Regulated sector: the hosting and the evidence it demands
Deploying an agent in health or finance means meeting hosting, traceability and control requirements that go beyond the GDPR. This offer rests on qualified hosting — HDS or SecNumCloud depending on your sector — reinforced security and documentation built for your auditors. Hosted in France: your regulated data stays with you. Every decision about a person stays human.
Updated on
The activity log can be worked from over the period requested, action by action.
The human approval points and their audit trail are documented.
🔗 Sourced · operating documentation and log
This architecture answers the European AI Act's requirements for high-risk uses.
✎ Support · human decision recorded
A Blue Lemon Agent agent for regulated sectors rests on qualified hosting — HDS or SecNumCloud depending on your sector — reinforced security and documentation built for your auditors: certification, scope, access matrix, workable log. No decision about a person is automated. Hosted in France, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
These figures describe our offer, not results measured at a client. How large the gain is on the level of certification required and the scope of the processing is confirmed by a pilot.
What does an AI agent demand in a regulated sector?
In health as in finance, the ability to produce evidence counts as much as the function the agent performs.
! The issue
A regulated sector calls for qualified hosting, full traceability and evidence that can be put to an auditor. All three are designed in from the architecture: they cannot be added afterwards. This offer builds them in, with the corresponding operating documentation.
✓ Our answer
Your compliance department has an agent hosted in France, whose every action is logged and whose human approval points are documented. No decision concerning a person is automated, in line with the European AI Act's requirements for high-risk uses. Local inference or an isolated resource hosted in France: your regulated data does not leave your perimeter.
Your regulated health or financial data: sovereignty & compliance
In health and finance, the architecture has to satisfy sector requirements on top of the GDPR. Here is how it does.
Local inference
The agent can run on a machine belonging to your organisation: no regulated data leaves the network.
Hosting in France
Otherwise, a dedicated and isolated resource hosted in France, under French law — your regulated-sector processing: processing and access within the European Union targeted by the architecture.
Reduced extraterritorial exposure
For your regulated health or financial data, the architecture aims to reduce exposure to the Cloud Act and FISA 702; being located in France or in the European Union does not, on its own, guarantee immunity.
Isolated resource
No pooling: an environment strictly dedicated to your organisation and its sector's requirements.
Evidence built for your auditors
Hosting certification, scope of the processing, access matrix and a workable log are documented and kept up to date.
AI Act: governed deployment
The agent is strictly in support; no decision concerning a person is automated, and every human approval is recorded; traceability and human oversight from end to end.
What depends on the architecture chosen These points are not general guarantees: they are settled deployment by deployment, in the quotation.
- The applicable location is that of the architecture set out in the quotation and verified before commissioning.
- Local execution is announced only for the configuration explicitly described and accepted in the quotation.
- The applicable isolation depends on the deployment mode set out in the quotation; no dedicated isolation is presumed.
- Roles and permissions are configured and accepted for the identities and systems actually connected.
- The events logged, their content, their retention period and who may access them are defined for the deployment chosen.
See the agent at work
5 real situations, taken from those that come up most often. Pick one: the exchange unfolds as it would in your organisation.
A scripted demonstration. These exchanges show how the agent behaves — its sources, its refusals, what it leaves to your teams. Nothing is sent from this page, no model is queried here, and the matters named are fictional. That is precisely what we promise your data.
The behaviours shown here — monitoring, automation rules, routing and reminders — are configured with you during deployment, from your tools, your rules and your thresholds.
The architecture points named in these exchanges — location, local execution, isolation, encryption, role-based access, logging — are not a guarantee attached to the demonstration: they are those of the architecture set out in your quotation, and verified before commissioning.
