Private AI for regulated organisations

Private AI for
Regulated Organisations

Futurion Solutions builds AI tools and automation that keep sensitive data inside your own boundary — on your hardware or your cloud account. We work with legal, compliance, finance and healthcare teams across Spain and the EU, mapping every deployment to GDPR, the EU AI Act, ISO 27001 and SOC 2.

GDPR

GDPR

  • Art. 46 - Appropriate safeguards - PII / sensitive data
  • Art. 35 - Data Protection Impact Assessment - High-risk / sensitive data
  • Art. 32(1)(b) - Confidentiality, integrity, availability, resilience - PII / sensitive data
  • Art. 32(1)(a) - Pseudonymisation and encryption - PII / sensitive data
  • Art. 9 - Special categories of personal data - Sensitive data
  • Art. 5(1)(c) - Data minimisation - PII
HIPAA

HIPAA

  • 45 CFR § 164.502(b) - Minimum necessary standard - PHI / sensitive health information
  • 45 CFR § 164.530(c) - Safeguards - PHI
  • 45 CFR § 164.312(a) - Access control - ePHI
  • 45 CFR § 164.312(b) - Audit controls - ePHI
AI

AI Act

  • Art. 10(5) - Processing special categories of personal data for bias detection and correction - Sensitive data
  • Art. 15 - Accuracy, robustness and cybersecurity - PII / sensitive data
  • Art. 78 - Confidentiality - PII / sensitive data / confidential information
ISO

ISO 27001

  • Annex A 5.14 - Information transfer - PII / sensitive data
  • Annex A 8.12 - Data leakage prevention - PII / sensitive data
  • Annex A 8.11 - Data masking - PII / sensitive data
  • Annex A 5.15 - Access control - PII / sensitive data
SOC2

SOC2

  • CC6.6 - Prevention of unauthorised access - PII / sensitive data
  • CC6.7 - Restriction of data transmission, movement, and removal - PII / sensitive data
  • CC7.2 - Monitoring for security events - PII / sensitive data
  • C1.1 - Identification and protection of confidential information - Confidential information / sensitive data
  • P4.1 - Personal information use limitation - PII
  • P6.1 - Disclosure to third parties - PII

Your Compliance Automation Services

Our Services
Protect Sensitive Information
Your Infrastructure — Your Rules
Our Stack
Local LLMs

TrustPrompt

Redact Personal Data Before It Reaches a Public LLM

A Chrome and Edge extension that detects and removes personal data in the browser, before a prompt is sent to ChatGPT, Claude, Gemini and six other services. The text you type is analysed on your own machine; the detection model ships inside the extension.

On-device detection

A 560-million-parameter NER model and 40 checksum-validated rules run in the browser. Detection works offline after install — there is no detection server to send text to.

Custom rules for your own identifiers

Add regex rules for the identifiers only your organisation uses — employee IDs, internal ticket numbers, patient IDs. Organisation rules run in an isolated worker with a timeout, so a bad pattern can never hang the page.

Central control for teams

Push policy through Group Policy, Intune or Jamf, with audit logging that records metadata only — never the prompt text.

TrustCore

Answer Questions About Your Own Documents, On Your Own Hardware

A browser extension with an optional local companion that indexes your documents and answers questions about them on your machine. Questions are answered from your indexed documents, and stay on your machine — there is no TrustCore cloud they pass through.

Graph RAG, not similarity alone

TrustCore builds a graph of the entities and relationships in your documents and reasons over it, surfacing connections that no single document states on its own.

Answers you can trace

Every answer is tied to the exact passage and page it came from, and clauses that conflict across documents are flagged with both sources.

Sovereign by default

Documents, the index and the graph stay on your device or on infrastructure you control. No SaaS, and no subprocessor on the local path.

TrustAuto

Business Process Automation, Built on Infrastructure You Control

TrustAuto automates the repetitive admin work in your business — built on Microsoft Power Automate or self-hosted n8n. The workflow engine orchestrates the tasks; your existing systems stay the authoritative record. It runs on-premise or in a hybrid setup, so sensitive data never leaves your control, and every engagement starts with a free Automation Roadmap. We are also an official SMSEagle Technology Partner — hardware SMS gateways your workflows call to send and receive SMS, WhatsApp and voice, with no cloud SMS provider in the path.

Start with a roadmap

A short assessment of your processes and data flows, returning a written report that scores each workflow and names the automations worth doing first.

Built on Power Automate or n8n

Reminders, follow-ups, intake, invoicing, approvals, and moving data between systems — on-premise or in a hybrid setup, with scoped access and audit trails built in rather than added afterwards.

Ongoing monitoring

We maintain the automations and tune them as volumes, exceptions, and the rules you work under change.

Private AI for Healthcare

MedCore — Private AI for Medical Organisations

MedCore is our private-AI solution for hospitals, clinics and medical groups: medical-grade AI infrastructure that runs entirely on your premises, built on HAPI FHIR and OpenEHR with clinical models that run locally. For context, read our analysis of OpenEvidence's EU/UK withdrawal and what it means for clinical AI architecture.

On-premise by default

Patient data stays within your organisation; nothing is sent to an external cloud.

Standards-based integration

Works with FHIR and OpenEHR records and the systems your teams already use.

Mapped to healthcare obligations

GDPR, the EU AI Act and AEPD requirements, with documentation kept inspection-ready.

FAQs

Frequently Asked Questions

How our tools and automation keep sensitive data inside your own boundary.

What does Futurion Solutions do?
We build private AI tools — TrustPrompt, TrustCore and TrustAuto — for organisations that work with sensitive or regulated data. TrustAuto automates repetitive business processes on Microsoft Power Automate or self-hosted n8n, and every engagement starts with a free Automation Roadmap. Everything is designed to run on infrastructure you control rather than a shared cloud service.
Does our data leave our own infrastructure?
No. TrustPrompt analyses text in the browser, TrustCore answers from documents on your own machine, and TrustAuto runs entirely on your own premises alongside the systems it automates. Sensitive data stays inside your boundary.
Which compliance frameworks do you map to?
GDPR, the EU AI Act, ISO 27001 and SOC 2, plus HIPAA and Spanish AEPD requirements for healthcare. Each deployment is documented against the obligations you answer to.
Can the products run fully on-premise?
Yes. TrustPrompt and TrustCore work locally by default; for heavier workloads you point them at endpoints you already run. MedCore runs entirely on your premises.
How is TrustPrompt different from a network DLP proxy?
A proxy has to receive your text to inspect it, which adds a party that now holds the data and breaks on encrypted or personal-device traffic. TrustPrompt removes personal data in the browser before the prompt is sent, so nothing new in the path ever sees the original text.
What is the free automation roadmap?
A short assessment of your data flows and compliance posture. You receive a written report with risk scores and the automations worth doing first. It is a roadmap you can act on independently, with no obligation.
What does this cost?
The roadmap is free. TrustPrompt and TrustCore are offered as per-seat plans with a free local tier; automation engagements are scoped from the roadmap. Plans follow the EU SME size bands.
Do you integrate with our existing systems?
Yes. Automations and tools work alongside your current software and records — including FHIR and OpenEHR in healthcare — rather than replacing them.

Compliance & AI Insights

View all posts »

See Where AI Fits — Without Moving Your Data

Start with a free roadmap of your data flows and automation opportunities, mapped to the regulations you answer to. No obligation.