Skip to main content

Platform

The stack we start from, and the reasoning behind it.

This is not a product you license. It is the reference architecture and agent runtime our engagements converge on, published so you can argue with it before you hire us.

On-premises reference architectureSix layers inside the client security boundary. From the bottom: infrastructure (GPU nodes, block and object storage, network boundary); serving (inference engines, model router, KV and prompt cache); data and retrieval (vector index, document store, connectors); agent runtime (planner, tool broker, memory, policy engine, state store); governance (identity, authorisation, audit log, evaluation, observability), which spans the full width; and interfaces (APIs, internal UI, existing line-of-business systems). Nothing crosses the boundary outward.client security boundary, no egressINTERFACESInternal APIsOIDC-protectedOperator consoletraces, approvalsLine-of-business systemsITSM, CRM, EDRMBatch / scheduled jobsAGENT RUNTIMEPlannergraph executionTool brokertyped contracts, MCPPolicy engineleast privilegeMemoryworking / episodicState storecheckpoint + replayDATA & RETRIEVALVector indexhybrid + rerankDocument storeACL-awareFeature storeSource connectorsSERVINGInference enginevLLM / SGLang / NIMModel routersize-to-taskPrompt + KV cacheEmbedding + rerankINFRASTRUCTUREGPU nodes (Kubernetes, MIG-aware)Block + object storageSegmented network, no outbound routeGovernance plane · identity (AD/LDAP, OIDC) · authorisation · immutable audit log · evaluation · OpenTelemetry
Figure 1. The reference stack. The governance plane spans every layer because retrofitting it to one layer at a time does not work.

Start with the constraint.

Most of these projects are shaped by what you cannot do rather than what you want. Data that cannot leave the estate, a model you cannot host with a third party, a decision somebody has to justify to a regulator. Tell us yours and we will say honestly whether we can work inside it.