Every AI. Inside your walls.
Subsidia is a sovereign AI engine, installed on your premises, for professions where client files cannot be shared — accountants, lawyers, notaries. Running locally, nothing leaves. And when an external call is chosen, it leaves masked.
What if the AI is wrong?
Your liability is on the line for everything you sign. So every claim cites the document and the page — verification is instant. And when the answer isn't in your files: "not in your knowledge base".
Where does my client's file go?
Nowhere. Every execution leaves a signed, chained certificate, verifiable offline — your auditor can check it without trusting us.
Your team is already using AI. You just can't see it.
The ban
The firm bans AI. It loses productivity to competitors who use it — and the leak continues anyway, quietly.
Shadow AI
Excerpts of client files already leave through public chatbots, on personal browsers. Nobody knows, nothing is traced.
The stalled project
The firm starts an AI project, someone asks where the data goes, and the project dies in committee. Six months lost.
We don't sell an app. We sell the engine.
An application gets copied in three months. The engine that routes, protects, proves and grounds itself in your documents — the one your existing tools plug into — is much harder to displace. Built for accountants first; lawyers and notaries next.
One engine, three bricks, one proof.
Synapse is the mandatory gate for every AI call: it picks the model that answers, masks what must not leave, and counts what it costs.
- RoutingBy complexity
The cheapest model actually capable of handling the request: a small local model to rephrase, a large one for a legal synthesis.
- ShieldPII / PHI Shield
Names, emails, numbers replaced with stable pseudonyms before anything leaves, restored in the answer. A local model sees the original: nothing leaves the network.
- MeterEvery call counted
Provider, model, tokens, cost, PII detected: everything is logged, line by line. "What left the building?" always has an answer.
A generic model doesn't know your files. Cortex ingests them, retrieves them, cites them — and flags when they contradict each other.
- IngestionEvery format
PDF, Word, Excel, emails — and scans, read by local OCR. Drop a file in a watched folder: it gets indexed.
- ChunkingAlong the real structure
Headings, sections, tables: every chunk knows which document and section it came from. That's what makes "2025 filing, p. 12" citable.
- SearchHybrid, reranked
Semantic and keyword search fused, then reranked. A relevance floor forbids citing an off-topic passage.
Reflex, the third brick: not a tool you have to open, but an engine that works overnight and presents the result in the morning.
- Monday, 7 amThe attention note
Review the files modified during the week and produce an attention note, ready with the coffee.
- A file arrivesIndexed, checked
Dropped in a watched folder: indexed, facts extracted, alert if it contradicts what's already known.
- A client emailDraft ready
A draft reply grounded in the file, ready to review.
The Gateway speaks OpenAI's protocol — and Anthropic's.
Everything you already use keeps working — now metered, masked and proven.
The model is an address
"pulse-auto", "pulse-sensitive", "agent:name+cortex": the engine's capabilities are chosen through the address — never imposed.
Signed, chained
Every response carries an ed25519 certificate chained to the previous one, verifiable offline. Your auditor doesn't have to trust us.
What you actually saw
The proof covers what was really displayed on screen, not a version reconstructed after the fact.
The offer, priced.
the assessment — 30 minutes, on site or by video call, no commitment.
installation and training, once.
the licence, support included, no commitment beyond the year.
You stop whenever you want: your documents are already on your premises, there's nothing to migrate. And if one machine isn't enough, we plug in a second one — nothing to reinstall.
P.S. — the Subsidia Box, a preconfigured machine to plug in inside your walls, is under construction. No promised date: it ships when it works.

My name is Dorian.
I build Subsidia alone, from Nîmes, incubated at the CCI du Gard. I ship every week and I answer support myself: if you write to me, I'm the one reading.
I'd rather lose a sale than promise something the product doesn't do yet — it's less spectacular, but it can be verified.
The questions we get first.
Why not just ChatGPT Enterprise?
Because your data goes to a third party, you pick neither the model nor the cost, and nothing proves after the fact what was sent. Subsidia routes, masks, sources and signs every call — and can run with no internet at all.
Can I start without installing anything?
Yes. You create an account, you get 60,000 tokens and a working workspace. Installing it on your own hardware only becomes useful the day you want nothing to leave the building.
If I move on-premise, do I rewrite everything?
No. Same API, same model addresses, same SDKs, same keys. You change the base URL and your integrations keep running.
What if the AI gets it wrong?
Every grounded answer cites the document and the page. Cortex flags when your own documents contradict each other, and says “not in your knowledge base” instead of inventing.
Who is behind this?
Protypa, a software company in Nîmes, France. The same person builds the engine and answers your messages — backed by the CCI du Gard incubator.
Start with an assessment.
Thirty minutes, on site or by video call, no commitment. We look at three things: what your team already uses, what's risky, and what an AI installed on your premises would change.
or simply: dorian@protypa.fr — reply within 24 business hours, by a human
