A secure company AI assistant
A secure company AI assistant is one shared AI layer that your employees and your systems use instead of dozens of private ChatGPT and Claude accounts. Sign-in runs through the Microsoft or Google accounts people already have, personal data is masked before it reaches the model, and every request is logged with who, when, what and at what cost.
The problem it solves
In most companies employees already work with public AI tools through private accounts. They paste in contracts, price lists and customer data, outside the view of IT and outside any rules. This is usually called shadow AI, and it is one of the largest gaps in company data protection today.
Banning AI does not remove it; it moves it to private phones where you see nothing. Buying a server sounds safe, but local models are markedly weaker and a server without a security team is in practice less secure than a certified data centre. Waiting does not help either: shadow AI is running in the company already.
What the AI layer does
- No new passwords. Employees sign in with the Microsoft or Google account they already have. When someone leaves the company, access ends automatically.
- Full audit. Every request is recorded: who asked, when, what and for how much. IT and management see it on one screen.
- Data protection at the input. Personal identification numbers, IBANs and contact details are masked automatically before anything is sent to the model.
- Vendor independence. The layer belongs to you. The model and the platform can be swapped without touching the rest of the company.
Where it runs: four deployment options
There is no single right answer. We choose the variant together, based on your data-protection requirements, your existing infrastructure and the capacity of your IT team, and we design it so that the choice can be changed later without a new project.
- Claude Enterprise, directly from the vendor. A finished enterprise application: company sign-in, user management, audit, a contractual ban on training on your data. Fastest start, in days. Data is processed outside the EU, so this fits where contractual protection is sufficient.
- AWS Bedrock in your own account, Frankfurt. Full EU data residency, your encryption keys, your security logs. The first choice when EU residency is required or AWS is already in place. Start in one to two weeks.
- Google Vertex AI in your own account, EU regions. The same principle for companies in the Google ecosystem. Start in one to two weeks.
- Microsoft Azure. Claude is available in Azure and a European deployment has been announced. For environments built purely on Microsoft technology we prepare the architecture so the move is a configuration change.
What it costs to run
Running costs come from the vendor, not from us, and they are small next to the licence costs companies already pay. As orientation from our proposals: consumption-based use of a model costs roughly half a cent to two cents per request, which for an actively used assistant comes to about two to eight euros per active user per month. Per-seat enterprise licences run at about 25 to 70 euros per user per month. A dedicated on-premises AI server starts at around 25,000 euros before anyone operates it.
Three model situations from our proposals: a company with 40 employees at roughly 1,100 to 1,200 euros per month of platform cost, 150 employees at roughly 1,800 to 2,200 euros, and 400 employees with an SAP integration at roughly 3,300 to 4,200 euros. The exact figure depends on the deployment option and on how heavily the assistant is used; we calculate it for your case in the assessment.
How the project runs
Five stages: assessment, architecture, implementation, enablement, operations. In the first week we map three questions: where you already run cloud and company identities, whether you require data processing in the EU, and who will look after the solution. Implementation then covers two to four processes with measurable impact, followed by role-based training on your team's actual tasks and monthly oversight.
Questions we get asked
Is our data used to train the model?
No. Every deployment option includes a contractual ban on training on your data, and in the AWS and Google variants the model runs inside your own cloud account under your own keys.
Can it stay inside the EU?
Yes. AWS Bedrock in Frankfurt and Google Vertex AI in EU regions give full EU data residency. Claude Enterprise processes data outside the EU under contractual protection, which is enough for many companies but not for all.
What about employees who paste in customer data?
Personal data such as identification numbers, IBANs, e-mail addresses and phone numbers is masked automatically before the request leaves your network. The audit log records that masking happened.
Why not just buy our own AI server?
A dedicated server means tens of thousands of euros up front, a markedly weaker model and security someone has to look after every day. A certified data centre has a security team around the clock and contractual guarantees, at a fraction of the cost. Where strict isolation is a real requirement, we compare a fully local variant with open models objectively.
Talk to us.
A 30-minute consultation on your scenarios. You will leave with a concrete assessment, whether we work together or not.