workloads pointed at a server runtime. A device-local model gives one member of staff a private assistant. It does not give your organisation shared, governed, auditable access to its own records — with roles, retention and an audit trail your board can inspect.
We run our own on-premises AI server so you do not have to. If you would rather run it on your own hardware, or on the devices your team already owns, we will help you do that instead — and we will tell you honestly which of the three fits your governance requirements.
We built our own AI server on-premises so sensitive chats, case data and meeting summaries can be processed within our controlled environment, reducing the need to send sensitive information to external AI services and lowering certain data-exposure risks that could put vulnerable or sensitive communities at risk.
These are a path, not a lock-in. Many customers start on the subscription and move to customer-owned infrastructure as their governance tightens — and we price that transition transparently.
Route 1 is Trellistry Operations · Private AI — module six of the platform. Routes 2 and 3 are Trellistry Private AI Services: standalone capability-building and dedicated deployments sold without an Operations subscription, so a buyer of a dedicated deployment is not buying a platform licence.
A governed environment we run, with your policies applied.
Build your own capability — server, workstation, or the devices you already own.
Customer-owned infrastructure, for organisations whose governance requires it.
Authorised recording → draft minutes, decisions, action items.
Summarise case notes and draft handover documents when staff change.
Draft from approved internal material — newsletters, updates, reports.
Search your own policies, handbooks and internal documents in natural language.
Translate resources between languages without exposing content externally.
Reconcile and merge spreadsheets, generate timetabling drafts and reports.
Every AI output is a draft for human review, never an authoritative record.
Full-precision inference, long context sufficient to read a whole case history or spreadsheet in one pass, our own hardware, and no external API calls. The specific models change as better ones ship; the guarantees do not.
Current infrastructure details — models, precision and hardware — are set out on our security page, verified and dated.
These convert a privacy conviction into something checkable. Ask any provider; here are our answers.
| Question | Our answer |
|---|---|
| Where was it processed? | On our own on-premises server, within our controlled environment. |
| Was anything retained, and for how long? | Content is processed and discarded. Usage metadata (timestamps, token counts) is retained for billing. No content logs. |
| Was it used for training? | No. Your content is never used to train any model. |
| Is anything stored for retrieval? | Only if you configure RAG (retrieval) with your own documents — and that data stays within your environment. |
| Could it end up in a future model version? | No. We do not train models on customer data. |
Every tier carries defined allowances — transcription hours, model class, monthly credits, concurrent users, storage, support level. We don't offer unlimited anything, and the reason is honest: it protects capacity for everyone sharing the infrastructure.
Up to 5 users
S$79/mo
Up to 20 users
S$179/mo
Up to 50 users
S$399/mo
50+ users
from S$799/mo
AI here never replaces pastoral judgement, safeguarding decisions, counselling or spiritual discernment. It removes the coordination around that work, never the judgement at its centre.
Our privacy argument rests on citable public reporting, not assertion. Presented soberly — this is evidence, not fear-mongering.
Mainstream providers publish no-default-training commitments for business and API data, and eligible customers can request zero-data-retention controls. But standard abuse-monitoring processes may still retain inputs for up to 30 days unless those controls are approved. If a breach occurs during that window, or if someone with access during that window acts maliciously, the content is still exposed.
OpenAI disclosed a March 2023 software bug in which some ChatGPT users could see other users' conversation titles, and in a limited nine-hour window some Plus subscribers' names, email addresses, billing addresses and partial payment card information could have been exposed.
Source: OpenAI incident write-up
The Dutch Data Protection Authority has warned that entering personal data into AI chatbots can itself constitute or cause a personal data breach, citing notified cases including an employee of a medical practice entering patient medical data and a telecoms employee entering a customer address file.
Source: Dutch DPA advisory
In March 2026 a supply-chain compromise of LiteLLM — a widely used open-source AI gateway — resulted in a reconstructed exposure dataset covering more than 2,500 organisations and roughly 434,000 CI/CD pipelines, including cloud credentials, SSH keys and AI provider API keys. The malicious packages were live for around 40 minutes. Singapore-linked entities, including listed companies and financial-sector firms, appear in the reconstructed dataset as potential exposure requiring investigation, not confirmed compromise.
Sources: The Hacker News · SecurityWeek · Protos Labs (Singapore assessment)
Peer-reviewed research has shown that language models can memorise and reproduce training data verbatim, including personally identifying information. Carlini and colleagues demonstrated extraction of verbatim training examples from language models; later work demonstrated substantially larger-scale extraction against several model families including a production version of ChatGPT, showing that alignment alone does not eliminate memorisation. It would be wrong to describe model-mediated leakage of personal information as merely hypothetical.
None of this means AI is unusable. It means the question "where was this processed, and who could see it" has to have an answer. That is what we exist to give you.
Try it for three months. If it isn't working, we fix it free — or refund your subscription in full and hand back a clean export of your data. No lock-in.
And it should cost you less than the alternative. Before you start, we agree a baseline with you: what your team currently spends on administration, in hours or in dollars, whichever you'd rather be measured on. If that baseline hasn't fallen after three months, the same refund applies.
Applies to the Trellistry Operations subscription. Professional services are covered against the scope agreed in writing for that engagement. Kingsfold memberships and subscriptions are separate products and are not covered. Donors, investors and supporters interested in Kingsfold are welcome to contact us.
Book a free 30-minute consultation. We'll help you understand which delivery model fits your governance needs.
Book a free 30-minute consultation