The company in this demonstration
Fictional companyMutuelle Ambrelis — health and income protection insurer
- Sector
- Supplementary health and income protection — care reimbursements, group company schemes, third-party administration
- Headcount
- 310 staff, including 6 in compliance (1 director, 2 lawyers, 2 controllers, 1 information security officer) and 14 in IT
- People served
- 240,000 members and 1,900 member companies, 34 of them under third-party administration
- Scale
- 3.1 million reimbursement statements a year, 47,000 income protection claims of which 8,560 require the medical adviser's opinion, 12 internal control reviews and 2 access reviews a year
- Tools in place
- Policy and claims system, 9 years of document management, a data warehouse of 214 fields, mail and corporate directory — the agent plugs into them, nothing is replaced or migrated
- Who decides
- The compliance director sets the scope of processing; the security officer approves the architecture and the roles; the medical adviser alone rules on any file touching a member's health
- Room for improvement
- Building the compliance file takes 65 % of a launch and is redone for every project; checking traceability takes 40 % of an internal control review and is done by hand; reviewing role-based access takes 35 %; and 11 weeks pass between a business request and the first use going live
Ambrelis is not looking to work around its obligations: it is looking to stop rewriting them for every project. Its data is among the most protected there is — care reimbursements on one side, group scheme financial flows on the other. The agent runs on local inference on a machine belonging to the insurer, or on a qualified resource hosted in France; it plugs read-only into the policy system, the document management system and the data warehouse, and nothing it produces goes out without a person's approval. The exchanges below cover a year, from the first compliance file to the review presented to the board.
This company, its figures and the exchanges that follow were invented for the demonstration. They illustrate a common situation; they describe no real client.
The gap I measured, and it is the gap that decides everything else: building the compliance file takes 65 % of a launch — 221 hours out of 340, and you start it again from scratch on every project. The three files I read describe the same architecture, the same roles and the same retention periods: the same document, written three times by three different people.
What I have already written, and what is waiting for you this morning: the full operating file — hosting qualification, scope of the data processed, role-based access matrix, usable activity log. The role-based access matrix is the table that states, function by function, which data a person may open and which stays closed to them. It is written once and it serves every use that follows.
What that shifts, calculated on your own baseline: building the file goes from 65 % to 8 % of a launch — from 221 hours to 27. 194 hours given back per use, and you have six ahead of you.
And the figure your executive committee will look at before the hours: 11 weeks currently pass between a business request and the first use going live. With the file no longer to be rebuilt, the second use went live in 3 weeks and the sixth in 12 days.
What I propose: that your compliance director read the operating file this week — 14 pages, every statement backed by a document of the insurer. She corrects a word where a word is needed, and it becomes the reference file for your six uses. operating-file_qualification-scope-access-log.pdf221 hours down to 27 per use
⛓ Sourced · timesheets from the last 3 launches, compliance files filed, register of processing activities
Hosting health data on behalf of others requires, in France, a host certified for that purpose: the obligation falls on the host, and it is proven by a certificate in force that you file with your documentation. SecNumCloud is a security qualification issued by the French national information systems security agency; it does not target health data but the level of security and immunity from foreign law.
What the sorting gives, use by use:
· 4 of your 6 uses touch health data — income protection claims, questions about statements, complaints, group scheme reviews. Those fall in the perimeter where the HDS hosting requirement applies, and the certificate is filed at go-live.
· 2 touch none — checking the onboarding documents of member companies, and maintaining your operating documentation. They sit on the qualified resource, and it is 100 % in France in both cases.
· Minimisation removes 153 fields out of 214. Minimising means processing only the data the stated purpose genuinely needs. These are not fields I refuse to read: they are fields none of your six uses needs, and every field removed is one line less to defend in front of an auditor.
The gain, and it is immediate: 2 uses out of 6 leave the most demanding perimeter, and their go-live no longer depends on your hosting-qualification calendar — 5 weeks saved on each of the two.
What I propose next: that the security officer settle the allocation of the six uses to the two environments — the table is done, one cross per use, with the reason alongside. He signs, and I build both environments straight after: 100 % in France, 0 data outside the European Union, backups included. scope-of-processing_61-fields-out-of-214.pdf12 health fields, 153 fields removed
⛓ Sourced · data dictionary of the 214 warehouse fields, specifications of the 6 uses, hosting certificates in force
The four documents an auditor asks for, and where each one stands:
· The hosting qualification — the HDS hosting requirement is settled with you at scoping, before any go-live: the host's certificate and the resource's qualification attestation are the documents that scoping must produce, dated on delivery, with their expiry and an alert set 90 days ahead.
