AI helps most with the work you cannot safely send it.

AI would help most on exactly the material you can't paste into a public tool — pastoral notes, case files, safeguarding records, the names of workers in sensitive places.

We run our own on-premises AI server so you don't have to.

We built our own AI server on-premises so sensitive chats, case data and meeting summaries can be processed within our controlled environment, reducing the need to send sensitive information to external AI services and lowering certain data-exposure risks that could put vulnerable or sensitive communities at risk.

Three ways to have private AI.

These are a path, not a lock-in. Many customers start on the subscription and move on-premise as their governance tightens — and we price that transition transparently.

1. Subscribe

You use our private AI server, hosted on our own premises.

Where the server sits
Our premises
Who operates it
We do
Where content is processed
Our controlled environment. Not sent to external AI services. Metadata only — no content logs.
Best when
You want AI for sensitive work now, without hardware, capital or in-house expertise.
What we deliver
Access, allowances, admin controls, onboarding and training.
Commitment
Monthly subscription, from S$79/month.

2. Learn to run your own

We train your team to deploy and operate an AI server on your premises.

Where the server sits
Your premises
Who operates it
Your team, after we hand over
Where content is processed
Within your building
Best when
You want the capability in-house permanently and have someone technical to own it.
What we deliver
Model selection, hardware planning, secure configuration, data-flow mapping, access control, RAG setup, update and incident procedures — we build the first environment with you, document it, and hand over operations.
Commitment
Fixed-scope training engagement, from S$3,500.

3. We build and run it for you

We design, install, configure and manage a dedicated AI server on your premises.

Where the server sits
Your premises
Who operates it
We do, under your control
Where content is processed
Within your building
Best when
Your governance requires the server on-site, but you don't want to run it yourself.
What we deliver
Architecture design, hardware specification and procurement, installation, access-control configuration, workflow integration, documented retention and backup, staff training, ongoing maintenance and security support.
Commitment
Project fee from S$25,000, quoted to scope, plus S$800–1,500/month maintenance.

What you can do with it today.

Secure meeting minutes

Authorised recording → draft minutes, decisions, action items.

Case-note summarisation

Summarise case notes and draft handover documents when staff change.

Draft communications

Draft from approved internal material — newsletters, updates, reports.

Policy and handbook search

Search your own policies, handbooks and internal documents in natural language.

Translation

Translate resources between languages without exposing content externally.

Spreadsheet reconciliation

Reconcile and merge spreadsheets, generate timetabling drafts and reports.

Every AI output is a draft for human review, never an authoritative record.

What's actually running.

Qwen3.6-27B

Full BF16 precision with a 262,144-token context window. Long context means it can read a whole spreadsheet or export at once, not just a chat message.

DeepSeek V4 Flash

For faster workloads where speed matters more than maximum reasoning depth.

Five questions to ask any AI vendor.

These convert a privacy conviction into something checkable. Ask any provider; here are our answers.

QuestionOur answer
Where was it processed?On our own on-premises server, within our controlled environment.
Was anything retained, and for how long?Content is processed and discarded. Usage metadata (timestamps, token counts) is retained for billing. No content logs.
Was it used for training?No. Your content is never used to train any model.
Is anything stored for retrieval?Only if you configure RAG (retrieval) with your own documents — and that data stays within your environment.
Could it end up in a future model version?No. We do not train models on customer data.

Subscription tiers.

Every tier carries defined allowances — transcription hours, model class, monthly credits, concurrent users, storage, support level. We don't offer unlimited anything, and the reason is honest: it protects capacity for everyone sharing the infrastructure.

Essentials

Up to 5 users

S$79/mo

Team

Up to 20 users

S$179/mo

Ministry Partner

Up to 50 users

S$399/mo

Enterprise / Denominational

50+ users

from S$799/mo

AI here never replaces pastoral judgement, safeguarding decisions, counselling or spiritual discernment. It removes the coordination around that work, never the judgement at its centre.

This is documented, not speculative.

Our privacy argument rests on citable public reporting, not assertion. Presented soberly — this is evidence, not fear-mongering.

1. Retention windows are a real exposure, even with good providers.

Mainstream providers publish no-default-training commitments for business and API data, and eligible customers can request zero-data-retention controls. But standard abuse-monitoring processes may still retain inputs for up to 30 days unless those controls are approved. If a breach occurs during that window, or if someone with access during that window acts maliciously, the content is still exposed.

2. Provider bugs have exposed user data.

OpenAI disclosed a March 2023 software bug in which some ChatGPT users could see other users' conversation titles, and in a limited nine-hour window some Plus subscribers' names, email addresses, billing addresses and partial payment card information could have been exposed.

Source: OpenAI incident write-up

3. Regulators treat chatbot inputs as a breach risk.

The Dutch Data Protection Authority has warned that entering personal data into AI chatbots can itself constitute or cause a personal data breach, citing notified cases including an employee of a medical practice entering patient medical data and a telecoms employee entering a customer address file.

Source: Dutch DPA advisory

4. The AI supply chain itself is a target.

In March 2026 a supply-chain compromise of LiteLLM — a widely used open-source AI gateway — resulted in a reconstructed exposure dataset covering more than 2,500 organisations and roughly 434,000 CI/CD pipelines, including cloud credentials, SSH keys and AI provider API keys. The malicious packages were live for around 40 minutes. Singapore-linked entities assessed to appear in the reconstructed dataset — as potential exposure requiring investigation, not confirmed compromise — include DBS Bank, Partior, SPH Media, PropertyGuru Group and ZALORA.

Sources: The Hacker News · SecurityWeek · Protos Labs (Singapore assessment)

5. Model memorisation is demonstrated, not hypothetical.

Peer-reviewed research has shown that language models can memorise and reproduce training data verbatim, including personally identifying information. Carlini and colleagues demonstrated extraction of verbatim training examples from language models; later work demonstrated substantially larger-scale extraction against several model families including a production version of ChatGPT, showing that alignment alone does not eliminate memorisation. It would be wrong to describe model-mediated leakage of personal information as merely hypothetical.

None of this means AI is unusable. It means the question "where was this processed, and who could see it" has to have an answer. That is what we exist to give you.

Try Trellistry for three months. If it isn't working for you, we'll fix it free — or give you a full refund and a clean export of your data. No lock-in.

Ready to use AI on the work that matters most?

Book a free 30-minute consultation. We'll help you understand which delivery model fits your governance needs.

Book a free 30-minute consultation

Or call +65 9696 2902