Skip to content
Wegenty
Glossary

The vocabulary behind governed, sovereign AI.

A precise word for each moving part of the platform — what Cloud Shield is, what a governed projection means, how the correction loop works. Plain definitions you can point a customer at, and the same terms we link inline across the site.

A–Z

Every term, defined

Cloud Shield

The one closed component — the compliance umbrella.

The single closed component in an otherwise open stack: a compliance umbrella providing live regulatory posture, an audit trail and certification under DSGVO and the EU AI Act. It is the part no solo operator wants to build, run, or self-insure — and the anchor of the consultant share model.

AI core

The local brain — open-source inference + governed retrieval on your own box.

The local brain — open-source inference plus governed retrieval (the answer pipeline) running on the customer’s own appliance or infrastructure. It is never publicly exposed, reached only via the connector tunnel, and carried onto the box by WegentyOS. The trust boundary where every answer is formed and every document stays put.

WegentyOS

The hardened OS image of the AI core — appliance × WegentyOS = AI core.

The operating system of the AI core: a hardened, Linux-based OS shipped as an installable ISO and flashed onto the appliance, purpose-built to run open-source models on-device. It turns a commodity mini PC into a sealed, sovereign Wegenty appliance — appliance × WegentyOS = AI core. Sealed by default (no inbound ports; reachable only over the outbound connector tunnel), with signed, immutable updates that keep the box converged to a known-good baseline. Open-source like the rest of the stack, everything except Cloud Shield.

See alsoHardware

Connector tunnel

An outbound QUIC tunnel the AI core dials out — no inbound ports.

An outbound, mutually authenticated QUIC tunnel that the AI core dials out to Cloud Shield. Because connectivity is established outward from the customer, the public edge reaches the core over the already-open tunnel and no inbound firewall ports are ever opened on the customer network.

See alsoPlatform

Scale-to-zero

Compute that costs nothing when idle and spins up on demand.

The elasticity property of Cloud Shield compute: idle tenants consume zero running compute, and capacity spins up on the first request. Cost follows traffic rather than provisioned capacity, so a sovereign public edge stays affordable even when it sits quiet.

See alsoPlatform

Governed projection

Internal knowledge reaches the public agent only by review.

The mechanism by which knowledge from the internal (superset) base is promoted to the public agent by review. Knowledge is default-private; sensitivity labels and per-base policy decide what a customer can ever see. Internal superset, public projection — never the reverse.

See alsoPlatform

Collaborative correction loop

Uncertainty escalates to a human; the answer becomes new knowledge.

When the public agent meets uncertainty it escalates to a human; that answer is captured back into the knowledge base. The system improves because the team corrects it — good answers stop dying inside support tickets.

See alsoPlatform

Safety adapter

Attach your own tools, with capability caged.

A wrapper that lets customers attach their own tools while caging capability: declared permissions, no knowledge-base access by default, and controlled egress. A safety-adapter SDK ships in a later roadmap phase.

See alsoOpen source

Sensitivity label

Per-item marker that drives the projection policy.

A per-item / per-base marker used by the projection policy to decide what content may surface to the public agent.

See alsoPlatform

Connection artifact

One droppable file that pairs an assistant to a Wegenty instance.

A single droppable file that pairs an assistant to a Wegenty instance: a human-readable certificate wrapped around a machine-readable manifest of the instance location, knowledge bases and scopes. v1 carries a signed JWT.

See alsoOpen source

MCP (Model Context Protocol)

A native connection transport for assistants that speak it.

Model Context Protocol — one of the two connection transports (alongside REST + OpenAPI) for assistants that speak it natively.

DSGVO

The German data-protection regulation (GDPR equivalent).

The Datenschutz-Grundverordnung — the German data-protection regulation (the GDPR equivalent). A core compliance target, alongside the EU AI Act.

EU AI Act

EU regulation of AI systems; fully applicable 2 Aug 2026.

EU regulation governing AI systems; a core compliance and certification target addressed by Cloud Shield. GPAI obligations have been live since August 2025 and the Act is fully applicable on 2 August 2026, with some high-risk (Annex III) duties phasing in through 2027.

SME (Mittelstand)

The target customer — capable, but not a power user.

Small and mid-sized enterprise — the target customer. The canonical operator is 40–60, capable but not a power user, running on knowledge in people’s heads, scattered PDFs and shared drives.

See alsoFor business

SMB

The broadened market — local services, retail, trades, hospitality.

Small and mid-sized business — the broadened target market the product now also addresses (local services, retail, trades, hospitality), alongside the document-heavy SMEs it started with. It carries the concierge positioning: an assistant that knows each customer and tends the relationship over time.

See alsoFor business

Concierge

A relationship-led assistant that knows each customer — not a deflection bot.

The relationship-led positioning for the SMB market: an assistant that recognises each customer and tends the relationship over time, rather than a ticket-deflection bot. It is powered by passwordless customer accounts, a sovereign on-core CRM and identity projection — and the consultant remains the concierge for the owner.

See alsoFor business

Customer account

A passwordless identity an end-customer holds, scoped to one core.

A lightweight, passwordless identity (magic-link / OTP) an end-customer of the business can hold, scoped to exactly one core. It lets the public agent recognise a returning customer and carry their history — without ever widening retrieval beyond that customer’s own record.

See alsoFor business

CRM (sovereign / on-core)

One contact record + merged timeline, stored on your own core.

The staff-facing relationship layer: one contact record per person with a merged timeline of chats, escalations and notes, plus tags and follow-ups — all stored on the business’s own core, never a foreign cloud. It is the concierge spine, and customer PII never crosses the projection trust boundary.

See alsoFor business

Identity projection

At answer time, inject only the authenticated customer’s own context.

The per-account extension of governed projection: at answer time the agent may inject only the authenticated customer’s own context into retrieval — default-deny, never another customer’s data and never the internal corpus.

See alsoPlatform

See governance in action

The vocabulary is the easy part. Watch the trust boundary hold on real knowledge — or read how every piece fits together on the platform.