Skip to content
EU inference · AWS FrankfurtGDPR Art. 28 processor

Use Claude and other leading AI models — without losing control of personal data.

Opsio Vault AI is a secure gateway between your applications and the AI models. It runs in the EU, removes personal data before the model sees it, blocks passwords and keys, and logs every call for your auditor. Opsio's AI team operates it under a data processing agreement. For development teams building AI into products, and IT teams giving staff approved AI tools.

Enforced by the platform
EU
Model inference
Frankfurt + EU inference
0
Prompts used to train models
No transcript store
Blocked
Passwords and API keys
Before any model call
100%
Calls logged for your auditor
Kept 18 months
vault-ai / request journey
Prompt · support-desk→ claude-sonnet
Draft a reply to PERSON_1 (EMAIL_1) confirming the refund to IBAN_1.
EU inference profileus-east-1
A write-once audit record proves what happened — without the content.
Delivered to your app · real values restored
Dear Anna Lindqvist, your refund to DE89 3704 0044 0532 0130 00 has been approved and will arrive within 3 working days.
Audit record · write-once
Served
caller
support-desk · app key
model
claude-sonnet · EU inference profile
inspection
3 identifiers pseudonymised
guardrail
passed
content
not logged
Content never logged · kept 18 months
Write-once audit// Illustrative
Free walkthrough · 30 minutes · No commitment

Say yes to AI — and still answer your auditor.

We show you the Vault AI portal, a real call being pseudonymised, a pasted secret being refused before any model sees it, and the evidence pack your auditor, customer or regulator can review. Then we agree the privacy profile that fits your organisation.

Models run in the EU
AWS Frankfurt · EU inference
Personal data pseudonymised before the model
Per-customer tokens
Secrets refused at the door
Before any model call
Every call provable
Write-once audit · 7-year evidence
Opsio advisor in a customer meeting in Sweden
Meet us in person or on a callOpsio · Sweden
Free walkthrough · ≈ 30 sec
Book a Vault AI walkthrough

30 minutes with an Opsio AI & compliance specialist. See the portal, a live refused call and the evidence pack.

Johan CarlssonFredrik Karlsson
You'll talk to Johan & Fredrik
Your Opsio team · Sweden
30 min·No fee·DPA on request
Ch.02The problem

Every prompt is a data transfer. Can you prove where it went?

Public AI services are the fastest way for personal data to leave your organisation unrecorded. Blocking them doesn't stop it — it just removes the controls.

Your teams want generative AI

And they should. It is the biggest productivity gain in a decade — for writing, analysis, code, contracts and customer service.

Every prompt can carry personal data

Customer names, identity numbers, contract terms, source code — or a password pasted by mistake — all sent to a public AI service.

You stay accountable

Under the GDPR your organisation remains accountable for that data as controller, whatever the AI vendor's terms say.

"What did you send, and can you prove it?"

When an auditor, a customer or a regulator asks what went where, most companies can't answer.

Saying "no" doesn't work

Ban AI and staff move to personal accounts. The data leaves anyway — with no controls at all.

Ch.03How it supports compliance

Six controls, enforced by the platform. Not promised in a policy.

Hover a card to see exactly what each control does. Opsio runs, patches, monitors and answers for the platform under a data processing agreement.

01

Models run in the EU

The platform runs in AWS Frankfurt and calls models only through EU inference profiles or in Frankfurt itself.

Hosted in AWS Frankfurt (eu-central-1)
EU inference profiles or Frankfurt-only models — never a global or US route
Non-EU model routes blocked at three separate layers
CloudTrail logs confirm it
Hover to expand
02

Personal data is pseudonymised before the model sees it

Detected personal data is replaced with pseudonymous tokens before the prompt reaches the model.

Names, emails, phones, addresses
IBANs, card and bank numbers, Swedish personal identity numbers, passport and driving-licence numbers
A separate token key per customer
Real values restored only on the way back to your app
Your privacy profile sets which data classes may be sent at all
Hover to expand
03

No transcript store. Logging off.

