EinCoreRAG

Enterprise RAG you can run in the EU — or air-gapped.

Multi-agent retrieval over your own knowledge base, deployable on Mistral AI + Qdrant with EU data residency or fully self-hosted. Tenant isolation, PII redaction, and audit-ready logs — for teams where the security review is the sale.

Features

  • Grounded RAG over your knowledge

    Ingest PDF, DOCX, CSV, TXT, or Markdown, or crawl your website; vector search returns cited answers from your content only. When it doesn't know, it hands off to a human — it doesn't invent.

  • Bring your own model (BYOM)

    Any OpenAI-compatible endpoint — Azure OpenAI, AWS Bedrock, or self-hosted vLLM, TGI, or Ollama on your own hardware. A multi-provider gateway fails over automatically so one outage doesn't take the assistant down.

  • Runs where your data must stay

    Single-tenant self-host, on-premise, or air-gapped; or an EU-sovereign cloud on Mistral AI and Qdrant with EU data residency. No required US data transfer, no CLOUD-Act exposure.

  • Human handoff

    Confidence-based escalation into a shared inbox with SLA and business hours; the AI resumes automatically if no one answers in time.

  • Every channel your people use

    An embeddable, Shadow-DOM-isolated web widget, plus Slack, WhatsApp, email, and helpdesk. Microsoft Teams (preview).

  • Observability & FinOps

    Per-tenant token-cost tracking, groundedness and hallucination monitoring, and OpenTelemetry tracing throughout.

Tech stack

  • FastAPI
  • LangGraph
  • PostgreSQL RLS
  • Qdrant
  • Redis
  • vLLM / Ollama
  • Mistral AI
  • OpenTelemetry
EinCoreRAG — Enterprise RAG you can run in the EU — or air-gapped.
  • EU

    Data residency

  • 0

    Required US data transfer

  • Air-gap

    Deployment option

  • Cited

    Every answer

The sovereign motion

From scoping call to evidence pack

A pilot that proves it inside your environment before you commit.

  1. 01

    Scoping call

    We map your use case, data sources, and compliance constraints — AI Act risk tier, DORA, GDPR.

  2. 02

    Pilot on your infrastructure

    6–8 weeks, single-tenant, under NDA: we ingest your documents and deploy EinCoreRAG inside your environment.

  3. 03

    Evidence + go/no-go

    You receive an independent security report and a generated EU AI Act / ROPA-DSAR evidence pack for a real use case — then you decide.

Security & Compliance

Compliance is the foundation, not a feature

Every claim here maps to a mechanism we can show your auditor — nothing more.

  • Certifications, stated honestly

    Controls mapped to SOC 2 / ISO 27001 evidence — attestation is on our roadmap, not yet held. We won't claim certifications we don't hold.

  • EU AI Act & GDPR aligned

    Aligned with the EU AI Act and GDPR, with a HIPAA-ready architecture for PHI handling.

  • Tenant isolation

    PostgreSQL Row-Level Security and per-tenant vector collections, with Redis namespacing, keep deployments cleanly separated.

  • Security firewalls

    A prompt-injection firewall on every input, PII redaction before the model sees your data, and denial-of-wallet spend caps.

  • Immutable audit trail

    Append-only, per-tenant, and database-enforced. Evidence is structured for SOC 2, ISO 27001, and EU AI Act reviews.

  • EU-sovereign deployment

    Inference on Mistral AI, vector search on Qdrant, EU data residency; no required US data transfer.

Where it runs

Deploy it where your data must stay

The same platform, from fully air-gapped to a fast hosted start — with an upgrade path between them.

  • Sovereign

    Self-host / on-prem / air-gapped

    Single-tenant, inside your own environment — including fully air-gapped on your own hardware, with your own models.

  • EU cloud

    EU-sovereign cloud

    Hosted on an EU-sovereign path — Mistral AI and Qdrant with EU data residency — when you want managed but in-region.

  • Hosted

    Hosted EU-region edition

    A lighter start for non-regulated teams who want to move fast, with an upgrade path to a fully sovereign deployment.

Watch

See the platform in action

A visual walkthrough — from knowledge ingestion to grounded, cited answers.

Listen

Hear the platform explained

A deep dive into the architecture, security, and sovereign deployment behind EinCoreRAG.

🎙️

Inside EinCoreRAG

Platform Deep Dive

Who it's for

Built for organisations that can't send data to a US cloud

Regulated EU institutions that need sovereign AI with the evidence to prove it.

  • 🏦

    Regional & cooperative banks

    Sovereign AI without depending on a US-cloud critical-ICT provider. DORA-ready.

  • 🛡️

    Insurers

    EU AI Act Article 26 deployer evidence from day one.

  • 🏥

    Hospitals & health groups

    Patient data never leaves the building; BAA-ready.

  • 🏛️

    Public sector

    An EU-incorporated vendor, tender-ready, with local-language delivery.

Sovereign pilot

Bring us the AI project your compliance team said no to

We'll scope it, deploy it inside your walls, and hand you the evidence — an independent security report and an EU AI Act / ROPA-DSAR pack for a real use case.

Book a sovereign pilot

FAQ

Frequently asked questions

  • Will it make up answers?

    No. Answers are retrieved from your own indexed knowledge base and stay grounded in those sources rather than the model's memory. When the answer isn't there, it hands off to a human.

  • Is each customer's data isolated?

    Tenant separation is enforced with PostgreSQL Row-Level Security and per-tenant vector collections, so deployments stay cleanly separated. For the strongest assurance, run single-tenant or fully air-gapped.

  • We can't send our data to a US cloud — what are our options?

    Deploy the EU-sovereign path on Mistral AI and Qdrant with EU data residency, self-host the inference layer on your own models, or run fully air-gapped. There is no required US data transfer.

  • What evidence do we get for auditors?

    An immutable, append-only, per-tenant audit trail, plus a generated EU AI Act / ROPA-DSAR evidence pack and an independent security report from the pilot — structured for SOC 2, ISO 27001, and HIPAA reviews.

Have a project in mind?

Tell us what you want to build. We respond within one business day.

Built by an EU-incorporated senior team — 20+ years in enterprise delivery.