Production-Ready AI Engineering · forward deployed

Your AI is not stuck on the model. It is stuck on your data.

Data first, then AI. We make SAP, MES and PLM reachable, then build the operating layer on top. Eight weeks to production, inside your own tenant — and we operate it from there: monitoring, evals, observability and CI/CD for models.

Working inside your Azure, AWS or GCP tenantGDPR and EU AI Act by designContracted under German law
SAPMESPLMDOCSTICKETSGOVERNANCECompanybrainYOUR TENANT
  • Search
  • Agents
  • Reports
  • Inspection

Models, interchangeable behind one gateway

  • Claude
  • OpenAI
  • Gemini
  • Qwen
  • Llama
  • Mistral

Questions this market actually asks

Pexon embeds senior forward deployed engineers inside industrial companies with €50 million to €2 billion in revenue. We start at the data layer, connecting SAP, MES, PLM and decades of documents, then build AI systems that respect your permission model, run inside your own cloud tenant, and are contracted under German law.

Why now

Everyone has run the pilot. Almost nobody has shipped.

Between 2024 and 2026 most industrial companies proved that AI works. The demo answered the question. Then it stopped — at the data. Six reasons it stops, and all six sit below the model.

  • 01 · Reachability

    The data cannot be reached

    SAP, MES, PLM, thirty years of SharePoint, SQL nobody has touched in a decade. No prompt reaches into that.

    The pilot never sees real data

  • 02 · Entitlements

    Permissions cannot be expressed

    Your real permission model has to travel with the context. A system that shows everyone everything cannot go to production.

    Security blocks the go-live

  • 03 · Capacity

    The person who could is busy

    The one engineer who would push it through is committed to three other things, and not hireable in months on this market.

    The project waits on one calendar

  • 04 · Cost

    The bill arrives without a cost centre

    Consumption pricing produces an invoice finance never approved.

    Month four is four times the estimate

  • 05 · Duplication

    Every use case pays for the foundation again

    Four proofs of concept, four separate stacks, no shared governance.

    No compounding, no scale effect

  • 06 · Ownership

    It runs, and nobody owns it

    The pilot team moved on. No evals, no monitoring, no accountable name.

    Quality drifts, silently

The consensus view

The companies with the best models in the world concluded, all at once, that the models are not the constraint.

In the last twelve months every major AI organisation moved capital into embedded engineering. This is the strongest available evidence that the delivery model works.

  1. May 2026

    OpenAI

    Stood up a dedicated deployment company, backed by over $4 bn, and acquired an applied-AI consultancy of roughly 150 forward deployed engineers to staff it.

  2. 2026

    Microsoft

    Built embedded engineering into its enterprise business on the same forward deployed model.

  3. 2026

    AWS

    $1 bn behind forward deployed engineering, including a programme to build the capability inside partners.

  4. Q1 2026

    Palantir

    Revenue +85 %, US commercial +133 %. A decade of embedded engineering, finally read as the proof.

  5. 12 months

    The market

    Job postings for forward deployed engineers rose more than sevenfold, from 643 to 5,330.

All of it is aimed at the largest enterprises on earth. We are aimed somewhere else: industrial companies between €50 million and €2 billion in revenue, with the same deployment gap and nobody embedded to close it.

Sources, each re-verified before launch: OpenAI, 11 May 2026 (deployment company; Tomoro acquisition, ~150 FDEs; >$4 bn initial investment) · Microsoft, Frontier Company · AWS Partner Network, Forward Deployed Engineering · Forbes, 28 May 2026 (Palantir Q1 2026) · Indeed data via Business Insider (FDE postings, April 2025 → April 2026).

What we do

Data-to-AI, built inside your business.

The asset in the middle is yours: your entities, your rules, your process knowhow. Raw systems on the left, agents doing real work on the right, and every one of them stops at a person who decides.

01 · RAW SYSTEMSSAP / ERPorders, materials, marginsMESbatch and machine historyPLM / CADparts and revisionsDOCS / TICKETSunreachable todayMAINFRAME / SQLunreachable today02 · ENGINEERED••• PII MASKEDextract · chunkembed · index03 · YOUR ASSETYour IPPROCESS KNOWHOWEntities and relationshipsMetric and rule definitionsPermission model, row levelLineage and eval baselineSTAYS IN YOUR TENANT04 · AGENTS AT WORKQuote preparationcited, a human approvesInvoice inspectionchecked against the rate cardRoot-cause analysisMES joined to QAHUMAN DECIDESCOST PER USE CASE FALLS · VALUE COMPOUNDSUSE CASE 5 COSTS A FRACTION
  • 01 Raw systems, unreachable today
  • 02 Engineered, not prompted
  • 03 The asset that compounds
  • 04 Agents prepare, humans decide
  • 01

    We start at the data layer

    Extract, clean, mask, and carry your permission model through.