Opsio keeps no copy of your prompts or answers, and Bedrock model-invocation logging is switched off.

No transcript store at Opsio
No training corpus at Opsio
Model invocation logging off
Amazon Bedrock does not train on or share your data
Hover to expand
04

Secrets are stopped at the door

A prompt containing a credential is refused before any model call — and costs nothing.

API keys
Passwords
Private keys
Access tokens
Hover to expand
05

Guardrails can't be skipped

A versioned guardrail blocks jailbreaks, prompt injection and harmful content.

Jailbreak & prompt-injection blocking
Harmful-content filtering
Versioned guardrail policy
Fail-closed: if a check can't run, the request is refused
Hover to expand
06

Every call can be proven

A write-once audit record for every request — metadata only, never the content.

Who called and which model
What inspection found & what the guardrail did
Tokens and cost
Compliance evidence kept for seven years
Hover to expand
What Vault AI is

A managed private AI service. One API. One portal.

Your applications and teams get leading large language models through one secure API and one portal. The privacy controls are enforced by the platform itself instead of promised in a policy — and Opsio runs, patches, monitors and answers for it.

The team behind Vault AI · Sweden
Johan Carlsson, Country Manager, Sweden — Opsio
Johan Carlsson
Country Manager, Sweden
Fredrik Karlsson, Group COO & CISO — Opsio
Fredrik Karlsson
Group COO & CISO
Oscar Bergenbrink, CTO — Opsio
Oscar Bergenbrink
CTO
Jacob Stålbro, Head of Innovation — Opsio
Jacob Stålbro
Head of Innovation
Operate
Opsio runs it

The platform, the model catalogue and the guardrails are operated by Opsio — nothing to host yourself.

Maintain
Opsio patches it

Updates, new models and guardrail versions are rolled out and tested by Opsio.

Monitor
Opsio monitors it

Availability, refusals, spend and anomalies are watched continuously.

Accountable
Opsio answers for it

Under a data processing agreement — Opsio is your processor, contractually bound.

Ch.04Models and prices

25 leading AI models, all processed in the EU.

Choose a company to see its models and what they cost today. Prices load from the live Vault AI price list, so what you see is what you're billed.

EU · every modelAll 25 models are processed in the EU. Non-EU routes are refused before any call.

Choosing? Read our ChatGPT vs Claude comparison.

Ch.05The customer portal

Your AI service, in one portal.

Keys, usage, cost, compliance evidence and invoices — for your developers, your DPO and your finance team. Shown from the real portal for a demo company.

Vault AI customer portal — Overview screen
  • Your month at a glance
  • Spend so far this month, and where it's heading
  • Requests that were served, and the ones that were refused
  • What needs your attention, and your onboarding progress
  • Messages from Opsio in one place

Screens from the real Vault AI portal for a demo company. All figures are simulated.

Also in the portal
Usage & cost

Spend by model, by application and day by day, with cost alerts.

Pricing

The price list you're on and what every model costs.

Reports

Download your records, or ask for a recurring report.

Documents

Your agreements, the terms that apply and who is involved.

People

Invite colleagues as Member (read) or Administrator.

Support

Raise requests with Opsio and see live service status.

Settings

Escalation contacts, network allow-list and spend ceiling.

Ch.06How you use Vault AI

From signed agreement to your first API call.

Four steps to get going, then your apps and tools call Vault AI exactly the way they call Anthropic or Amazon Bedrock today.

  1. Step 1

    Agree

    Sign the data processing agreement and agree your privacy profile: which data classes are allowed, your model catalogue and your limits.

  2. Step 2

    Onboard

    Eight recorded onboarding checks — agreements, contacts, data and transfer questionnaire, technical set-up, first key — ending in a dated onboarding certificate.

