custeo

Decide, per request,
where AI runs.
And prove it.

Custeo is the control plane for confidential European AI. It places every request on a destination your policy allows, keeps working when a provider does not, and leaves a record you can hand to a regulator.

// logged / proven / in jurisdiction

The problem

Residency is not sovereignty.

A processing agreement with an American provider gives contractual protection. It does not change who has legal reach over the data. An EU region does not change it either, because control follows the provider, not the postcode.

So firms with a duty of confidentiality are left choosing between a blanket ban, a licence they cannot fully defend, and staff quietly pasting client files into public tools. When the regulator asks where a file was processed, there is no answer.

What a provider cannot tell you

  • Whether the work should have gone there at all.
  • What was removed before it left.
  • What happened at every other provider you use.
  • Who asked, and whether they were allowed to.
How it works

Every request is placed, not sent.

An application feeds the Custeo control plane, which places each request on a permitted, healthy destination An application sends every request to the Custeo control plane, which asks what is in it, how far it may go and which provider is available. Work goes to the firm's own machines, to EU provider A, or to a frontier model. EU provider B is out of capacity, so its traffic moves to provider A without leaving the jurisdiction. Your application one endpoint, no code changes // custeo control plane What is in it? checked on your side How far may it go? your policy, and who asks Which one is available? live health and capacity Your machines on your premises EU provider A taking B's work EU provider B out of capacity Frontier model if policy allows // every decision above is recorded, across all providers
Your own machines are optional. Most firms start with providers only. Cost never overrules the limit: a cheaper or faster destination outside what your policy allows is not considered. If nothing allowed is available, the work waits or is refused. It is never sent somewhere it should not go.
The same system, three requests

What is inside decides how far it travels.

"Summarise this client file for tomorrow's hearing."

Found: national ID, case file. Privileged material.

Stays in the building Not offered to any outside provider, at any price.

"Draft a reply to this client about their appointment."

Found: email address, phone number. Personal, not privileged.

A European provider Contact details replaced with placeholders before sending.

"Write a blog post about our new office opening."

Found: nothing sensitive. Public marketing copy.

The strongest model available Free to use the best option, wherever it is.
deviceedgeEU cloudfrontier

Deep green stays home and lightens toward the edge. A fixed grammar, used the same way everywhere.

What you get

Four things, and none of them is a datacenter.

01

An endpoint

Point an application at one address. It works with the standard libraries already in use, including agent tool calling.

02

A control panel

Set the rules in plain language, watch every provider, see cost per team, export the record.

03

A tool guard

Agents also send data to chat, email and CRM systems. The same rules apply there, and blocked calls never reach the tool.

04

The evidence

A record per request that spans every provider, sealed so a later edit is detectable.

We do not sell compute, models or hardware. You keep your own provider contracts, and you can add or drop a provider without changing a line of your application. That independence is the point. The layer is worth having because it is not tied to any supplier underneath it.

The proof

One record per request, across every provider.

The routing is commodity. The proof is not. Each decision is written to an append-only record, sealed so that any later edit to a line breaks the chain and is detected.

request  4efde4b71eef
user     m.jansen@kantoor.nl / advocaat
found    national ID, case file → privileged
rule     privileged material may not leave the premises
ran on   office server / on premises
model    qwen3-32b / sha256:9f2c1a
cost     EUR 0.0004
// sealed / any later edit to this line breaks the chain
Who it is for

Two kinds of buyer.

A regulated firm

Law, accountancy, healthcare. You want your people to use AI without client material leaving, and you need an answer when a regulator asks where it was processed.

You buy control and proof over your own use.

A vendor serving them

You sell software into regulated sectors. You have customers in several countries, you cannot be down because one provider is, and you are asked for sovereignty in every deal.

You buy sovereignty as a feature for every customer, from one integration.

Where the honest answer is to use one provider

A single site, one kind of data, no agents, and a supplier you already trust. That firm does not need a control plane. Being able to say so is what makes the rest of this credible.

Talk to us

We run the infrastructure confidential European AI can trust.

If you carry a duty of confidentiality, or you sell to people who do, we would like to hear how you handle it today.

hallo@custeo.eu