SECURITY & SOVEREIGNTY

It never leaves your house.

Dimbo is sovereign by construction. The whole system runs where you control it: a benchmarked local model, local vision, local transcription. Air-gapped is the default. When an external model is ever used, PII is anonymized first. Your raw data stays in your database, every edge carries its provenance, and no agent acts until a person says so.

Deployment

Same platform, same intelligence: you choose where the model runs.

On-prem appliance, EU-hosted, or PII-gated cloud. The only thing that changes is the perimeter. Every tier gets the full pipeline, the full graph, the full Action Center. Sovereignty is a deployment choice, never a feature you buy back.

Dimension Cloud · PII-gated EU-hosted (T1–2) On-prem appliance (T3)
Where it runs Managed cloud, frontier model EU jurisdiction, managed infrastructure Inside your walls, on a local GPU
What leaves the perimeter Anonymized payload only — Presidio gateway masks IBANs, cards, phone numbers and credentials before a token leaves; the frontier model never sees a raw identifier Nothing outside the EU — data residency in the Union, no US CLOUD Act exposure, key encrypted in platform secrets, never in code Nothing, ever — local LLM plus local vision and local Whisper transcription, fully air-gapped by default
Best for Fastest to start, frontier-model reasoning quality EU-only data residency requirements, managed ops Zero perimeter crossing, defense/pharma-grade sovereignty
Capability Identical — full pipeline, full graph, full Action Center on every tier. Sovereignty is a deployment choice, never a feature you buy back.
The privacy gateway

One gate stands between your data and any external model.

Every signal takes the same path. The masking gate is a hard wall in the pipeline, impossible to switch off by accident. Local deployments never reach it; when a payload does, it is anonymized before it crosses.

01 · Ingest

Signal arrives

Email, document, ERP record, voice note, machine reading: all read-only, into the pipeline.

02 · Store

Raw stays home

The un-anonymized original is written to your PostgreSQL and never leaves it. Only a masked copy travels.

03 · Mask

Presidio gateway

The hard wall. PII is anonymized on the copy bound for any external model. Configured entirely from one file, no code changes.

04 · Reason (local)

On-prem / EU

On-prem and EU-hosted tiers keep everything inside the perimeter. Nothing is exposed at all.

04 · Reason (cloud)

Masked only

The frontier model receives the anonymized payload and returns its reasoning. It never sees a raw identifier.

Why sovereignty, and why now

Your data is already leaking into consumer AI.

Prohibition doesn't work; people paste contracts, customer records, source code and financial figures into public models to get their jobs done. The remedy is substitution: a governed, sovereign assistant that answers from live company knowledge inside your perimeter, with PII gating and a full audit trail.

75%
of knowledge workers already use generative AI at work, most of it outside any governance.
Microsoft/LinkedIn · Work Trend Index 2024
78%
bring their own AI (“BYOAI”), pasting company data into tools IT never approved.
Microsoft/LinkedIn · Work Trend Index 2024
$4.88M
average cost of a data breach in 2024: the collision point with GDPR, the EU AI Act, NIS2 and Schrems II.
IBM · Cost of a Data Breach 2024
The governed alternative: a representative case

At “Adriatica Pharma Services,” a CDMO, a chemist needs a draft from a proprietary batch record.

Pasted into a public chatbot, that batch record is a GMP and GDPR event nobody logs. With Dimbo's sovereign, role-scoped assistant, the same draft is produced inside the perimeter. The query and the evidence land in the audit trail, and the record never leaves the building. This is what substitution looks like in practice. Representative scenario.

Privacy & GDPR by design

GDPR-by-design is a property of how the system is built.

Anonymization isn't a toggle bolted on at the edge; it's a wall in the pipeline. What gets masked is controlled from one config file. IBANs, cards and credentials are always masked; names and dates stay visible for the matching that makes the graph work. Change what's masked without touching a line of code.

Your raw text is stored un-anonymized in your own database and stays there. Only the copy bound for an external model is masked. Every entity, every link, every agent decision carries its provenance: where it came from, and how sure Dimbo is. The audit trail is a query, not an archaeology project.

Presidio gateway

Masked before it leaves

PII anonymized before any external model sees a token: configured from one file, reloadable at runtime.

Raw stays home

Un-anonymized in your DB

The original is written to your PostgreSQL and never travels. Only a masked copy does.

Provenance

On every edge

Every connection is traceable to its source, stamped internal-operations vs external-world-knowledge.

Audit trail

Every decision, logged

Explicit agent actions land in an append-only log: what was proposed, by whom, on what evidence.

Governance & the EU AI Act

Human oversight is the mechanism, built into the product from the start.

The EU AI Act asks for meaningful human oversight of AI systems. Dimbo meets it with the autonomy ladder, the same mechanism that runs the product. Every capability starts passive: it proposes, leaving a person to approve, edit or reject. Nothing acts on its own until a process has earned it, and promotion is always the customer's decision.

Oversight is per-process and revocable. A single master kill-switch holds auto-execution off until you turn it on. At the top of the ladder, actions carry an undo window; any human disagreement demotes that process one rung, downward-only, automatically. Every level change is audited and emitted as an event.

  • Per-process levels 0→4 — oversight scoped to each action type
  • Promotion is user-only — the vendor never elevates a process on your behalf
  • Downward auto-demotion on any human reject or edit — trust contracts instantly
  • Master kill-switch — auto-execution ships off; you decide when it arms
  • Every level change audited & emitted as an event — oversight you can prove
dimbo · action center
Action Centerhuman oversight
financeawaiting approval
Payment-reminder reply drafted for an invoice trending past terms
2 signals · 1 sourcejudged confidence 0.79
ApproveEditReject
Autonomy ladder · Draft replies · Client Marelli
Level 1 · Propose
7 clean approvals · promotion is your callPromote
Honest by policy

Real properties, honest status.

We state what the system actually does, and we don't claim certifications we don't hold. GDPR-by-design is a property of the architecture. Here's the honest register.

Properties we hold · things we don't claim

On-prem appliance live EU-hosted tier live PII anonymized before any external model live GDPR-by-design live Provenance on every edge live EU AI Act oversight-by-design live Raw data stays in your database live Full audit trail on every action live Formal third-party certification (SOC 2 / ISO 27001) planned

We do not assert SOC 2, ISO 27001 or any certification we haven't earned, and we won't dress a property up as a badge. What we sell is what the architecture actually gives you: sovereignty, on-prem, PII anonymization, provenance, audit trail, and human oversight built into the core, with GDPR-by-design part of that architecture.

See it run on your infrastructure.

The free Deadline Audit runs on your data, on your infrastructure: the surest way to see the sovereignty story is to watch it never leave the building.