  3. Step 3

    Connect

    Issue a key per application in the portal. Point your app at the Vault AI endpoint from your approved network addresses or over VPN.

  4. Step 4

    Operate

    Follow usage and cost, see every refused call explained, set budgets, and download the evidence pack for your auditor.

No rewrite needed.

Vault AI speaks the Anthropic Messages API and the Amazon Bedrock Converse API. Existing applications, Anthropic SDKs and AWS SDKs keep working — you change a base URL and a key.

Developers

Keep your apps and SDKs. Change a base URL and a key; use model aliases like claude-sonnet. Streaming requests are supported — the answer is released once it has passed outbound inspection.

Teams & tools

Tools that let you set a custom Anthropic or Bedrock endpoint work the same way, each with its own key. Model names sent by common tools are mapped to your approved EU models.

Admins, DPO & finance

The portal: issue and revoke keys, set budgets and limits, see usage and cost per model, every refused call explained, invoices, and the evidence pack for your auditor.

app.py
import os, anthropic

client = anthropic.Anthropic(
    base_url="https://vault.opsiocloud.com",
    api_key=os.environ["VAULT_AI_KEY"],   # opsio_… key for this app
)

reply = client.messages.create(
    model="claude-sonnet",               # alias from your catalogue
    max_tokens=1024,
    messages=[{"role": "user", "content": "Summarise this contract…"}],
)
print(reply.content[0].text)
Anthropic SDK for Python — unchanged, apart from two lines. the lines that change

When a call is refused, you're told why.

Refusals come back as clear error codes, and the portal shows which policy acted and what to change. The most common ones:

422
secret_detected

A password, key or token was in the prompt. No model was called and nothing was charged.

Remove the secret and send again.

403
model_not_approved

The model isn't in your catalogue — including any non-EU model route.

Use one of your approved aliases.

429
rate_limited

A requests-per-minute or daily token limit was reached.

Retry after the stated time, or raise the limit.

402
budget_exhausted

A spend ceiling or application budget set to hard-stop was reached.

Raise the budget in the portal.

503
guardrail_unavailable

The guardrail couldn't be applied, so the call was refused rather than served unchecked.

Retry — this is the fail-safe working.

What Vault AI is built to give you

Your people use the best AI models on your own data. The models run in the EU, personal data is pseudonymised before it reaches the model, a pasted password is stopped at the door, and when your auditor asks, you can show exactly what happened.

Ch.07Compliance

GDPR today. AI Act, NIS2 and DORA ready.

How Vault AI's controls map to the regulations your auditors, customers and regulators ask about.

Opsio acts as processor under an Article 28 GDPR data processing agreement. Model inference, the platform and audit records run in AWS EU regions. Sign-in codes and service notifications are sent through Resend, a US-based sub-processor, under the EU Standard Contractual Clauses and the EU-U.S. Data Privacy Framework; Resend receives recipient addresses and message metadata, never prompt content. You receive the full GDPR document set: DPA, records of processing, DPIA, transfer impact assessment, sub-processor register, retention schedule and a data-subject request runbook. See also what a GDPR-ready cloud service agreement should contain.
Ch.08Free EU AI Act readiness assessment

Your EU AI Act policies, written from your answers. Free.

Vault AI enforces the technical controls. The policies are the other half of EU AI Act compliance, and Opsio's free AI readiness assessment writes them for you: answer about forty minutes of questions across fourteen steps, and the moment you send them you get a readiness score and four documents built from your answers.

AI Governance Framework

Who is accountable for AI, how a use case moves from idea to operation, how risk is classified and which tools are approved.

EU AI Act hooks

  • Art. 4 AI literacy
  • Art. 26 deployer obligations
  • Art. 9 risk management

AI Acceptable Use Policy

Which AI tools and accounts staff may use, what may and may not be entered, how outputs are checked and how incidents are reported.