· The scope of the data processed — 61 fields kept out of 214, the purpose of each, its retention period, and the date the field entered the scope.
· The role-based access matrix — 6 roles for your 20 people concerned, kept current as staff move.
· The activity log — usable action by action over whatever period he chooses, with no rebuilding and no export prepared for the occasion.
What that changes for your team, in figures: your last three audits took 9, 11 and 8 days of preparation respectively from your two controllers. With the file maintained, preparing the next one takes half a day of reading — 27 controller days given back to control itself.
What I propose, and it is the best use of January: a dry-run review, half a day. I put the 34 questions your last three auditors actually asked, I answer them with the documents in hand in front of your compliance director, and whatever is missing gets fixed in January rather than in March. The protocol fits on one page and it is already written. dry-run-review_34-auditor-questions.pdf9, 11 and 8 days down to half a day
⛓ Sourced · reports from the last 3 audits, questions asked by the auditors, certificates and attestations in force
Where the model runs: inference is local, on the machine your IT department installed in your own server room. Across the 3.1 million statements processed this year and the 47,000 provident-benefit files, not one byte left your network — your firewall's outbound counter says so, and that is what carries the proof.
What “sovereign” means concretely here: the model, the 214 fields of your data warehouse and the 9 years of your document management system stay within your walls; no transfer outside the European Union in the architecture settled with your head of information security; access is granted by role, traced, and withdrawn in one minute. And the model can be swapped without your data moving: the base is yours, the model is interchangeable — which is what makes sovereign AI an architecture rather than a promise.
What it gives you back: the “hosting and data flows” part of the compliance file weighed 68 hours per launch and was rewritten for every project. It is now written once, dated, and re-signed in 3 hours per use case: across the six use cases in service, more than 390 hours given back, rounded down.
The figure that does not flatter me: local inference costs me 1.9 seconds per statement against 0.7 seconds for a model called remotely — almost three times slower. At your volumes that means 4 hours of overnight processing instead of 1 h 30. That is the price of sovereignty, and it is paid at night: neither your 6 compliance staff nor your 14 IT staff wait in front of a screen. If that delay ever got in the way of a daytime use case, the answer is a bigger machine — I will cost it out on one page — not a step outside your walls.
⛓ Sourced · 3.1 M statements, 0 bytes leaving the network, 68 h down to 3 h per use case
Traceability, here, is the ability to say who did what, when, on which data, and what the system produced in return. 4.7 million actions were logged this year, and each one carries the author, the timestamp, the data touched and the outcome.
What I hand over at every review, without being asked:
· The statement for the period, filtered on the perimeter the controller chose.
· The exceptions — any action without the expected validation, any out-of-role access, any data touched outside the declared scope. This year: 0, 0 and 0, and the statement proves it line by line rather than by assertion.
· The 12 checks of your annual plan, each with its outcome and the document behind it.
The time this shifts: checking traceability goes from 40 % to 5 % of a review — from 16 hours to 2. Across 12 reviews a year, that is 168 hours going back to analysing the exceptions, which is the one job your controllers are the only ones able to do.
What I propose for the February review: that the controller choose his period the evening before and find the statement on arrival. On the two reviews where we tried it, the meeting lasted 50 minutes instead of 3 hours — and it was about the exceptions, not about finding them. activity-log_4-7-million-actions.pdf16 hours down to 2, 0 out-of-role access
⛓ Sourced · activity log for the year, internal control plan, minutes of the last 12 reviews
What the matrix carries, and where it comes from: 6 roles for the 20 people concerned, fed from your corporate directory. An arrival, a departure or a change of department is reflected the same day — it is staff movement that ages a matrix, never the matrix itself.
What this year's review brought up, and I give it to you with its correction: 23 accounts carried a right they had not used for 9 months — mostly people who changed department without the old right falling away. The 23 withdrawals are written, one per line, with the date the right was last used alongside. You approve the list, and the 23 rights fall within the minute.
