Skip to content
Wegenty
The platform

The product is governance, not retrieval.

Agents you can trust.

Anyone can bolt a chatbot onto a pile of PDFs. The hard, valuable part is the boundary between private knowledge and a public-facing agent — and the loop that makes it improve. That boundary is the platform.

One local LLM, many knowledge bases Default-private by design Open core, one closed shield
Architecture

A private superset, projected into a public agent

One locally-hosted LLM serves many knowledge bases. The internal base is the superset; the customer agent is a governed projection of it — and a human correction loop feeds improvements back in.

Internal · the superset
Your knowledge base
Full corpus, staff-facing. Default-private. Never leaves the building.
Governance
Projection · policy
Sensitivity labels decide what a customer can ever see. Promoted by review.
Public · customer-facing
The CX agent
A governed projection — filtered, scoped, and unable to leak the internal corpus.

No path back: the public agent can never read into the internal corpus. The reverse data flow is blocked by construction — there is no setting that opens it.

The correction loop — the one path back: when the agent is unsure it escalates to a human, and that vetted answer is captured into the knowledge base. Knowledge only returns through a person, never through the agent.

The arrows only point one way by construction. Knowledge flows from private to public through review — the public agent has no path back into the internal corpus.

The trust spine

“Agents you can trust” — backed by mechanism, not adjective

Three properties hold the platform up — Controllable, Explainable, Accountable. Each one maps to a concrete mechanism in the architecture, not a slogan.

Controllable

You hold the reins.

A governed projection plus scoped, revocable access decide what a customer can ever see — and a connected tool reaches no knowledge base until you grant it.

Explainable

No black boxes.

Every answer cites its sources, and every retrieval, escalation and promotion is recorded — so you can audit why the agent said what it said, not just what it said.

Accountable

Someone answers for it.

Cloud Shield carries the live compliance posture, and a human consultant stands behind the result. The correction loop puts a person on the hook where the agent is unsure.

The only governed, sovereign-by-default AI assistant an SME can adopt without an engineer — because a trusted local consultant runs it for them.

Core mechanisms

Five mechanisms do the governing

Projection decides what may be seen, identity projection narrows that to a single customer, the correction loop decides what is learned, adapters decide what tools may do, and Cloud Shield carries the compliance.

Projection

Governed projection + sensitivity labels

The internal knowledge base is the superset. The public customer agent is a projection of it — never the reverse. Every chunk carries a sensitivity label, and per-base policy decides what a customer can ever see. Knowledge is default-private and only reaches the public surface by review.

Identity projection

The agent recognises a customer without widening scope

A returning customer holds a passwordless account scoped to one core. At answer time the agent may inject only that customer’s own context into retrieval — default-deny, never another customer’s data and never the internal corpus. It is the per-account extension of governed projection: the agent grows more personal without the scope growing wider.

Correction loop

The collaborative correction loop

When the agent is unsure, it escalates to a human instead of guessing. That human answer is captured back into the knowledge base, so the system improves precisely where it was weak. Good answers stop dying inside support tickets.

Adapters

Safety adapters cage third-party tools

External tools run behind safety adapters with declared permissions, no knowledge-base access by default, and controlled egress. A gated marketplace comes later. The cage is the default; access is something you grant on purpose.

Cloud Shield

Cloud Shield — the one closed component

Everything else is open source. Cloud Shield is the single closed piece: a compliance umbrella carrying live regulatory posture, the audit trail, and certification support under DSGVO and the EU AI Act — the part no solo operator wants to build or self-insure.

Bring your own model

The model is a swappable engine — the governance never moves

Inference runs behind a single facade, so the brain that powers the public agent is a dial, not the product. Run a model locally for full sovereignty, or pin Claude or GPT to an EU region when you want frontier quality — either way the governed projection, cited answers, grounding judge and human escalation stay exactly the same. Model choice is a performance, cost and Cloud Shield sovereignty trade, never a governance trade.

Bring whatever brain you trust. We make it cite its sources, stay inside your approved knowledge, and hand off to a human when it’s unsure — the same way whether the brain is on your box or in an EU region.

    1Local
    Full sovereignty

    On-box model

    The default. The model runs on your own box and no question text ever leaves the premises — sovereign by default, predictable flat cost.

    2Frontier · EU
    EU data residency

    Claude or GPT

    Claude or GPT pinned to an EU region for frontier reasoning. Data stays in-EU with no training on it — an informed, logged, per-instance choice.

    3Invariant
    Never changes

    Same governance

    Swapping the engine changes who computes the tokens, not what the agent may say. Governed projection, citations, grounding judge and escalation are untouched.

