Sectors

Sectors where the boundary is not negotiable

We work where the constraint on AI is not imagination or budget, but the fact that somebody has to sign a form saying they know exactly where the data went, and in defence and central government that somebody is an accreditor.

  • Defence
  • Central government
  • Air-gapped delivery
  • NCSC CAF
  • DISA STIG
  • CIS Level 2

Defence

Inference on hardware inside your own perimeter, with no egress path at all. Hosts hardened to STIG and CIS Level 2, and the Secure by Design artefacts your accreditor expects.

Gatekeeper MOD Secure by Design, JSP 604 and Def Stan 05-138

Read more

Central government

Departmental AI that survives GovAssure, Secure by Design and ATRS scrutiny, running on infrastructure the department controls rather than in someone else’s tenancy.

Gatekeeper GovAssure against the NCSC CAF, and Secure by Design

Read more

Financial services

Model risk documentation, explainability and consumer outcomes scrutiny, with the client data that makes AI useful never leaving a controlled environment.

Gatekeeper SS1/23 model risk expectations and Consumer Duty evidence

Read more

Healthcare & NHS

Patient data cannot be posted to a US API. We build inside your boundary and produce the DPIA and information governance evidence that gets a project approved.

Gatekeeper DSPT, DTAC and information governance sign-off

Read more

Legal & professional services

Privilege and client confidentiality make hosted AI a hard sell. Private retrieval over your matter files keeps the material inside the firm.

Gatekeeper Legal professional privilege and SRA supervision duties

Read more

Public sector

Councils, NDPBs and wider public services. Transparency obligations and public scrutiny raise the evidence bar, so we build to the standards your assurance team already answers to.

Gatekeeper ATRS entries, AIME self-assessment and procurement scrutiny

Read more

Not on this list?

These are the sectors where we do the most work, not the only ones we will take. The common thread is a hard constraint on where data may be processed and a function that has to approve things on evidence, which also describes a good deal of the defence supply chain, critical national infrastructure, education, housing, insurance and utilities.

If your version of the problem is "the use case is obvious and the compliance position is why it has not happened", we are probably a reasonable fit.

Tell us about it

Start with a straight answer

A 30-minute call, no pitch deck. Tell us what you are trying to do and we will tell you whether AI is the right tool, what it would take, and what it would cost, or that you should not bother.