And the argument I suggest you keep for your auditors, because it is rare: a right is withdrawn on a word and it is withdrawn within the minute, across every use at once, and the withdrawal is itself logged. Most systems can grant access quickly; few can prove the date and time at which they took it back.
The time this shifts: reviewing role-based access goes from 35 % to 4 % of the operating effort — from 62 hours to 7 per half-year. Across two reviews a year, 110 hours given back.
What I propose next: that any right left unused for 120 days be flagged on its own, with the withdrawal already drafted. Over the past year, that single rule would have taken the 23 accounts out three months earlier — you set the period, I put the rule in place the same day. role-based-access-matrix_6-roles-20-people.pdf62 hours down to 7, 23 rights withdrawn
⛓ Sourced · corporate directory, access log, staff movements for the year
How the compartmentalisation is built:
· The 12 health fields live in a separate space, encrypted apart, whose key is held by none of the five other roles. A compliance controller opens the file, its timeline and its administrative documents; he does not open the medical data — and he has no need to open it to do his job, which the matrix states in black and white.
· The medical adviser has the complete file, and each of his openings is logged like any other.
· Encryption in transit and at rest, keys held by the insurer, and encrypted backups hosted in France.
· Nothing I read trains a model, neither ours nor a third party's. What I learn from Ambrelis serves Ambrelis.
· Hosting in France, under French law, architecture designed to reduce exposure to extraterritorial legislation, location alone not being enough to guarantee immunity.
The figure that sums up the year: 0 out-of-role access across 4.7 million actions, 0 data taken outside the insurer's perimeter, processing in the EU targeted.
And what that earns you commercially, since that is the real question: of your 34 third-party administration mandates, 11 require hosting in France and a demonstration of compartmentalisation in the framework contract — third-party administration means running another organisation's schemes on its behalf, with its members and its data. You are now able to show it in writing, dated, with no preparatory work.
What I propose: that I maintain the sheet those 11 principals ask for at renewal — hosting, subcontractors, retention periods, who accesses what. It is asked for once a year, takes three days to find, and it has been written since this morning. compartmentalisation-and-encryption_who-sees-what.pdf12 health fields isolated, 0 out-of-role access
✎ Framework · compartmentalisation architecture, access log, framework contracts of the 34 administration mandates
· Member questions about statements — 138,000 a year, an answer prepared in 20 minutes instead of 4 days. The largest volume, and the most visible to the member.
· Income protection claims — 8,560 a year, 22 days down to 6.
· Checking member companies' onboarding documents — 1,900 files, completeness checked on the day of filing.
· Complaints — 4,200 a year, the file rebuilt with its history before the first reading.
· Annual review of group schemes — 1,900 contracts, gaps between the amendment and the configuration raised before the review.
· Maintaining the operating documentation — current at all times, and it is what your auditor will read in March.
What the foundation changed on lead times, and it is the most telling figure: 11 weeks between a business request and go-live for the first use; 3 weeks for the second; 12 days for the sixth. It is not the uses that got shorter, it is the file that no longer had to be rebuilt.
What that is worth in effort: 194 hours given back per use on building the file alone, 1,164 hours across the six.
What I propose: that we take the seventh now. Your committee minutes name chasing unpaid contributions as the first candidate — I build the operating file in 27 hours and the use goes live within a fortnight if your compliance director selects it. six-uses_on-a-single-regulated-foundation.pdf11 weeks, then 3, then 12 days
⛓ Sourced · specifications of the 6 uses, go-live log, minutes of the information systems committee
The nine reasons, in volume order: out-of-pocket amount not understood, reimbursement lead time, annual cap reached, procedure outside the schedule, fee overrun, direct billing refused at the pharmacy, change of bank details, removal of a dependant, certificate to reissue.
What separates a prepared answer from a general one, and this is the whole point: I read the member's group scheme, his level of cover and his statement, and the answer carries his own figure. Not “your policy provides for a cap” but “your optical cover provides €300 per two-year period, you used €190 of it on 14 March, and €110 remain until 14 March next year”.