The invariant

The internal base and the public agent never share a scope

This is the trust boundary the whole platform is built to hold. The private superset and the public projection do not share retrieval scope, and they do not share guardrails. A customer query can only ever reach what policy has explicitly promoted — there is no configuration that quietly merges the two.

Projection is one-directional by construction, not by careful operation. That is what lets a non-technical owner trust it without auditing every prompt.

Separate retrieval scope

The public agent indexes only the promoted projection — never the internal corpus.

Separate guardrails

Each surface enforces its own policy; the customer surface cannot inherit internal access.

One-way promotion

Knowledge moves private → public by review. There is no reverse path.

Connectivity

Any assistant can connect — one droppable file

A single connection artifact pairs an assistant to an instance. Drop one file and the assistant speaks to the system over REST + OpenAPI or MCP — no bespoke integration, no standing access. Everything it can touch is declared up front and caged by a safety adapter.

  • Declared, not discovered. The artifact says exactly what the assistant may call — there is no ambient access to find.
  • No KB access by default. A connected tool reaches no knowledge base until you grant it, scoped and revocable.
  • Controlled egress. Outbound traffic flows through audited channels, so a tool cannot quietly exfiltrate.
REST + OpenAPI

Point an assistant at a documented REST surface. The OpenAPI description tells the adapter exactly which operations exist and what they accept — nothing more is reachable.

MCP

Speak the Model Context Protocol to expose tools and resources to the assistant over a typed, declarative contract — caged by the same adapter rules as everything else.

Connector tunnel

A connector daemon next to each core dials an outbound, mutually-authenticated QUIC tunnel to Cloud Shield — the zero-trust public edge. You open no inbound ports; the core is reached over the tunnel it opened, never one imposed on it.

The connection artifact: one droppable file that pairs an assistant to an instance — and a gated marketplace of caged tools comes later.

Security posture

Sovereign by default, compliant by design

The posture is the same however you run it — pure local, publicly exposed, or behind Cloud Shield; on the appliance or your own infra. Default-private, least privilege, full audit, EU-lawful.

Default-private

Knowledge bases start closed. Nothing is public until a person promotes it by review.

Scoped & revocable

Access is granted per base, per role — and can be withdrawn at any time. Least privilege by default.

Controlled egress

Outbound calls go through declared, audited channels. A tool cannot quietly phone home.

Full audit trail

Every retrieval, escalation, promotion and tool call is recorded for review and certification.

DSGVO aligned

Data stays in the building or in an EU region. Processing is local, lawful and demonstrable.

EU AI Act ready

Cloud Shield carries the live regulatory posture toward full applicability on 2 Aug 2026.

The EU AI Act is fully applicable on 2 August 2026, with GPAI obligations already live. Cloud Shield carries that posture so your consultant — and you — don’t have to.

Platform questions, answered

How does the platform stop the agent from leaking internal data?

The public agent never indexes the internal corpus — it only indexes the promoted projection. The two surfaces have separate retrieval scopes and separate guardrails, and the reverse data path is blocked by construction, not by careful configuration. Every chunk also carries a sensitivity label, so a customer query can only ever reach what policy has explicitly promoted. There is no setting that merges the private superset and the public projection.

What happens when the agent does not know the answer?

It escalates to a human instead of guessing. That is the correction loop: the customer gets a fast hand-off to someone who knows them, and the vetted human answer is captured back into the knowledge base — so the system improves exactly where it was weak. Knowledge only returns to the corpus through a person, never through the agent itself.

Which parts are open source, and what is closed?

Everything is open source except one component: Cloud Shield. It is the single closed piece — a compliance umbrella carrying the live regulatory posture, the audit trail, and certification support under DSGVO and the EU AI Act. You can fork everything but the liability: the part no solo operator wants to build or self-insure.

Can an SME run this without an engineer on staff?

Yes — that is the point. A trusted local consultant installs and runs it for you, so adopting governed AI does not require hiring or contracting an engineer. The governance boundary is one-directional by construction rather than by careful operation, which is what lets a non-technical owner rely on it without auditing every prompt.

Is it DSGVO and EU AI Act compliant?

It is built to be. Data stays in the building or in an EU region, processing is local and demonstrable, and every retrieval, escalation, promotion and tool call is recorded for review and certification. Cloud Shield carries the live regulatory posture toward the EU AI Act becoming fully applicable on 2 August 2026, with GPAI obligations already live since August 2025.

See the trust boundary hold — on your own knowledge.

Try the interactive demo, or book a 20-minute walkthrough of the governance architecture. No data leaves your building, ever.