  • 02

    Neutral on models and clouds

    Frontier, open-weight or fully on-premise. No licence to defend.

  • 03

    Your knowledge stays yours

    Never leaves the tenant, never trains an outside model. Code included.

How it works

No pilot phase. One thread through to production first.

The failure pattern in enterprise AI is a wide pilot that touches everything and ships nothing. We invert it: one real data source, one real use case, all the way through to something a person uses, then widen.

Phase
W1
W2
W3
W4
W5
W6
W7
W8
W9
W10

01 · ACCESS

Get in

Access, data reality, permission model. Sprint goals in writing.

2 wks

02 · BUILD

First thread

One source end to end. PII masked, access rights carried through.

3 wks

03 · PROVE

Measure and sharpen

Evals against your own questions, judged by your specialists.

2 wks

04 · SHIP

Production

Monitoring, cost control, runbooks. Handover starts here.

1 wk

05 · ONGOING

Widen or hand over

More sources and business units, or transition into operations.

open
  • Gate: you decide whether the next phase starts
  • Handover begins in phase 04, not at the end

Each engagement makes the next one cheaper for you, not just for us.

That is the point of doing this repeatedly in one industry. The connectors, masking pipelines and eval harnesses we bring with us were paid for by earlier work, and you inherit them on day one rather than funding them again.

ENQ #4127 · PLANT 04ExampleGROUNDED ANSWERPERMISSION AWAREHUMAN IN THE LOOP
  1. Maintenance lead

    Which torque spec applies to the flange on the 2019 revision, and has it changed since?

  2. Assistant

    420 Nm, unchanged for the 2019 revision. The 2021 revision raised it to 460 Nm, so check the plate before you work.

    Assembly_Manual_R2019.pdf · p. 148
    ECR-2021-0442 · approved 14 Mar 2021

  3. Maintenance lead

    Show me the change request.

  1. Service engineer · Plant 04

    What did we quote this customer on the last three orders?

  2. Assistant

    You can see two of three. Order 8841 sits under a contract your role does not cover.

    8839 · €41,200
    8840 · €38,750
    8841 · restricted

    Entra ID group: SERVICE-P04
    Row filter applied before retrieval, not after

  1. Agent · invoice inspection

    Freight invoice 77-2291 checked against the rate card. Two lines deviate.

  2. Agent

    Line 4 overcharged €280 against the agreed tariff. Line 7 lacks a matching delivery note.

    Ratecard_2026_Q2.xlsx · row 219
    Awaiting human approval before the debit note goes out

  3. Accounts payable

    Approved. Send the debit note.

EVERY ANSWER CARRIES ITS SOURCE · YOUR TENANT

ROW FILTER APPLIED BEFORE RETRIEVAL · YOUR TENANT

AGENT PREPARED · HUMAN APPROVED · YOUR TENANT

Illustration. The order numbers, amounts and document names in these transcripts are invented for the example. They are not Pexon figures and they are not any client's figures.

In production

Agents and your people in one thread.

The assistant prepares, cites and stops. A person approves. No extra licence per head, no context retyped, and nothing leaves your tenant.

Pick a claim to see the exchange behind it

Every response cites the document and page it came from, so your specialists verify in seconds instead of trusting. When the corpus cannot support an answer, it says so rather than inventing one.

Rights come from Entra ID and are enforced before retrieval, not filtered afterwards. A user sees exactly what their role already allows, down to the row.

Routine inspection and preparation run unattended. Anything with consequence stops at a named person, with the full trail attached, ready to approve or reject.

The outcome

What you end up with: a company that can query what it already knows.

Every enterprise runs four infrastructure layers. ERP for operations. CRM for customers. Identity for access. Cloud for compute. A fifth is being built now, and unlike the other four it cannot be bought off a shelf, because it is made of your own knowledge.