The lead time, which is the real gain: the first answer used to go out in 4 working days on average; it is prepared in 20 minutes and waits for the case handler's approval. Across the nine reasons, 92,000 answers a year come out this way.
What that gave you, measured over the first half-year: complaints about response times fell by 38 %, and the 4,200 annual complaints moved to a run rate of 2,600. A complaint costs you 41 minutes of a case handler on average: that is 1,090 hours less over the year.
The figure I also give you, because it is better that it comes from me: on the 46,000 questions that fall outside the nine reasons, I hand over a written answer but I do not send it — they are too varied for a common regime, and they still go out within 4 hours because they reach the case handler already written, file open and policy alongside.
What I propose next: that a tenth reason be opened — adding a newborn, 3,100 questions a year, a single cover rule, and the answer already written. You read it over, and it joins the regime of the other nine the next day. member-questions_9-reasons-92000-answers.pdf4 days down to 20 minutes, −38 % complaints
⛓ Sourced · 138,000 questions from the year, group schemes and cover levels, complaints register
How that holds technically: a use has access to no data until its specification is signed — purpose, fields requested, roles authorised, retention period. This is not an after-the-fact check, it is the condition of access to the data, and it is what your auditor has been trying to verify for three years without ever being able to prove it.
What that changes for the department asking, and this is where compliance stops being a brake: I build its specification from its request in plain language — the fields it thinks it wants, those its purpose genuinely needs, and the gap between the two, quantified. Across the six uses, the initial request carried 34 fields on average and the signed specification kept 12. The department lost nothing: none of the six asked to reopen a field that had been removed.
What that changes for compliance: your director reads a two-page specification instead of arbitrating a project already built. Across the six, her decision took 2 days on average, against 5 weeks before — she decides faster because she decides earlier.
What I propose: a standing desk — any department writes its request in three lines, I hand back the quantified specification the next day, and compliance rules on the document. Of the four requests received this quarter, two were selected, one reworded with half as many fields, and one dropped by the department itself once it saw that its purpose held without any named data. That desk opens tomorrow morning if you want it.
What I hand over for each of the 8,560 claims that require his opinion:
· The documents gathered and checked — sick note, salary certificate, applicable group scheme, amendments in force, payment history. What is missing is requested from the right holder on the day of filing, not three weeks later.
· The chronological timeline, on one page: dates, amounts, earlier decisions.
· The match against the cover — waiting period, maximum benefit duration, applicable rate, each one referred to the clause of the member company's group scheme and to its version date.
· The points calling for his judgement, set out at the top, with the material that bears on them.
Where the law places the signature, and why that is an argument rather than a constraint: a decision producing legal effects on a person cannot rest on automated processing alone — every person has the right to obtain human intervention. It is that signature that makes your decision reasoned, enforceable and defensible if the member challenges it. What I give back to you is not the signature: it is the 21 days that used to come before it.
The result measured over the year: average lead time 22 days → 6 days; files complete on filing: 8,100 out of 8,560, against 4,900 last year; 8,560 decisions taken by a professional, 0 automated, and each decision carries its author and its timestamp.
What I propose next: that the member receive, on filing, the exact list of what is missing and the date his file will be complete. Over the trial quarter, 340 files were completed 9 days earlier on average — and “where is my claim?” calls halved on that scope. income-protection-claim_instructed-and-reasoned.pdf22 days down to 6, 8,100 complete files out of 8,560
⛓ Sourced · 8,560 claims from the year, group schemes and amendments, log of the medical adviser's decisions
What it covers, and I bounded it on your own files:
· Sick leave under 30 days, on a group scheme with no amendment under way, with every document gathered and no point of medical judgement. Over the past year, 3,240 of the 8,560 claims met those four conditions, and the medical adviser granted every one — 3,240 times out of 3,240.
· A cap in amount: €2,500 of benefit per claim, above which the claim goes back to the medical adviser. That threshold covers 3,240 claims; at €4,000 it would cover 3,890, and I give you both figures so that you choose on numbers.
