Skip to content

Built to be trusted: every answer traces to published rule.

Folaint is auditable, EU-sovereign and interoperable by design. It runs on your own infrastructure, your data never leaves your environment, and the open foundation underneath means no lock-in.

The foundation

Trust is a property of the architecture, not a promise.

Runs on your infrastructure

On-premise by default. Open-source models only: your prompts never reach a US cloud AI provider.

EU-sovereign by default

Hosted in Europe, GDPR-respecting, built to align with the EU AI Act.

Every answer is traceable

Full provenance to the source document or system, auditable when it counts.

Open standards, no lock-in

RDF / OWL / SHACL. You can export and keep your foundation.

Deployment options

Four deployment models. One line that holds in all of them.

Pick a model: the figure shows where the perimeter sits, what stays inside it, and what is allowed to cross at all.

Everything runs on your own hardware, inside your own network. This is how we ship by default.

Your data centre
  • Your documents
  • Knowledge graph
  • Rule evaluation
  • Language model, open source
  • Answer with provenance

Five things, the same five in all four models. The language model is on the list: it runs where your data sits, not somewhere else.

Outside

  • US cloud AI providers
  • Hyperscaler models
  • Third-party model APIs

No path there, in none of the four models. Your prompts never reach these services, because the architecture leaves them no way.

What crosses the line

Signed updates, which you install yourself.

  • Your hardware, network and accounts
  • No content data leaves the perimeter
  • Signed updates, released by you

The deployment model moves the line. It never opens it.

Proof, not goodwill

Every answer carries its own origin.

One case from a construction project: a question, the answer to it, and below it every element the answer was built from. Walk the chain.

What the reviewer sees

Does window F-14 in room 2.14 meet the daylight requirement?

Window F-14 in room 2.14 does not meet the daylight requirement: ASR A3.4, sect. 5.1 (3) requires 2.30 m² of structural opening, the design provides 1.84 m².

What the language model did

The finding is settled before the model writes its first letter. It phrases the result, it does not judge it.

Where each element comes fromClick a link

Illustrative example, the sign-off included. The case is the same one shown on the home page and under How we work; the wording and citations of both rules were checked against the sources.

Where we stand

What’s in place today, and what is still on the way.

GDPRCompliant
ISO 27001In progress
EU AI ActAligned
Data residency EUStuttgart, Germany

These reflect our current wireframe roadmap, the posture we are building toward, stated plainly rather than overclaimed.

How we handle data

Principles you can hold us to.

Defaults that hold up under scrutiny, in place from the start rather than bolted on after the fact.

Data minimization

We hold only what an answer needs, for only as long as it needs it.

Encryption in transit and at rest

Standard, everywhere, not a premium tier.

Role-based access control

People see what their role permits, and nothing beyond it.

Full audit logs

Who asked, what was answered, and which sources it drew on, all recorded.

Your experts approve what becomes truth

Nothing enters the graph as fact until a named person signs off.

The model is never in the deterministic path

Rules and provenance decide the answer; the model helps phrase it, not judge it.

Trust, by design

The same conviction runs through everything we build.

Security here isn’t a checklist we run at the end; it follows from how the system is made. If that matters to you, let’s talk about it directly.