Sovereign AI · On-premise · Private cloud

Sovereign AI, running on your own infrastructure.

Knowledge assistants, voice agents and automation deployed on-premise or in your private cloud. Your data, models and logs never leave your control.

On your servers No data sent to third-party AI You own the code
Trusted by government and enterprise clientsReferences and case details shared in discovery, or on request
GDPREU AI ActHIPAAGLBADPDP ActRBI · SEBI
YOUR TEAM Chat Voice API
YOUR INFRASTRUCTURE · ON-PREM OR PRIVATE CLOUD
DeepVox core running
retrieval permissions automation audit
YOUR DATA
Documents Wiki Records ERP Email
YOUR MODELS
Open-weight LLM Speech
✓ chat · clause found in contract · access checked · logged
Public AI APIs
Data sent outside: 0 bytes

Your knowledge is scattered. Your data can't leave the building.

01

Answers live everywhere

Wikis, drives, inboxes and legacy systems each hold part of the picture, and nobody can search them all.

02

Public AI is off the table

Patient records, client files and financial data can't be sent to a third-party AI service, whatever region it's hosted in.

03

Vendors want to lock you in

Products priced per seat, per document or per conversation, with no way out that doesn't mean starting over.

What we build

Three parts of one foundation.

Most clients start with one and grow into the others.

SERVICES · where most begin

Knowledge & retrieval systems

A governed knowledge base, retrieval that respects permissions, and an assistant over the top. Built from open source, integrated with what you already run, owned by you.

  • Access by department, role and person
  • Kept accurate: document owners, review dates and checks that flag outdated content
  • Small models fine-tuned on your domain where they beat retrieval alone, with the weights yours
Learn more
PRODUCT · the alternative

The DeepVox platform

Our own assistant layer, for teams that want speed and a supported platform. When it's a candidate we say so, and score it against the alternatives on the same criteria.

Learn more
AUTOMATION · where value compounds

End-to-end AI automation

Not a chatbot bolted on. The system reads the document, applies the rules, updates the record, routes the exception to a person and logs everything.

Learn more
ONE FOUNDATION Your knowledge·Retrieval·Access control·Audit trail built once, on your infrastructure
One core, three ways in

The experience your people already know, on infrastructure you control.

Retrieval, permissions, business logic and the audit trail are built once. The channel is configuration: ask in chat, on a call, or from another system, including AI tools like Claude, ChatGPT or Cursor over MCP. Same answer, same source, in the language people ask in, even when the document is written in another.

Explore the platform
INTRANET ASSISTANT
What's our policy on remote access for contractors?
Contractors get VPN access only from a managed device, approved by their team lead, for the length of their contract.IT Security Policy v4 · §3.2
✓ same retrieval ✓ same permissions ✓ same source ✓ same audit entry
Connectors

Connects to what you already run.

Your knowledge stays where it lives. Connectors run inside your infrastructure, keep content in sync, and carry each source's permissions across, so people only see answers from what they're already allowed to open.

YOUR OWN SYSTEMS

Databases, internal tools, legacy platforms. If it has an API, a database or an export, we build the connector during customization, and the code is yours.

COVERS

Files · wikis · email and chat · tickets · CRM and ERP · databases

Source permissions respected Continuous sync, no manual uploads Runs inside your infrastructure All 27 connectors
Access control

You decide who uses which agent, on what data.

We configure access against your real permission model during customization: by department, by role, by person. Enforced on your infrastructure, and every decision logged.

Example configuration. Roles and agents are set up to match your organisation.
WHO Policy assistantinternal Contract reviewinternal Invoice automationinternal Patient voice lineexternal
FinanceAsk—Ask + act—
HRAsk———
LegalAskAsk + act——
Patient services leadone named personAsk——Manage
Patients calling inoutside your organisation———Ask · own records only

By department, then by person

Assign agents to teams, then grant or restrict individuals within them.

Internal and external, kept apart

Customer- and patient-facing agents run with a narrower scope and never reach internal knowledge they don't need.

Asking is not acting

Reading an answer and changing a record are separate permissions, with approval gates where you want them.

Departments and roles sync from Entra ID, Keycloak or your existing directory. Nothing to set up twice.

How access control works
By team

What it looks like on a Tuesday.

