Skip to content

Your data can’t leave the building. Your AI doesn’t have to either.

Your own models, on your own hardware, in your own building. RIVER supplies the hardware, deploys and tunes the models, connects them to your platform, and hands you the documentation an audit asks for.

Sounds like you if the data cannot leave the building, and the audit will ask where the models run.

  • Your models, on your hardware, in your building
  • New Zealand owned, under New Zealand law
  • Audit-ready, with the documentation to prove it
Why the cloud was never an option

The data can’t leave. So a US model was never on the table.

You already know the answer to “just use the cloud API” is no. The data is too sensitive, the audit is too close, and “data residency” turns out to mean a foreign vendor’s datacentre, still under foreign law. The fix isn’t a policy. It’s running the models where the data already lives - in your building, on hardware you own.

Sending it to the cloud

Running it in your building

Your sensitive data leaves the building for a model you don't control.

The models run on your own hardware. Nothing leaves.

The audit asks where inference runs, and the honest answer is “a US cloud”.

You show exactly where every model runs - in your building, under New Zealand law.

“Data residency” is a foreign vendor's datacentre, still reachable under foreign law.

Genuine sovereignty: NZ-owned, on your hardware, no foreign jurisdiction in the path.

Residency is where data sits. Sovereignty is who can compel it.

Security documentation is a scramble every time procurement asks.

The evidence pack is ready - ISO-aligned, with access logs, on request.

A public AI tool is off the table for this data, so the project stalls.

A private model you're actually allowed to use, so the work ships.

The intelligence comes to your data. The data never leaves.

What it does

Your models, your hardware, in your own building.

RIVER supplies and installs the hardware, deploys and tunes the models, connects them to your platform, and hands you the documentation an audit asks for. Nothing routes to a public cloud model.

Runs in your building

It starts with the hardware. The models run on nodes you own, inside your own network, so there is no external model in the path and nothing to send offshore.

0
external calls at inference - every model runs on-prem
Your platformNodes

3 nodes · all on-premise · 0 external calls

node-akl-01Online · 2 models loaded
node-akl-02Online · 2 models loaded
node-akl-03Standby · failover
External model APIBlocked by policy

Inference stays inside your network. No request reaches a public cloud model, by design - not by configuration you have to trust.

Answers the audit

Sovereign isn't only where it runs - it's whether you can prove it. The deployment ships with the evidence a security review asks for, and the models are tuned to your own work.

27001 + 42001
the ISO frameworks the build is designed to
Your platformAssurance
ISO 27001
Information security - aligned
ISO 42001
AI governance - aligned
100%
access events logged and exportable

Recent activity

  • Clinical model queried by an authorised user2m ago
  • Admin exported the access log for audit1h ago
  • Policy blocked an unauthorised egress attempt3h ago
  • Model updated to the current releaseyesterday
Why it works

Sovereignty you can prove, not just claim.

RIVER is New Zealand owned and builds on 100+ proven modules, so a sovereign deployment tailors in weeks - and it is built to pass the security review that comes next.

0
external calls at inference - the models run in your building
100%
yours - hardware, models, data and IP, under New Zealand law
27001 + 42001
the ISO frameworks the build is designed to

Everything a security or procurement team needs is in our Trust Centre

  • 100% New Zealand built, Māori and Pacific owned, operated under New Zealand law - not a foreign vendor's jurisdiction.
  • You own all of it - the hardware, the models, your data, workflows and IP. Not licensed, not handed back at the end of a term.
  • Audit-ready: aligned to ISO 27001 and ISO 42001, with the security documentation and access logs a review asks for. Independent certification is in progress.
RIVER approached every detail with care. Every decision was made with consideration and purpose.
Daemon CoyleGM, Mental Health Foundation · 2021
Getting started

Start with the requirements, then stand it up.

Scope

Weeks 1-2

We agree your security and sovereignty requirements, which models you need, and how many nodes - before any hardware is ordered.

Deploy

Weeks 3-6

We supply and install the hardware in your building, deploy and tune the models, and connect them to your platform.

Assure

Weeks 6-8

Security documentation, access controls and monitoring are handed over, and you sign off against your own requirements.

The investment

Project size

One node in your building: hardware, your models deployed and tuned, connected to your platform.

From $35,000 per node+ GST setup, plus support

Sovereign AI is sold with a platform, never on its own - the models need your Catalyst instance to run against. Start the platform on the Retainer from $5,000 a month. Delivered to your agreed security requirements, or we don’t invoice the deployment.

Every deployment includes

  • Hardware supplied, configured and installed in your building
  • Your chosen models deployed, tuned to your work, and kept current
  • Connected to your platform, with plain-language answers over your own data
  • The security documentation an audit asks for - ISO-aligned, with access logs
  • Monitoring, updates and model currency handled for you
  • Everything yours to keep: hardware, models, data and IP
Questions

The questions people ask when they’re ready to move.

Ready when you are

Easy to start. Fast to prove. Built to scale.

Tell us about your Sovereign AI, and we’ll take it from there. Prefer to look first? Ask Moana, or take the free Readiness Check.

Client stories

Teams like yours, in their own words.

A decade of work, across health, sport, finance and the public good.