What we do · Applied artificial intelligence

Applied Artificial Intelligence

We develop high-end AI solutions with engineering discipline: models chosen for cost, quality, security and regulatory requirements, applications that carry out real work, agents that work within defined permissions, infrastructure to run all of it wherever the client decides, and active defense against breach attempts. Decisions stay with people, and we design the approval points where they accept or reject what the system proposes.

ShapeFixed-scope project; then operation or subscription
First stepAI inventory and governance, 3 weeks
FoundationArquipélago; commercial and open models; MCP and APIs

When it makes sense

A process consumes too many people

Document triage, data extraction from contracts, order classification, first response to customers. Reading-intensive work that keeps people from the decisions that need their judgment.

The AI needs a home of its own

Regulatory data residency requirements that call for hosting or processing in specific regions, restrictions on external vendors, or volumes that make in-house infrastructure more economical.

Nobody knows how much AI the company already uses

Tools bought on a corporate card, features switched on by default, assistants on personal accounts. Company data leaving through channels no policy covers.

The defense has to react at the speed of the attack

A breach attempt at three in the morning does not wait for the team to wake up. Detection, isolation and containment have to happen in seconds, under predefined response rules.

What we do

  • Applications and agents for real processesTriage, classification, data extraction, assisted drafting, customer response with human escalation, automation of whole workflows. Approval points sit at the stages where risk is highest, so the rest of the workflow runs without interruption.

  • Internal search and knowledgeAnswers drawn from contracts, manuals, tickets and records, with the source cited and access control enforced at query time.

  • AI infrastructureServers and services to run open models in the client's environment or ours, with hosting and processing arrangements designed to meet regulatory data residency requirements. Dedicated facilities, with partners, when the volume justifies them.

  • Active defense during breach attemptsAgents that detect, isolate and respond in real time inside the client's perimeter: credential lockout, machine isolation, decoys and traps that draw in and record the intruder, automatic containment under written rules and with human oversight where actions have major consequences.

  • Adversary emulationWith written authorization and a defined scope, agents that attack the client's own environment the way an adversary would, to prove the defense works and to find what it does not cover. The exercise is never directed at third parties.

  • AI inventory and governanceWhich AI is already in use, who authorized it, what it can access; risk classification under the LGPD, ANPD guidance and the EU AI Act; a policy grounded in actual use; audit trails.

  • Arquipélago and specialized componentsOur agentic operating system, on which we build components for different needs, with governance built in and independence from any model vendor. Meet Arquipélago.

What you receive

An application or an agent in production inside your operation, with the authorization model documented and implemented, the evaluation set built from real cases with metrics agreed with the people who use it, the evidence trail configured and the documentation for your team. For governance, the inventory, the risk classification, the policy and the remediation plan with estimated effort. For defense, the response rules written with the client, the agents deployed and a report of every activation.

AI inventory and governance

3 weeks · fixed price

Which AI is already in use in your environment, who authorized it, what it can access, the regulatory exposure and the control model to adopt.

Request a Conversation

Application or agent made to measure

Fixed scope · one operation

A workflow built for your operation, with a defined authorization model, an evaluation set and an evidence trail.

Request a Conversation

Frequently asked

Does our data go to the model vendor?

It depends on the model, and the choice is made on that basis. Open models run on the client's infrastructure or ours; commercial models are used under a contract that excludes training on the client's data. We say which is which before starting.

Does the AI replace the team?

It replaces repetitive work that requires reading. Decisions stay with people, and designing the approval points, where someone reviews what the system proposes before it takes effect, is part of the work.

Does "active defense" mean attacking whoever attacks us?

No. Adversary emulation and intrusive testing happen only against the client's own environment, with written authorization, a target, a scope and a window. Against third parties, we work through legal counsel and law enforcement, alongside the professionals responsible.