Each team gets the agents it needs, and only those. A few typical starting points:

LEGAL

Contract review

Clauses flagged against your playbook, drafts for a lawyer to approve.

automation · chat
HR

Policy answers

Leave, benefits and handbook questions answered with the source attached.

chat
FINANCE

Invoice automation

Invoices read, matched and routed for approval, exceptions to a person.

automation
SUPPORT

Voice line

Calls answered, requests resolved, records updated, every call logged.

voice
IT

Helpdesk

Access requests, how-tos and known issues handled before they become tickets.

chat · voice · api
Our approach

We start with your requirement, not our demo.

Most vendors arrive with a product and work backwards. We arrive with a method: discovery first, then a transparent map from what you need to the tools that fit. Often that means open-source components you keep outright. The decision rests on evidence, not on what we happen to sell.

  1. 01

    Discovery

    What knowledge exists and where, who may see what, which processes cost time, where the regulatory boundary sits. A paid engagement with a deliverable, not a sales call.

  2. 02

    Mapping

    Requirements become weighted criteria. Two or three candidates per layer, scored on fit, integration, security, cost and operational burden, with the working shown.

    EXAMPLE SCORING · ONE LAYERWEIGHTED / 100
    Open-source stack 86 DeepVox platform 78 Vendor product 64
  3. 03

    Customization

    Configured and integrated against your real systems and permission model. What's missing gets built, and the source is yours.

  4. 04

    Operation

    Deployment, training, runbooks, then ongoing support if you want it. If not, run it yourself or hand it to someone else.

Voice

A voice agent that does more than talk.

It takes the call, resolves the request, updates the record and logs the interaction, because it sits on the same automation layer as everything else. Speech recognition and synthesis run on your infrastructure too.

Explore voice agents Hear a live demo
Inbound call · live on-prem speech · no cloud
I need to move my MRI appointment on Thursday. Is anything free on Friday?
Done. You're booked for Friday at 10:30, and a confirmation is on its way by text.
✓ intent · reschedule_appointment
✓ identity · patient verified
✓ policy · rebooking rules retrieved
✓ system · schedule record updated
✓ audit · call logged on-prem
Inbound voice agentsUnderstand intent, retrieve, resolve or route
Outbound voiceReminders, confirmations, follow-ups, surveys
Call triage and routingIntent detected on the first sentence
Live agent assistAnswers surfaced mid-call, notes drafted after
Transcription and QASummaries, actions, compliance checks at volume
Voice data captureFill forms, update records, open tickets by speaking
IVR replacementNatural conversation instead of menu trees
Voice notes to recordsClinicians, inspectors and field teams dictate
What we automate

From answering questions to removing work.

Document processing

Intake, classification, extraction, validation, routing, filing.

Tickets and requests

Triage, routing, drafted responses, resolution, escalation.

Data pipelines

Ingestion, cleaning, enrichment, syncing between systems.

Approvals and workflows

Multi-step routing, rules-based decisions, sign-off tracking.

Content and reports

Scheduled assembly, narrative generation, distribution.

Monitoring and alerting

Watching sources for change, filtering signal, notifying.

Human-in-the-loop by design.

Approval gates, confidence thresholds and full audit trails are on in every automation by default. Built for the auditor, not around them.

1 · AI DRAFTS
Supplier contract draft · 3 clauses flagged
2 · A PERSON APPROVES
Supplier contract APPROVED · M. WEBER
3 · LOGGED
14:02 drafted · model 14:09 approved · M. Weber 14:09 filed · contract system audit entry written
Built for regulated markets

Data control isn't a hosting region. It's who runs the stack.

Different rulebooks, one answer: the system runs on infrastructure you control, so sensitive data never leaves your boundary. We design for the rules in each market before we write a line of code.

Europe

EU · DACH · CH
GDPR · CLOUD Act exposure

A local data centre run by a US provider is still reachable. Self-hosted closes the gap.

§203 StGB

For German lawyers, tax advisers and doctors, self-hosting is a requirement, not a preference.

DORA · revFADP

ICT third-party obligations for finance, and a Swiss hosting story for Switzerland.

EU AI Act

Classification documented, and the high-risk line flagged before you cross it.

United States

Federal · State
HIPAA

Patient data stays inside your environment, with no third-party AI service in the data path.

GLBA · SEC

Customer financial information protected under the controls your examiners already review.

Attorney–client privilege

Client files and work product never leave the firm's systems.