  1. 01ERPOperations: orders, materials, margins, stock.
  2. 02CRMCustomers: accounts, history, commitments.
  3. 03IdentityAccess and security: who is allowed to see what.
  4. 04CloudCompute: your tenant, your regions, your cost centre.
  5. 05Your company brainThe layer every AI application in your business will need to reach. Made of your own knowledge, so it cannot be bought off a shelf.

Your engineers stop searching for the drawing. Your service desk stops re-answering the same ticket. Your quality team stops reconstructing why a decision was made in 2019. The knowledge was always there. It was just unreachable.

Y Combinator named “Company Brain” one of fifteen categories in its Summer 2026 Requests for Startups. The through-line: the missing piece is company context, not model capability — and what gets sold is the finished work, not the tool.

Data-to-AI use cases

Where this pays for itself.

Eight patterns, each starting from a system you already own. Each begins as a two-week blueprint — none begins as a twelve-month programme.

  • 1 answer

    Head of Sales · SAP

    Orders, margins and stock get one number, traceable to the row

    Governed semantic layer

  • hours

    Plant Manager · MES

    Root cause in hours instead of weeks, recurring faults visible

    Machine context joined to QA

  • no rework

    Head of Engineering · PLM

    Engineers find the existing solution instead of redesigning it

    Part and revision aware search

  • L1 + L2

    Head of Service · Tickets

    A real share of volume resolves without a human touching it

    Confidence threshold and review

  • no surprises

    Legal and Procurement

    Renewal and liability deadlines stop arriving by email

    Clause-level obligation tracking

  • −1 FTE

    Head of Quality

    Certificate checking stops being a full-time job

    Inspection against specification

  • unblocked

    CIO · Legacy

    Modernisation becomes possible because the rules are documented

    Business rules extracted, tests generated

  • condition

    Head of Maintenance

    Maintenance moves off the calendar and onto real condition

    Feature pipelines on failure history

Eight patterns, each starting from a system you already own. Each begins as a two-week blueprint, none as a twelve-month programme.

Delivered

Three numbers from production systems, not from a market study.

−90 %
Research time per technical enquiry at a transformer manufacturer, down from up to 30 minutes to seconds.
800+
Client banks the platform is built to serve under BaFin supervision and KRITIS obligations, with elastic scale-out in final validation.
+40 %
First-fix rate on internal enquiries at an engine manufacturer, with the permission model carried through to 5,000+ users.

Each figure is taken from the case study linked below, where its scope and measurement basis are stated. None of them is a market study or an industry average.

References

Six references, and the number each one moved.

Clients are described rather than named. Each card links to the case study, which states the scope of the work and how the figure was measured.

  • 800+

    Self-hosted RAG platform for a cooperative banking group

    Sector
    Financial services, banking IT, critical infrastructure
    Result
    800+ client banks in scope, around 300 active users per bank

    Read the case study

  • −90 %

    Product support assistant at a transformer manufacturer

    Sector
    Energy technology, transformers, industrial manufacturing
    Result
    −90 % research time per technical enquiry, at zero recurring licence cost

    Read the case study

  • +40 %

    Permission-aware maintenance assistant at an engine manufacturer

    Sector
    Industrial manufacturing, engines, drive systems
    Result
    −30 % response time, +40 % first-fix rate, 5,000+ users served

    Read the case study

  • 700 h

    Multi-agent standards assistant at an automotive supplier

    Sector
    Industrial manufacturing, automotive supply, precision components
    Result
    300 to 400 engineering users at production go-live, 700 additional hours reordered

    Read the case study

  • −80 %

    End-of-line visual inspection at an engine manufacturer

    Sector
    Industrial manufacturing, engines, production quality
    Result
    Up to −80 % downstream cost of defects, reaction time at the line toward zero

    Read the case study

  • 3 tracks

    Model versioning and FinOps at a regulated asset manager

    Sector
    Banking, asset management, fund services
    Result
    Three parallel model tracks on a twice-yearly upgrade cadence, nodes right-sized per workload

    Read the case study

Sovereignty as a spectrum

Sovereignty is not a yes-or-no question. Place yourself on it.

