The questions everyone asks first.
Straight answers on sovereignty and your data, DSGVO and the EU AI Act, what is open versus closed, what it costs, and how a governed agent actually keeps internal knowledge from leaking. Controllable, explainable, accountable — agents you can trust.
Where your knowledge lives
Sovereign by default: your knowledge works for you without leaving the building.
Does my data leave the building?
No. The whole point is sovereign by default: one locally-hosted LLM serves your knowledge bases, and your corpus stays where it is. On the appliance, nothing leaves the building at all. Even the public agent only ever sees what policy has explicitly promoted — your internal knowledge is never shipped to a foreign cloud to make this work.
How is it deployed — what are my choices?
One box (a pre-imaged AI core in your own network) plus three independent choices: who sets it up, how it’s reachable (pure local · a DIY public API · or behind Cloud Shield — combinable), and who tailors it. Sovereignty is the floor, not an upsell.
Who can see our internal knowledge?
Only the people you grant it to. Knowledge bases are default-private, access is scoped per base and per role and is revocable at any time, outbound calls go through declared and audited channels, and every retrieval, escalation and promotion is recorded in a full audit trail. The internal base and the public agent never share retrieval scope or guardrails — even when they share a model.
DSGVO, the EU AI Act & Cloud Shield
The compliance burden — DSGVO and the EU AI Act — is carried by Cloud Shield, so a non-technical owner never has to track it.
Is it DSGVO compliant?
It is built to be. Processing is local — data stays in the building or in an EU region — so it is lawful and demonstrable rather than a leap of faith. Default-private knowledge bases, scoped and revocable access, controlled egress and a full audit trail are the mechanisms that make a DSGVO posture provable rather than promised. Legal uncertainty is the #1 cited AI barrier for German SMEs; the platform exists to remove it.
What about the EU AI Act?
The EU AI Act is fully applicable on 2 August 2026, with GPAI obligations live since August 2025 and some high-risk (Annex III) duties phasing in through 2027. Cloud Shield carries the live regulatory posture toward that deadline so your consultant — and you — do not have to track it yourselves. The compliance deadline becomes reassurance rather than a threat.
What is Cloud Shield?
Cloud Shield is the one closed component in an otherwise open stack: a compliance umbrella that holds live regulatory posture, the audit trail, and certification support under DSGVO and the EU AI Act. It is the part no solo operator wants to build, run, or self-insure — so the platform carries it. It is also why the consultant share model holds: the open core can be copied, but the liability cannot be forked.
Open by principle
Open core, one closed shield — fork everything but the liability. See how that stacks up against a closed alternative like Sierra, or read the principles the trust boundary is built on.
What's open versus closed?
Open core, one closed shield. The local LLM, the knowledge bases, the governed projection, the correction loop and the safety adapters are all open source. The single closed piece is Cloud Shield — the compliance umbrella. This is open by principle, not open-washing: fork everything but the liability.
Can I self-host?
Yes. A free, self-hosted Community tier runs the open stack on your own infrastructure — read the code, run the stack, probe the trust boundary. Self-hosting is fully supported for technical adopters; the only thing you cannot self-host is Cloud Shield, because compliance certification flows only through Wegenty.
Does the trust boundary actually hold under scrutiny?
That is the design goal, and it is the thing the open core invites you to test. Projection is one-directional by construction, not by careful operation: the public agent indexes only the promoted projection, never the internal corpus, and the two surfaces do not share retrieval scope or guardrails. There is no configuration that quietly merges them — which is exactly what a technical adopter should verify rather than take on trust.
Can I connect my own model — Claude or ChatGPT?
Yes. The model is a swappable engine; you connect it to Wegenty’s governance layer, not straight to your customers. Local is the default (full sovereignty); Claude or GPT can run pinned to an EU region when you accept that trade. Either way the agent still only answers from your approved knowledge, cites its sources, and hands off to a human when unsure.
Buying it without an engineer
You buy an outcome from a trusted local consultant — not a software project to staff.
Do I need an engineer to run this?
No — that is the core promise. Wegenty is the only governed, sovereign-by-default AI assistant an SME can adopt without an engineer, because a trusted local consultant runs it for them. The appliance is pre-imaged, the managed option is one-click, and a single droppable connection artifact pairs an assistant to your instance. You never have to understand the plumbing.
Who installs it?
A trusted local consultant — the same kind of advisor you already work with, such as an energy-efficiency expert, Steuerberater, MSP or trade-association advisor. They drop in an appliance or spin up a managed instance, point it at your knowledge base, and set the projection policy that decides what a customer can ever see. You get an outcome from someone you trust, not a software project.
How is it priced?
Cost maps to the layers you choose, not a single tier. The constant is the appliance: a one-time hardware purchase plus a maintenance-and-update contract. On top sit three optional, independent line items — a setup fee if a consultant (or Wegenty) stands it up for you, a recurring Cloud Shield subscription only if you expose the core publicly, and a customization fee if you have it tailored. Sovereignty is the floor, not an upsell: running pure local costs you the box and the contract, nothing more. A free Community tier exists for self-hosters; numbers are set with the first consultants.
Is this just a chatbot that deflects tickets?
No — it is a concierge, not a deflection bot. It knows each customer and tends the relationship over time. Passwordless customer accounts (magic-link or one-time code, scoped to a single core) let it recognise a returning customer and carry their history, and a sovereign CRM on your own core keeps one contact record and a merged timeline — chats, escalations, notes — that never leaves the building for a foreign cloud. At answer time it injects only that authenticated customer’s own context — never another customer’s data or your internal corpus. For the owner, the concierge is the trusted local consultant who runs the whole thing.
How governed AI actually works
Two mechanisms do the governing: governed projection decides what a customer can see, and the correction loop decides what the system learns.
How does it avoid leaking internal knowledge to customers?
Through governed projection. The internal knowledge base is the superset; the public customer agent is a projection of it — never the reverse. Every chunk carries a sensitivity label, and per-base policy decides what may ever surface. Knowledge is default-private and only reaches the public agent by review. Because projection is one-directional by construction, a customer query can only ever reach what policy has explicitly promoted.
What happens when the agent doesn't know the answer?
It escalates to a human instead of guessing — that is the collaborative correction loop. When the agent meets uncertainty it hands off to a person who knows you, and that human answer is captured back into the knowledge base. So the next customer with the same question gets a good answer directly. Good answers stop dying inside support tickets, and the system improves precisely where it was weakest.
Still have a question? Ask it on your own knowledge.
Try the interactive demo, or book a short walkthrough of the governance architecture. No data leaves your building, ever.