CCPA / CPRA · state laws

Access, deletion and audit built in, so privacy requests can be answered from the logs.

India

National · Sector
DPDP Act · DPDP Rules 2025

Consent, purpose limits and breach duties, with every interaction logged for accountability.

RBI

Payment system data stored only in India, on infrastructure you can show the regulator.

SEBI CSCRF

Cyber-resilience controls met on infrastructure you control, ready if the data-localisation control returns.

IRDAI · health data

Insurer and hospital records kept in-country, under your own access rules.

Sectors Healthcare Financial services Legal & professional services Insurance Public sector Manufacturing
No lock-in

Exit cost is knowledge transfer, not licence forfeiture.

  • A running system on your own infrastructure
  • Source code for everything we built, from the first commit
  • Open formats and documented APIs throughout
  • Runbooks your team, or a successor, can take over
  • A rehearsed exit test, walked through before you ask
THE STACK WE WORK IN

Open, proven, swappable.

We don't commit to a stack in advance; the mapping step decides. This is the portfolio we go deep in. Every model call routes through a gateway, so changing providers is configuration, not a rebuild.

KNOWLEDGE MANAGEMENTBookStack · XWiki
ASSISTANT & RETRIEVALOnyx · Haystack · LlamaIndex · LibreChat — or the DeepVox platform
DOCUMENT INGESTIONDocling · Unstructured · Apache Tika · Tesseract
INDEX & VECTOR STOREPostgreSQL + pgvector · Qdrant · OpenSearch
PERMISSIONS & IDENTITYOpen Policy Agent · Keycloak · Entra ID · purpose-built services
EMBEDDINGS & RERANKINGBGE-M3 · bge-reranker
MODELSconfig change Qwen, Mistral and other open-weight models; hosted providers where you prefer. Small models fine-tuned on your domain, on your hardware, with the weights yours. active → Qwen · self-hosted
MODEL GATEWAYLiteLLMEvery model call routes here. No model lock-in, by architecture. See usage and model cost per department.
MODEL SERVINGvLLM · SGLang · Ollama
VOICEWhisper and open speech recognition · open text-to-speech
OBSERVABILITYLangfuse · Phoenix · Grafana stack
WORKFLOW & ORCHESTRATIONn8n · custom services · Kubernetes · Helm

Licence literacy included. Products relicense, and many "open" platforms paywall the SSO, RBAC and audit features regulated teams need. We flag it before you commit.

Who builds it

AI research, retrieval engineering and privacy law, in one founding team.

That's why compliance is designed in from the first conversation, not bolted on before launch.

Meet the team

Lohit Kapoor

Founding member

PhD, with 12 years of industry experience.

Atita Arora

Founding member

Retrieval systems specialist, formerly at Qdrant and Voyage AI.

Varun Jagannath

Founding member

AI privacy lawyer, educated at Leiden University.

How we compare

Most options sell you a product. We hand you a system.

The four ways organisations usually buy AI over their knowledge, and where we differ. When one of them fits you better, we'll tell you in discovery.

DeepVox Per-seat AI searche.g. Glean, Slite Microsoft 365 CopilotMicrosoft Enterprise search platformse.g. Mindbreeze, Sinequa Sovereign AI platformse.g. Cohere North, Langdock
Runs fully on your infrastructure ✓On-prem or private cloud ◐Vendor cloud, or your cloud run by the vendor ✕Microsoft's cloud ✓On-prem options ✓On-prem options
Who operates it ✓You, or us if you prefer ✕The vendor ✕Microsoft ◐You or the vendor ◐You or the vendor
What the price grows with ✓Scope of work. Infrastructure at cost ✕Every user ✕Every user, on top of Microsoft 365 ◐Documents indexed, or licence ◐Users or licence
You own the code ✓From the first commit ✕Licensed product ✕Licensed product ✕Licensed product ✕Licensed product
Native voice agents ✓Inbound, outbound, in-app —Not a core offering —Not a core offering —Not a core offering —Not a core offering
Built around your requirement ✓Options scored openly, ours included —Their product —Their product —Their product —Their product
✓Yes ◐Partly or depends ✕No —Not a core offering

Categories summarise vendors' publicly available information as of October 2026. Individual products vary. Ask us for a like-for-like assessment during discovery.

Detailed comparisons
How you buy

Staged, so each step earns the next.

