Skip to main content

Technical Guide

BYOK AI Infrastructure: Secure AI for Regulated Businesses

Bring Your Own Keys (BYOK) AI infrastructure enables regulated businesses to deploy AI with customer-controlled encryption and EU data residency. For workloads where you cannot send data to external services (because of regulation, contractual constraints, or risk appetite) self-hosted AI gives you cryptographic control over your data at every step.

What is BYOK AI?

BYOK (Bring Your Own Keys) AI infrastructure means you control the encryption keys that protect your data, even when processed by AI models. Combined with EU-only data residency, this ensures:

  • Your data never leaves EU jurisdiction
  • You control encryption key lifecycle
  • AI providers cannot access your plaintext data
  • Compliance with GDPR and sector regulations (UK-DPA, NHS DSPT, FCA)

Where this stands today

Customer-held-key (BYOK) encryption — where you hold the keys and we cryptographically cannot decrypt your data — is on our roadmap for dedicated external-client deployments. We have not yet delivered a BYOK engagement. Our own operations today use operator-managed encryption via our OpenBao secrets vault: Genitco retains key custody for operational recovery, consistent with a managed-service model. What follows describes the architecture we would build for a client who needs full BYOK, not something already running.

Why standard AI doesn't work for regulated businesses

The data residency problem

Many AI API services process data in the US or undisclosed locations. Some providers offer EU regions and publish clear data handling policies — but even then, regulated industries may face restrictions on sending sensitive data to any third party. For healthcare organisations handling patient records, or businesses operating under sector-specific regulation, on-premise processing may be the only compliant path.

The uncontrolled processing problem

The real risk is not using AI APIs per se — it is sending sensitive data to services without clear data processing agreements, without knowing where processing occurs, or without contractual guarantees on retention and training. Reputable API providers publish data processing agreements and honour them; the problem is when businesses skip that diligence, or when their regulator requires demonstrable on-premise control regardless. BYOK self-hosted infrastructure eliminates the dependency entirely.

The audit problem

Regulators and auditors ask: "Where is our data? Who has access?" Standard AI services make these questions hard to answer. BYOK infrastructure provides clear answers.

Architecture Overview

Core components

  • EU-only compute: Infrastructure running exclusively in EU data centres (Frankfurt, Amsterdam, Dublin)
  • Customer-managed keys: You control encryption keys via AWS KMS, Azure Key Vault, or HashiCorp Vault
  • Encrypted inference: Data is decrypted only in secure enclaves, processed, then re-encrypted
  • Zero retention: No logging or training on your data

Data flow

  1. Your application sends encrypted data to EU infrastructure
  2. Data is decrypted within a secure execution environment
  3. AI model processes data and generates response
  4. Response is encrypted with your key
  5. Encrypted response returned to your application
  6. Decryption happens in your environment only

Use Cases

Healthcare — Clinical documentation

Automate clinical note generation while keeping patient data in EU-only infrastructure with customer-controlled keys. Full audit logging included (NHS DSPT and UK GDPR Article 30).

Legal — Contract analysis

Process sensitive client contracts through AI without exposing data to third-party training sets. Client confidentiality maintained.

Finance — Risk assessment

Analyse financial data and generate risk reports with full audit trails and regulatory-compliant data handling.

Hospitality — Personalised service

Use guest data for AI-powered personalisation while maintaining GDPR compliance and data sovereignty.

Implementation Options

These are the architectures we would scope and build for a client who needs full BYOK — a bespoke engagement, not an off-the-shelf product. Talk to us about which fits your requirements.

Option 1: Fully managed

We would deploy and manage BYOK AI infrastructure in your EU cloud account. You control the keys; we handle the operations.

  • AWS, Azure, or GCP deployment
  • EU regions only (Frankfurt, Amsterdam, Dublin)
  • Your KMS keys, your control
  • Infrastructure uptime backed by cloud provider SLA (AWS/Azure/GCP)
  • Audit-ready documentation included

Option 2: Self-hosted guidance

We would architect and hand over BYOK AI infrastructure for your team to operate. Full documentation and knowledge transfer included.

  • Infrastructure-as-code templates
  • Security hardening guides
  • Operational runbooks
  • Incident response playbooks

Option 3: Hybrid approach

Start managed, transition to self-hosted as your team builds capability. Phased handover with ongoing advisory.

Compliance Mapping

GDPR

  • Article 44: Data transfers — EU-only processing
  • Article 32: Security — Encryption with customer keys
  • Article 5: Principles — Purpose limitation enforced
  • Article 25: Privacy by design — Built in from start

Sector-specific

  • Financial services: FCA/PRA guidance compliance
  • Healthcare: NHS Digital standards (UK)
  • Legal: SRA Code of Conduct compliance

Technical Specifications

Infrastructure

  • Compute: Kubernetes (RKE2 / K3s) on EU bare-metal (Hetzner DE/FI)
  • GPU: NVIDIA A10G or H100 instances for inference
  • Storage: Encrypted S3/Azure Blob/GCS with customer keys
  • Network: Private subnets, no public internet egress

AI Models

  • Open-source models (Llama, Mistral, Falcon) — no API calls
  • Self-hosted embeddings models
  • Custom fine-tuning available
  • No data retention or training on your inputs

Security

  • AES-256 encryption at rest
  • TLS 1.3 in transit
  • Hardware Security Module (HSM) key storage
  • Automatic key rotation
  • Secure enclaves for inference (where available)

Costs and Timeline

Typical deployment

  • Timeline: 4-6 weeks from kickoff to production
  • Cost: Scope-dependent, priced per engagement — see below for what drives it
  • Setup: One-time implementation fee, quoted after scoping

What affects cost

  • Inference volume (tokens per month)
  • Model size (7B, 13B, 70B parameters)
  • Availability requirements (single/multi-region)
  • Additional services (monitoring, backup, DR)

FAQ

Can you use OpenAI/Anthropic APIs with BYOK?

Not with full BYOK. Third-party APIs require sending data to their servers, which removes cryptographic control. BYOK infrastructure uses self-hosted open-source models (Llama, Mistral, and others). These models provide strong performance for many business use cases — document processing, summarisation, classification, and structured extraction. For tasks requiring the most advanced reasoning or multimodal capability, the right model depends on your use case and compliance constraints.

What if we need models larger than 70B parameters?

We support 70B+ parameter models through multi-GPU configurations. For very large models (175B+), we can architect distributed inference or recommend phased approaches.

How do we handle model updates?

Models are containerised and deployed via CI/CD. Updates are tested in staging before production deployment. Blue-green deployments minimise downtime.

What happens if we lose our encryption keys?

In a full BYOK deployment, we would recommend HSM-backed keys with organisational recovery procedures. Keys can be escrowed with your legal/ security team. Without keys, data is cryptographically unrecoverable — that is the tradeoff a genuine BYOK guarantee requires.

Ready for compliant AI?

Book a free architecture call to discuss your specific compliance requirements and whether a BYOK deployment fits them.

Discuss your BYOK requirements
Global infrastructure·Your data, never ours·AI and infrastructure you control·GDPR by design