It runs where your data already sits
Your cloud, a dedicated arrangement, or your own premises, chosen against the obligation that applies.
Nothing regulated leaves

Service
For firms where client data is the constraint, we build systems that run where your data already sits, with access controls and a record of every action, so compliance is a property of the build rather than a promise about it.
Free · You keep the write-up either way
Typical focus areas
Data extraction·Lead routing·Status tracking·Report generation·Data reconciliationor anywhere your team spends hours doing repetitive data work.
In short
Compliant AI deployment means running the system inside infrastructure the organisation controls, so regulated data never passes to a third party. In practice that involves choosing a hosting arrangement that satisfies the relevant obligation, restricting access to named people, keeping a record of every action for audit, and being able to demonstrate all of it. For sectors under HIPAA, financial regulation or legal privilege, this is usually what decides whether an AI project can proceed at all.
Works with the systems you already run
The problem
A partner sees what these systems can do and immediately asks the only question that matters in a regulated firm: where does the file go. If the honest answer is a third party in another country, the conversation is over, and it should be.
So the deployment decision comes first and the capability second. Once the system runs inside infrastructure you control, with access restricted to people you have named and a record of everything it did, the project becomes an ordinary one.
For privileged, health or client-money data that is not a risk to be managed, it is a rule to be followed. It rules out most of what the market is selling before any evaluation begins.
Who asked what, which records were touched, what came back. Without that record the system cannot be signed off, however well it performs.
It works, so it spreads. Six months later client data is in a system procurement has never reviewed and nobody can say who has access.
The vendor terms allow them to retain and process the data in ways your own client agreements do not. It is discovered late, usually by someone reading the terms properly for the first time.
What changes
Client files would have to go to a third party.
They stay inside infrastructure you control.
There is no record of what the system did.
Every action is logged, attributable and exportable.
Access spreads informally through a department.
Only named people can reach it, and that list is reviewed.
Compliance is a promise in a sales deck.
Compliance is a property of where and how it runs.
What we build
Your cloud, a dedicated arrangement, or your own premises, chosen against the obligation that applies.
Nothing regulated leaves
Access is a list you control and review, not something that spreads informally through a department.
Procurement can sign it off
Who asked, what was touched, what came back. Exportable, because somebody will eventually ask.
An audit takes minutes
Written up for a client, an auditor or an insurer, so the answer does not need assembling under pressure.
No scramble at review time
Proof
Every engagement we take in legal, health or financial work starts with this question rather than ending with it. The deployment shape gets settled before anyone discusses what the system will do, because it determines what is possible. Firms that take it in the other order tend to build something they then cannot use.
How it works
Which regulation, which client commitments, which data. That determines what is permitted, and everything else follows from it.
Your own cloud, a dedicated arrangement, or fully on your premises. Each has different cost and effort, and the obligation decides which is actually available to you.
Access limited to named people, a record of every action, retention rules that match your policy. Added afterwards these never quite fit.
Written up so it can be handed to a client, an auditor or an insurer without a scramble. That document is part of the deliverable.
How we compare
| Chronexa | In-house hire | Freelancer | DIY tool | |
|---|---|---|---|---|
| System ownership | You own it | You own it | You own it | Rented (SaaS) |
| Time to production | 4–6 weeks | 3–6 months | Varies | Months of trial & error |
| Cost model | Fixed price | $120k+ salary | Hourly rate | Subscription + time |
| Maintenance included | ||||
| Security & compliance | Varies | Varies | ||
| Guaranteed outcome |
* In-house costs assume a full-time mid-level engineer. Time-to-production estimates are averages based on our client data.
Confidence & control
Scope
Scope, timeline and price are agreed after a short call, never before. We write down what the system has to do, and what it costs, before any build starts.
Questions
Not usually. For most firms the practical answer is a private arrangement inside your own cloud account, which satisfies the obligation without you running hardware. Genuine on-premise is available where the requirement demands it, and it costs more.
Where the engagement involves health data and we are handling it, that is a normal part of the arrangement. It is worth raising on the first call because it shapes how the deployment is designed.
It costs more than the public option and usually less than people expect, and the comparison that matters is against not being able to do the project at all. We set out the options with their costs so the choice is yours to make.
With the documentation, which is part of what we deliver: where it runs, who can reach it, what is recorded and how long things are kept. Producing that at the point of the question is the thing that goes badly for most firms.
Marginally, in some configurations. In the work we do the difference is not noticeable next to the process it replaces, and it is the price of the data staying where it has to stay.
Every engagement is priced to its own scope, so there is no list price. After a short discovery call we agree in writing what the work covers and what it costs, before any build starts.
Still deciding? Book a discovery call and we will tell you honestly whether this is worth building for you.
Related

Bring us the workflow that keeps eating your team's week.
The audit is free. If we can't find automation worth more than it costs to build, you owe us nothing, and you keep the roadmap.
Prefer email? info@chronexa.io
We'll review your workflows and come back with where AI saves the most time and cost.