EU AI Act hooks

  • Art. 4 AI literacy
  • Art. 5 prohibited practices
  • Art. 50 transparency

AI Vendor Due Diligence Checklist

Twenty-three sections for assessing an AI supplier, from data, privacy and security to contracts, oversight, agents and exit.

EU AI Act hooks

  • Art. 25 provider–deployer duties
  • GDPR Art. 28 processors

AI Risk Assessment Template

The record that decides whether a use case may proceed: purpose, data, oversight, legal mapping, classification, controls and approval.

EU AI Act hooks

  • Art. 9 risk management
  • Art. 27 fundamental-rights impact
  • Annex III classification
Policy and platform, together

Your acceptable use policy names the AI tools staff may use. Vault AI is a tool you can name there and then prove: models in the EU, personal data pseudonymised before the model, passwords refused, and every call on the audit record. The vendor checklist has its answers ready in the Vault AI document set.

Free · no card · save and hand to a colleague at any step
Ch.09What your company gets

Everything you need to use AI — and to prove it.

A private endpoint, a portal your security and finance teams will use, and the paperwork your DPO and auditors expect.

A private AI endpoint

A curated model catalogue and a privacy profile agreed at onboarding.

A customer portal

Usage and cost per model, every refused call with the policy that acted and what to change, per-application API keys (expiring and revocable), spend ceilings and budgets.

An auditor-ready evidence pack

Download it at any time — plus an AI Act register and impact-assessment record.

A full GDPR document set

DPA, records of processing, DPIA, transfer impact assessment, sub-processor register, retention schedule and a data-subject request runbook. Not sure where you stand? Take the AI governance & readiness assessment.

Structured onboarding

A defined onboarding programme that ends in a dated onboarding certificate.

Cost control

Rate limits, token ceilings and hard budget stops per company and per application, and transparent invoices tied to an immutable price list.
Ch.10How companies move forward with Vault

From shadow AI to governed AI at scale.

Five steps companies take once AI is safe to use on real data.

Adopt

Replace shadow AI

Give staff a sanctioned, governed AI service they will actually use — instead of personal accounts.

You get

One approved endpoint and portal for the whole company.

Step 01
Build

Put AI to work

Customer service, document analysis, code and contracts — on real customer data, safely.

You get

Production AI on personal data, without exposing it to the model.

Step 02
Sell

Win regulated deals

Answer security questionnaires and customer audits with evidence instead of assurances.

You get

A downloadable evidence pack and GDPR document set.

Step 03
Choose

Stay model-agnostic

Switch or combine Claude, Nova and Mistral without re-engineering or re-assessing your privacy controls.

You get

Simple model aliases; controls stay the same.

Step 04
Prepare

Get regulation-ready

Prepare for the EU AI Act, NIS2 and DORA with a single record of how AI handles your data.

You get

An AI Act register and impact-assessment record.

Step 05
Ch.11FAQ

Private AI and the GDPR — your questions answered.

Opsio Vault AI is a managed private AI service. Your applications and teams get leading large language models through one secure API and one portal, and the privacy controls are enforced by the platform itself instead of promised in a policy. Opsio runs it, patches it, monitors it and answers for it under a data processing agreement.

Stop saying no to AI

Give your teams the best AI models — with the controls built in.

Tell us how your organisation wants to use AI, and we'll show you how Vault AI keeps it compliant.

Contact · 1 business day reply

Talk to Opsio.

Ask for the GDPR document set, the evidence pack, the supported-model list or pricing. We'll respond with a structured next step within one business day.

Fast track
Skip the form — book a 30-min walkthrough.

Get a slot with Johan or Fredrik this week.

Book a walkthrough
Hosting
AWS Frankfurt
EU inference
Reply
New inquiries:
1 business day
DPA (GDPR Art. 28)
NDA on request
No engagement fee
Free consultation
≈ 60 seconds

Tell us how you want to use AI

A short brief is enough — we'll reply with a structured next step.

Vault AI demo