
Your models.Your hardware.Your building.
We install open source language models on infrastructure you own and control. No third party API, no data leaving your perimeter, no clause in someone else's terms deciding what happens to your case files.
Most organisations cannot use the tools everyone is telling them to use.
A law firm cannot paste privileged material into a hosted model. A council cannot send resident records to an endpoint in another jurisdiction. A clinic cannot accept a data processing agreement that permits training on what it submits. The restriction is not caution, it is the terms they operate under.
The answer is not to go without. Open weight models are now good enough for document review, drafting, retrieval and classification, and they will run on hardware you can put in your own rack. The difficulty is that installing, tuning and maintaining them is a specialist job, and it is not one your IT provider has done before.
If the model runs inside your perimeter, the data protection question becomes an infrastructure question. That one you already know how to answer.
From bare hardware to a model your staff actually use.
- Requirement and model selectionWhich open weight model fits the work, the hardware budget and the licence terms you can accept.
- Infrastructure specificationGPU sizing, host build and network placement, whether that is your rack, your colocation or your private cloud tenancy.
- Installation and hardeningInference stack, access control, logging and segmentation, built and configured by the team that also breaks into things for a living.
- Retrieval over your own documentsConnecting the model to your files, matters or case records so the answers cite your material rather than the open internet.
- IntegrationInto the systems people already have open, rather than a chat window they have to remember to visit.
- Handover or ongoing operationRun it yourself with documentation and training, or leave it with us. Both are supported.
What this looks like in practice.
- Llama, Mistral, Qwen, Gemma and other open weight families, selected against the workload
- On premise hardware, colocation, or a private cloud tenancy you control
- Air gapped or egress restricted, depending on what the use case genuinely needs
- Integrated with your existing identity provider, with per group permissions
- Nothing is sent to a third party. Nothing is used for training by anyone but you.
- Full request logging inside your estate, for audit and for incident response
The on premise layer beneath a platform serving 60+ UK councils.
Invision Protect delivers continuous, evidence led penetration testing to UK local authorities and public services. Some of those organisations cannot allow their data to sit in anyone else's environment, whatever the assurances attached to it.
CHMS provides the deployment that solves it: the full platform, installed and running inside the organisation's own infrastructure, under their own control.
“For organisations that require everything inside their own environment, a fully self-hosted, on-premise deployment is available via CHMS Cyber Sec.”

Find out what a scoping call costs you.
Nothing. Half an hour, an honest read on your exposure, and a fixed annual number if it is a fit.