Not priced per user, per document or per conversation. Infrastructure is contracted by you at cost, so 150 users or 500 costs materially the same.

Pricing and stages in detail
COST Per-seat licence DeepVox 50 150 500 users
Illustrative shape, not a quote. Your costs depend on your infrastructure.
STAGE 1 · 2 WEEKS

Discovery sprint

Requirements mapped to candidate stacks, licence risk register, regulatory assessment, costed recommendation.

Fixed price · credited to the next stage
STAGE 2 · 6–10 WEEKS

Proof of concept

A working system on your own content, measured against an evaluation set you keep.

Fixed price · acceptance criteria
STAGE 3

Production build

Full deployment, integrations, permissions, training and handover.

Fixed scope · staged
STAGE 4 · OPTIONAL

Managed support

Operation, model updates, governance reporting, continuous improvement. Backed by a 99.9% uptime SLA.

Monthly retainer

Fair questions.

Aren't open-source models weaker?

At the frontier, yes, and we'll say so. For grounded answers over curated documentation the gap is narrow, and reranking plus well-structured knowledge closes much of it. Where it helps, a small model fine-tuned on your domain can match larger general models on your tasks. We benchmark candidates on your own questions during discovery, and because the gateway abstracts the provider, adding a hosted model later is configuration.

Can't we just use Microsoft Copilot?

Sometimes, yes. It falls short when data can't leave the tenancy boundary the way Copilot needs, when professional secrecy applies, when knowledge lives outside Microsoft, or when your permission model or automation goes beyond what it can express. If none of that applies, we'll tell you.

You have your own product. How are you neutral?

We disclose it up front. When our platform is a candidate, it's scored on the same criteria as everything else, and we'll accept independent review of the scoring. Clients who want full ownership take the open-source route.

What happens if we want to leave?

You own the source from the first commit, the evaluation set is yours, and a fixed-price handover package is quotable at any point. Switching costs you documentation transfer, not the project.

How do you handle voice latency and call-recording consent?

Speech recognition, the model and speech synthesis all run on your infrastructure and stream into each other, so callers hear a reply in about a second, and they can interrupt at any time. We measure it on your hardware during the proof of concept. Every call opens with a recording notice and a way to continue without it. You choose whether to keep audio, transcripts or neither, and for how long, and consent is logged with the call. We configure this for the rules in each market you operate in.

Is our data used to train anyone's models?

Only your own. The models run inside your environment, and your documents, questions and answers stay there. If we fine-tune a model on your data, that happens on your infrastructure and the resulting model belongs to you. Nothing is sent to us or to a model provider unless you choose to add a hosted model for a specific use.

How accurate are the answers?

Every answer is grounded in your documents and cites its source, so people can check it. During the proof of concept we measure accuracy against an evaluation set built from your own questions, and that set stays with you to re-test any future change.

Does it respect the permissions we already have?

Yes. Connectors carry each source's permissions across, and departments and roles come from your existing directory. People only get answers from content they're already allowed to open.

How long until we have something working?

A two-week discovery sprint gives you a costed recommendation. A proof of concept on your own content follows in six to ten weeks, measured against acceptance criteria agreed up front.

What hardware do we need?

It depends on the models, the number of users and whether you run voice. We size it during discovery. Small fine-tuned models need far less than large general ones, which often keeps the footprint modest. If you aren't ready to buy GPUs, you can start with a hosted model through the gateway and move on-prem later without rebuilding.

You're a small firm. What if you disappear?

That risk is designed out. Commitments are staged, so your exposure is bounded at every step. You own all source code from the first commit, and the runbooks let your team or another supplier take over. Losing us would cost you documentation transfer, not the project.

Does the EU AI Act apply to this?

Most internal knowledge assistants are not high-risk, but the classification has to be documented rather than assumed. Some automations, such as CV screening, credit scoring or anything acting as a medical device, carry heavy obligations. We tell you where the line is before you cross it.

Which regions do you work in?

Europe, the United States and India, from offices in Berlin, Dover and Hyderabad. We design for the rules in each market: GDPR, the EU AI Act and DORA in Europe; HIPAA, GLBA and state privacy laws in the US; and the DPDP Act, RBI and SEBI requirements in India.

Start with two weeks of evidence, not a sales call.

A fixed-price discovery sprint, credited against whatever comes next. Or write to us at sales@deepvox.ai.

Book a discovery sprint