AI would help most on exactly the material you can't paste into a public tool — pastoral notes, case files, safeguarding records, the names of workers in sensitive places.
We run our own on-premises AI server so you don't have to.
We built our own AI server on-premises so sensitive chats, case data and meeting summaries can be processed within our controlled environment, reducing the need to send sensitive information to external AI services and lowering certain data-exposure risks that could put vulnerable or sensitive communities at risk.
These are a path, not a lock-in. Many customers start on the subscription and move on-premise as their governance tightens — and we price that transition transparently.
You use our private AI server, hosted on our own premises.
We train your team to deploy and operate an AI server on your premises.
We design, install, configure and manage a dedicated AI server on your premises.
Authorised recording → draft minutes, decisions, action items.
Summarise case notes and draft handover documents when staff change.
Draft from approved internal material — newsletters, updates, reports.
Search your own policies, handbooks and internal documents in natural language.
Translate resources between languages without exposing content externally.
Reconcile and merge spreadsheets, generate timetabling drafts and reports.
Every AI output is a draft for human review, never an authoritative record.
Full BF16 precision with a 262,144-token context window. Long context means it can read a whole spreadsheet or export at once, not just a chat message.
For faster workloads where speed matters more than maximum reasoning depth.
These convert a privacy conviction into something checkable. Ask any provider; here are our answers.
| Question | Our answer |
|---|---|
| Where was it processed? | On our own on-premises server, within our controlled environment. |
| Was anything retained, and for how long? | Content is processed and discarded. Usage metadata (timestamps, token counts) is retained for billing. No content logs. |
| Was it used for training? | No. Your content is never used to train any model. |
| Is anything stored for retrieval? | Only if you configure RAG (retrieval) with your own documents — and that data stays within your environment. |
| Could it end up in a future model version? | No. We do not train models on customer data. |
Every tier carries defined allowances — transcription hours, model class, monthly credits, concurrent users, storage, support level. We don't offer unlimited anything, and the reason is honest: it protects capacity for everyone sharing the infrastructure.
Up to 5 users
S$79/mo
Up to 20 users
S$179/mo
Up to 50 users
S$399/mo
50+ users
from S$799/mo
AI here never replaces pastoral judgement, safeguarding decisions, counselling or spiritual discernment. It removes the coordination around that work, never the judgement at its centre.
Our privacy argument rests on citable public reporting, not assertion. Presented soberly — this is evidence, not fear-mongering.
Mainstream providers publish no-default-training commitments for business and API data, and eligible customers can request zero-data-retention controls. But standard abuse-monitoring processes may still retain inputs for up to 30 days unless those controls are approved. If a breach occurs during that window, or if someone with access during that window acts maliciously, the content is still exposed.
OpenAI disclosed a March 2023 software bug in which some ChatGPT users could see other users' conversation titles, and in a limited nine-hour window some Plus subscribers' names, email addresses, billing addresses and partial payment card information could have been exposed.
Source: OpenAI incident write-up
The Dutch Data Protection Authority has warned that entering personal data into AI chatbots can itself constitute or cause a personal data breach, citing notified cases including an employee of a medical practice entering patient medical data and a telecoms employee entering a customer address file.
Source: Dutch DPA advisory
In March 2026 a supply-chain compromise of LiteLLM — a widely used open-source AI gateway — resulted in a reconstructed exposure dataset covering more than 2,500 organisations and roughly 434,000 CI/CD pipelines, including cloud credentials, SSH keys and AI provider API keys. The malicious packages were live for around 40 minutes. Singapore-linked entities assessed to appear in the reconstructed dataset — as potential exposure requiring investigation, not confirmed compromise — include DBS Bank, Partior, SPH Media, PropertyGuru Group and ZALORA.
Sources: The Hacker News · SecurityWeek · Protos Labs (Singapore assessment)
Peer-reviewed research has shown that language models can memorise and reproduce training data verbatim, including personally identifying information. Carlini and colleagues demonstrated extraction of verbatim training examples from language models; later work demonstrated substantially larger-scale extraction against several model families including a production version of ChatGPT, showing that alignment alone does not eliminate memorisation. It would be wrong to describe model-mediated leakage of personal information as merely hypothetical.
None of this means AI is unusable. It means the question "where was this processed, and who could see it" has to have an answer. That is what we exist to give you.
Try Trellistry for three months. If it isn't working for you, we'll fix it free — or give you a full refund and a clean export of your data. No lock-in.
Book a free 30-minute consultation. We'll help you understand which delivery model fits your governance needs.
Book a free 30-minute consultationOr call +65 9696 2902