Skip to content
huoku

Built to be checked.

Sovereignty is more than where the servers are. It is which AI models you use, who can see what, how personal data is handled, and a record of everything the platform did. This page is for the people who have to sign off on that.

Where it runs

Dedicated to you, wherever you choose.

The whole platform is installed for you: the application, search, identity, and the models that read your documents. External services are used only where you choose them, such as an AI model provider.

European sovereign cloud

A dedicated deployment on European infrastructure, under European jurisdiction.

European infrastructure · dedicated to you
huoku
  • Application
  • Search
  • Identity
  • Indexing models
Only if you choose
AI model provider of your choice

Your own cloud or data centre

Installed in your Kubernetes. With local models and self-hosted search, no external AI service is needed at all, so it can run air-gapped.

Your Kubernetes · cloud or on-premise
huoku
  • Application
  • Search
  • Identity
  • Indexing models
Your own AI models (optional)
Only if you choose
AI model provider of your choice

Hybrid, also supported

The platform in the cloud, the document reader inside your network next to file shares, SAP and databases. Raw documents stay home.

Your network
Satellite document reader

File shares · SAP · databases

Connects out, encryptedOnly processed, masked content moves
European cloud
huoku

Your models

Choose the AI, agent by agent.

huoku is not tied to one model vendor. Use a local model for sensitive work and a larger one where it's allowed, or keep everything in-house.

Who sees what

Permissions follow the data, from document to answer.

Access rules are applied inside the search engine, so an agent can never retrieve a document the person asking could not open.

Personal data

Masked before it is stored.

Data Guard masks personal data such as identity numbers and IBANs before anything is indexed. The original value never reaches the search index or the AI model.

huoku · Data Guard
The Data Guard pattern editor: a Finnish personal identity code matched and masked in a live test, and the instances running the rules.
  • Tested live on the masking engine before it goes into effect.
  • Every instance runs the same rules.

EU AI Act

Prohibited uses blocked in the runtime.

Every agent declares what it is for. Uses prohibited under Article 5 of the EU AI Act are refused when the agent is created and again when it runs.

huoku · System card
An agent's system card: EU AI Act technical documentation (Art. 11, Annex IV), an immutable snapshot with its content hash, and the agent's intended purpose.
  • Written as EU AI Act technical documentation.
  • Every change creates a new snapshot, sealed with a hash.

Audit

A complete record, by design.

Who did what, when, with which agent. Security events are always recorded; conversation content only if you decide so.

huoku · Audit log
The audit log: retention setting, prompt and answer text not recorded by default, filters and export.
  • Prompt and answer text is not recorded by default.
  • Filter by event, service or user, and export.

For your technical team

The details your engineers will ask about.

Bring your security team.

We'll walk them through the architecture, the controls and the audit trail on a live system.

Or write to sales@huoku.ai