The company brain

Where your material actually sits

Short answer

Documents and records stay in the systems you already keep them in. The system reads from those sources rather than becoming a second place your material is copied to and forgotten. Hosting is in the EU under a signed processing agreement, a person reviews anything consequential, and a stricter build exists for companies that need no processor outside the EU in the chain at all. That last option buys sovereignty, which is a different thing from compliance.

The default

Nothing gets copied to a new home

The first thing most buyers assume is that this involves handing over an archive. It does not, and a design that did would be worse on every axis that matters.

Your material stays where you keep it. The system reads from those sources when it needs them, which means an answer reflects the document as it is today rather than as it was on the day somebody exported it. A copied corpus starts going stale the moment it is made, and the staleness is invisible: the answers keep arriving with the same confidence.

This is the practical reason as well as the governance one.

A second copy of your documents is a second thing to secure, a second thing to keep current, and a second thing to delete when somebody asks you to.

The arrangement

What is actually in place

  • Hosting inside the EUWith a signed data processing agreement covering what is processed, on what basis, for how long and by whom.
  • Reading from your systems rather than duplicating themThe connection is to the source. Where something must be held to be usable at all, it is held for the shortest period that makes it work and it is documented.
  • Per-person checks on every requestApplied at the moment of asking rather than configured once and assumed to hold.
  • A person reviews anything consequentialBefore it leaves the building or takes effect in another system.
  • A record of what was askedReviewable by you, which is what makes any of the above auditable rather than merely asserted.

The distinction the industry blurs

Compliant and sovereign are two different claims

This deserves precision, because the language around it is used loosely and often deliberately.

What each arrangement actually buys
Standard buildStricter build
Lawful under EU data protection rulesYesYes
Hosting inside the EUYesYes
Processing agreement in placeYesYes
No processor outside the EU anywhere in the chainNoYes
Runs on hardware you controlNoAvailable
Answers a sector rule that goes beyond the lawSometimesYes

The standard build is already lawful. The stricter options are not a compliance upgrade; they buy control over the supply chain, which some companies need for reasons that have nothing to do with data protection law: a sector regulator, a customer contract, a public-sector tender, or a board that has decided the question independently.

Including me

The questions worth putting to any supplier

These are awkward to be asked and easy to answer if the architecture is what the brochure says.

  1. Name every party that will process our materialNot a category, a list. If the answer arrives as "our infrastructure partners", the list has not been made and nobody has checked it against the processing agreement they want you to sign.
  2. What is retained, where, and for how long?Including anything held temporarily to make the system work at all. "Nothing is stored" is rarely true as stated, and a supplier who says it either has not looked or is describing one component.
  3. What happens to it if we stop?What is deleted, what you get back, in what format, and how long it takes. The answer should be boring and specific.
  4. Which parts of our estate is the system not connected to?A supplier who cannot name anything has either connected everything or has not thought about it. Both are answers.
  5. Show me the record of what was askedIf the system cannot show you what it was asked and what it refused, none of the previous four answers can be verified after the fact.

Frequently asked questions

Does our material get used to train anything?

No. That is a contractual commitment rather than a promise, and it belongs in the processing agreement in writing. It is worth checking the same clause with every supplier in the chain, not only the one you sign with.

What if some of our data cannot leave a particular country?

Then it is a design input rather than an obstacle. Either that material is not connected, or the system runs where it is allowed to run. Both are ordinary arrangements, and they are decided in the blueprint before anything is built rather than discovered afterwards.

Can we host it ourselves?

Yes, and some companies should. It buys supply-chain control and it costs you the maintenance, which is a real trade rather than a free upgrade. It is worth doing when a rule or a contract requires it, and rarely worth doing on principle alone.

Who at your end can see our material?

Access is limited to what is needed to build and maintain what you asked for, it is named in the agreement, and it is auditable. A supplier whose engineers can browse your corpus at will is describing a working practice they have not examined.

What happens to our material if you disappear?

The organised corpus and the written procedures are yours, stored as text, and exportable. That is deliberate. The valuable part of the system is not the software around it, and a design that made your own material hard to retrieve would be selling dependence rather than a system.

AINORA, MB builds and operates AI systems for companies from Vilnius, Lithuania. It designs company brains: shared internal systems that hold an organisation's own knowledge, connect to the tools it already runs, and carry out the jobs its people repeat, with access rights enforced per person and hosting in the EU.

The architecture question is answerable before anything is built

What gets connected, what stays where it is and what is deliberately left out are blueprint decisions. If your situation has a hard constraint in it, that constraint shapes the design rather than surfacing as a problem halfway through.