· A date: the mandate runs six months, and it is renewal that needs a signature — not stopping.
· A statement every morning: the benefits granted the day before, on one page. A mistake is caught in an hour, not in three weeks.
· Immediate withdrawal: a word from you and the claims go back to draft for approval, within the minute, with nothing else changing.
What that earns, in figures: 3,240 claims granted on the day of filing instead of 6 days, 1,300 hours of medical adviser time given back to his 5,320 complex claims, and a member on sick leave paid in the week he needs it. It is also the figure your member companies look at when their group scheme comes up for renewal.
The decision belongs to your compliance director and your medical adviser — and it is taken on a text that is already written, with one signature. You sign this morning, the 3,240 claims in the regime start tomorrow, and the review is set in your diary on the 15th of the sixth month. benefit-mandate_capped-dated-withdrawable.pdf3,240 claims, €2,500 cap, 6-month review
✎ Framework · drafted mandate, 8,560 claims of the year sorted by condition, earlier decisions of the medical adviser
What I hand to the professional before he rules:
· The candidate ground, written in plain language, and the clause of the group scheme that supports it, with its version date and the applicable amendment.
· The documents that establish it, each numbered and referenced in the text.
· What points the other way, where there is such material — and there is, in 1 file out of 6. A refusal that ignores the favourable element is a refusal that falls.
· The 3 comparable precedents of the insurer, with the decision taken at the time. Equal treatment is proven with precedents, and nobody ever has time to look for them.
· And the notification letter drafted, with the appeal routes of your policy and the time limit to use them.
What that changed, measured over the year: of 1,040 refusals notified, 61 were challenged against 148 last year, and 39 of the 61 challenges were upheld on re-examination against 22 of the 148. A reasoned refusal is challenged less, and it holds better when it is.
And the time it gives back: drafting a reasoned refusal used to mean three days of back-and-forth between the case handler and the lawyer; it now takes four minutes of reading. Across 1,040 refusals, that is your two lawyers getting their time back for the 61 genuine challenges.
What I propose now: that the 61 challenges of the year become 61 indexed precedents, and that every new refusal go out with the three closest ones. Of the 22 challenges in the last quarter, 17 resembled a case already settled — and your lawyers gave their answer in half a day instead of a week.
The three items you were measuring, and what they became:
· Building the compliance file: 65 % → 8 % of a launch — 221 hours to 27, 194 hours per use, 1,164 hours across the six.
· Checking traceability: 40 % → 5 % of a review — 16 hours to 2, 168 hours across 12 reviews.
· Reviewing role-based access: 35 % → 4 % of the operating effort — 62 hours to 7 per half-year, 110 hours over the year.
What those hours became, according to your own timesheets: +44 % on exception analysis and advice to the business, and two third-party administration tenders you had not answered last year because you could not produce the hosting file in time. You answered both and won one: €210,000 of annual fees, and it is the only figure in this review that shows on your income statement.
The figure that does not flatter me, and I publish it with the rest: of 4,100 claims instructed in the first half-year, 218 had to be reworked on substance — 5.3 %.
Its cause, measured rather than assumed: 171 of the 218 concerned group schemes whose amendment in force was not in your document management — it lived with the broker. I was faithfully reproducing an outdated version of the policy. The other 47 were situations with no precedent at your house.
What I did with it, and it is measured: any policy whose amendment is missing triggers a request to the broker the same day, and the claim waits for the document instead of going out on an old version. Second half-year: 39 reworks on 4,460 claims — 0.9 %, and not one of them comes from a missing amendment any more.
What I propose for the board: the calculation page is written and fits on one side — three effort lines, two lead times, one revenue figure. Give it to the directors with the notice of meeting: a figure read the day before is discussed better than a figure discovered in session. yearly-review_1442-hours-and-a-contract-won.pdf65→8, 40→5, 35→4, and 5.3 % down to 0.9 %
⛓ Sourced · timesheets for the year, log of claim reworks, responses to administration tenders
· I request the missing document from whoever holds it, on the day of filing. Over the year, 3,180 requests sent, 2,890 documents back within eight days — and the reverse holds too: a document received closes the request instantly, so a member is never chased for a paper he has already provided.
