On-Premise / GDPR AI

Use AI without giving up control of your data.

Sensitive company or customer data? For AI there are several paths: on-premise, local models in Austria, or EU cloud. We pick the right one with you, with GDPR in mind from the start.

Illustration: dog and monkey closing a vault

You’re in the right place if:

  • you work with sensitive data: customer or employee data, trade secrets, health, genetics.
  • you want AI, but don’t know whether you can even do that with your data.
Who we are2x10

At 2x10, you talk directly to the founders and the senior engineers who build your software. No account managers, no layers of juniors in between. We’ve been bringing AI into real products since 2022. Our own systems have served millions of users.

Three ways to use LLMs in your product

Choosing models and providers decides whether you ship more than a demo. And with sensitive data, where it goes. Most teams know where data is stored. With AI, the new question is where it goes the moment an LLM processes it.

Frontier models directly (Claude, GPT, Gemini)

Pros: Most functionality, fastest, cheapest way to use top models. Providers like Anthropic don’t train on your data, everything encrypted.

Cons: The data leaves the EU (servers mostly in the US). “Not for training” doesn’t mean “stays in the country”.

Frontier models via AWS Bedrock

Pros: Models like Claude run in an EU region, an additional security layer in between, no training on your data.

Cons: More expensive, sometimes fewer features than the direct API. And: AWS is a US corporation.

Open-source models, local in Austria

Pros: Data on Austrian servers in a partner data center. Cheaper above a certain volume and for the right tasks. Independent of fluctuating token prices.

Cons: Open-source models run roughly half a year behind the top models. For most tasks that’s enough, for the most demanding ones not always.

Usually the answer is a mix. We draw the line along your data, not along a sales pitch.

When your system really can’t go down

Big model providers have outages, and token prices fluctuate. Depend on one, and you inherit both.

  • Frontier models first: best results while the provider is up.
  • A tested local system in reserve: for simpler tasks or when the provider is stuck.
  • LLM routing switches automatically to wherever makes sense right now.

Resilience when you need it. And independence from fluctuating token prices and the big US providers.

What you get

How we handle sensitive data

Data separation

Sensitive data strictly separated, with clear rules on who accesses what.

01 · Base

Traceable

Prompt tracing logs what goes to a model and what comes back. Audit-proof.

02

Legally supported

If you want, with the data protection lawyers we worked with on the COVID projects. Or with yours.

03

No data leaks

Sensitive data never goes to an external model unnoticed. What leaves the system is governed by rules, not chance.

04 · Goal

With Novid20, our anti-COVID start-up

We supported 35 million lab tests, technically and strategically, across 5,381 institutions like schools, kindergartens and care homes. In Bavaria alone, our software was connected to nine labs and processed more than 3.5 million tests a month. Live systems handling sensitive health data under media and regulatory scrutiny. We bring that experience with us.

Illustration: monkey researching at a microscope, dog carrying a test tube
0135 millionlab tests supported strategically & technically
025,381institutions: schools, kindergartens, care homes
03liveunder authority and media scrutiny
040training data to public LLMs
“I have worked with 2x10 on several regulatorily demanding projects and am impressed every time by how competently they approach the complex task at hand.”
Dr. Klaus Pateter · Managing Partner, bpp law · AI & data protection law

A fit, if:

  • your data is sensitive or regulated
  • contracts rule out the simple US cloud
  • you want to know where your data really sits
  • you’re ready to invest in data sovereignty

Better elsewhere, if:

  • your data isn’t sensitive
  • you want “everything local” without budget
  • you just need an audit checkbox
  • speed matters more to you than control

FAQ

Compliance depends on your specific case and needs legal review. We build so it’s achievable: data separation, EU or local processing, traceability. With specialized legal advice if you want it.

No. A mix often makes sense: the sensitive parts local, the rest in the EU cloud. We draw that line along your data.

Somewhat weaker than the top models, roughly half a year behind. For most tasks that’s enough. Where it isn’t, we mix.

You remain the controller. We deliver the technical implementation and, if you want, bring in specialized data protection lawyers we’ve already worked with on large projects.

Yes. Through a partnership with an Austrian data center, open-source models run locally and the data doesn’t leave Austria.

N° 06 Contact

Tell me what you’re planning.

No form, no ticket system. Email me directly and you get me, not an inbox someone else manages.

Moritz MiedlerMoritz Miedler · Founder, replies personally
2x10 Technologies · Viennahello@2x10.com