Cold aisle in a private data hall
Service 02
Self hosted · Air gappable

Your models.
Your hardware.
Your building.

We install open source language models on infrastructure you own and control. No third party API, no data leaving your perimeter, no clause in someone else's terms deciding what happens to your case files.

01The problem

Why this exists

Most organisations cannot use the tools everyone is telling them to use.

A law firm cannot paste privileged material into a hosted model. A council cannot send resident records to an endpoint in another jurisdiction. A clinic cannot accept a data processing agreement that permits training on what it submits. The restriction is not caution, it is the terms they operate under.

The answer is not to go without. Open weight models are now good enough for document review, drafting, retrieval and classification, and they will run on hardware you can put in your own rack. The difficulty is that installing, tuning and maintaining them is a specialist job, and it is not one your IT provider has done before.

If the model runs inside your perimeter, the data protection question becomes an infrastructure question. That one you already know how to answer.

02What we deliver

End to end

From bare hardware to a model your staff actually use.

  • 01Requirement and model selectionWhich open weight model fits the work, the hardware budget and the licence terms you can accept.
  • 02Infrastructure specificationGPU sizing, host build and network placement, whether that is your rack, your colocation or your private cloud tenancy.
  • 03Installation and hardeningInference stack, access control, logging and segmentation, built and configured by the team that also breaks into things for a living.
  • 04Retrieval over your own documentsConnecting the model to your files, matters or case records so the answers cite your material rather than the open internet.
  • 05IntegrationInto the systems people already have open, rather than a chat window they have to remember to visit.
  • 06Handover or ongoing operationRun it yourself with documentation and training, or leave it with us. Both are supported.
03Typical deployment

Specification

What this looks like in practice.

Models
Llama, Mistral, Qwen, Gemma and other open weight families, selected against the workload
Placement
On premise hardware, colocation, or a private cloud tenancy you control
Network
Air gapped or egress restricted, depending on what the use case genuinely needs
Access
Integrated with your existing identity provider, with per group permissions
Data
Nothing is sent to a third party. Nothing is used for training by anyone but you.
Evidence
Full request logging inside your estate, for audit and for incident response
05Selected work

Invision Protect

The on premise layer beneath a platform serving 60+ UK councils.

Invision Protect delivers continuous, evidence led penetration testing to UK local authorities and public services. Some of those organisations cannot allow their data to sit in anyone else's environment, whatever the assurances attached to it.

CHMS provides the deployment that solves it: the full platform, installed and running inside the organisation's own infrastructure, under their own control.

For organisations that require everything inside their own environment, a fully self-hosted, on-premise deployment is available via CHMS Cyber Sec.

Invision Protect
Civic architecture in the United Kingdom
60+ UK local authorities run on the platform. CHMS provides the deployment for those that cannot use anyone else’s environment.
06Next step

No obligation

Find out what a scoping call costs you.

Nothing. Half an hour, an honest read on your exposure, and a fixed annual number if it is a fit.