· I flag every certificate, qualification and amendment whose expiry is approaching, 90 days ahead. This year, 14 expiries flagged, 14 renewed in time, including the hosting certificate your auditor would have asked for in March.
· I hand you the week's statement every Monday: output, exceptions, expiries, files waiting on a document. It is the only thing I send of my own accord, and it goes only to the compliance department.
And the acts that stay with a person, because that is precisely what gives them their value: every decision about a member is signed by a professional — 8,560 times out of 8,560 this year; the allocation of a use to an environment is signed by the security officer; a field entering the scope is signed by the compliance director. Those three signatures are what makes your decisions enforceable — and I make them possible in minutes instead of weeks.
What I propose for the session: that Monday's statement go to the audit committee once a quarter, as it is. Four pages a year, no extra writing, and the committee sees the system working rather than a report written for it.
What there is to dismantle on the day you stop:
· The index and the environments. They are deleted, and they held none of your files — only the means of finding them where they are. Your nine years of document management have not moved by one byte: same files, same paths, same rights.
· The activity log. It is handed to you in an open format, or destroyed — you choose, and the question is settled at go-live rather than on departure.
· The operating file, the map of the 61 fields, the matrix of the 6 roles, the nine standard answers, the income protection instruction grid and the 61 indexed precedents. They are yours: they are made of your material, they stay in your files, readable without us. That is the asset this year will have created, and there would be no reason for it to remain with us.
What does not exist, and is worth checking with everyone: no migration on the way in, therefore none on the way out. Your policy system is not replaced, your document management stays yours, no format belongs to us, and none of your 310 staff changed tools — your case handlers read over instead of assembling.
What I propose so that this does not stay a sentence: a dry-run exit at the end of the first quarter, half a day: we switch off, we check that the insurer handles claims exactly as before, we switch back on. The protocol is written, it fits on one page, and the date that costs you least is the first Friday of February — 640 files open that day against 1,900 at the September peak. The board will know what the promise is worth before committing to a second year. reversibility_what-stays-with-the-insurer.pdf0 migration in, 0 migration out
✎ Framework · index architecture, export formats for the file and the log, dry-run exit protocol
Your case is not here? That is exactly what a 15-minute conversation is for. Book the free audit →
What does the agent actually do?
One regulated foundation, several business functions. All these uses work in support, subject to your approval.
Qualified hosting
HDS or SecNumCloud, according to your sector's requirements.
Audit documentation
Certification, scope, access matrix and a workable log.
Reinforced security
Partitioning, encryption and access controls at the level your sector requires.
Sovereign AI
The hosting and confidentiality foundation the offer rests on.
Need to go further?
These agents handle a different business process, with their own owner and their own price. They are added to this one.
In 15 minutes we identify the most relevant agent — without oversizing the project.
What does a regulated organisation gain from starting on a compliant foundation?
By building the requirements in from the architecture, the effort shifts from achieving compliance to using the agent. How large the gain is depends on your volume and remains to be confirmed by a pilot.
The stages of your AI agent project
Audit & scoping
15 minutes to target the use case with the best return.
Quote or direct sign-up
A catalogue offer is bought online; a specific need gets a costed quote.
Design
We design the agent and its guardrails.
Integration & testing
We connect your tools to the agent, which is itself hosted in France.
Rollout
Going live and training your team.
Operation
Continuous supervision and improvement.
One package, one agent
An agent for regulated sectors (qualified hosting, reinforced security, audit documentation), installed and operated for you.
Four guarantees that matter in a regulated sector
Related resources
Your questions, our answers
Which hosting requirement applies?
What evidence is provided to an auditor?
Can the agent decide on its own in this area?
Can several business functions be deployed on this foundation?
Where is the data hosted?
How long does it take to deploy this agent?
Going further
Let's size up the potential within your regulatory framework
15 minutes to frame your requirements and your processing — hosted in France, supervised, with no commitment.