PragmaticMaximally sovereign

  1. EU cloud

    Level 1

    What
    Azure AI Foundry or AWS Bedrock in an EU region, your identities, your keys
    For whom
    The fastest route to production for most companies
    Trigger
    Time to value, existing contracts with Microsoft or AWS
  2. Dedicated EU capacity

    Level 2

    What
    Reserved compute, private endpoints, no shared inferencing
    For whom
    Cloud is permitted, shared resources are not
    Trigger
    Tenant-isolation requirement, predictable latency and cost
  3. Your own data centre

    Level 3

    What
    Your GPUs, your hardware, open-weight models
    For whom
    When data cannot leave the building, or volume tips the cloud economics
    Trigger
    Works council, group policy, data classification
  4. Air-gapped

    Level 4

    What
    No network crossing, fully isolated operation
    For whom
    Critical infrastructure, defence, highest protection classes
    Trigger
    Regulatory obligation

You do not have to decide today. The platform is built so models and location of operation are interchangeable: one gateway in front, one governance model behind. What runs in the EU cloud today runs on your own GPUs tomorrow, without rebuilding the applications.

Two buyers, one project

Security and the business unit want different things. Both get them.

IT, CISO and security

  • A platform that passes your own committees
  • Identities through Entra ID, permissions down to document level
  • Logging, cost control, model governance
  • Built to be compatible with MaRisk, DORA, NIS2 and ISO 27001

Business unit, plant and operations

  • One use case running in production in 6 to 8 weeks
  • Answers with source citation, not guessed
  • Manual work replaced, not simulated
  • No waiting for a group-wide programme

AI agencies deliver only the application. System integrators deliver only the infrastructure. We deliver both, because one without the other does not reach production.

The path

You are not buying the platform. You are buying the first step.

  1. Level 0Scattered AI toolsYour state today
  2. Level 1The AI platformGateway, governance, cost control
  3. Level 2The assistant that knows your documents6 to 8 weeks, fixed price
  4. Level 3Connected to your systemsSAP, ERP, PLM, file shares
  5. Level 4Workflows that actAI prepares, a human decides
  6. Level 5OperationsIn production, monitored, handover-ready

The platform at level 1 is what makes levels 2 to 5 cheap.

Levels 2 and 3 in detail

We start with one use case, not with a programme.

Level 2

An assistant on your manuals, standards and project files

Inside your network, in production in 6 to 8 weeks, at a fixed price. Every answer carries a source citation back to the original document, so your specialists can verify instead of trusting.

Typical first projects: knowledge assistant on technical documentation, bid and tender analysis, standards and regulation research.

answer with source citation

Level 3

The assistant reads your real data

SAP, ERP, PLM, file shares, ticket systems. Order status, bills of material and price levels where they originate rather than in a copy. From here AI replaces manual work instead of simulating it.

Typical extensions: document inspection against specification, freight invoice checking, order intake capture, service reports.

extraction with flagged fields

The second use case is cheaper than the first. The fifth costs a fraction.

The architecture

Seven layers, one governance model across all of them.

Pro-code, not prompt writing. This is the reference architecture your installation is derived from, and the choice per layer follows your data classification rather than our preference.

  1. 01

    Applications

    Chat surface, business apps, Office integration

    • OpenWebUI
    • own frontends
    • Teams
  2. 02

    Agents and workflows

    Orchestration of tasks and processes

    • LangGraph
    • Agents SDK
    • n8n
    • Logic Apps
  3. 03

    Tool connectivity

    Standardised access to your systems over MCP

    • MCP servers
    • SAP
    • ERP
    • web search
  4. 04

    Model gateway

    One entry point: cost, limits, filters, logging

    • LiteLLM
  5. 05

    Model providers

    Interchangeable behind the gateway, per sovereignty level

    • Azure AI Foundry
    • AWS Bedrock
    • on-prem via vLLM
  6. 06

    Knowledge and data layer

    Vector search plus our own ETL for indexing and embedding

    • Azure AI Search
    • Qdrant
    • pgvector
    • own ETL
  7. 07

    Infrastructure

    EU cloud, your data centre, air-gapped

    • Azure
    • AWS
    • Kubernetes
    • own GPUs

Governance, identity, logging

  • Entra ID and single sign-on
  • Permissions down to document level, enforced before the query
  • Guardrails and PII detection
  • Complete, immutable logging
  • Quality and hallucination measurement
  • Budget and alerting per team

Model versions are deliberately not named here. The choice is made at project time by request class and data classification, with evaluation on your own data rather than a public benchmark.

The gateway layer

One entry point in front of every model you will ever use.

Model choice stops being a procurement decision and becomes a routing rule. Swap a provider without touching a single application.

  • One interface for any model

    Every provider behind a single contract and a single call. Your applications never learn a vendor name.

    Frontier, open-weight, on-prem

  • Higher availability

    When one provider degrades, the gateway routes to the next without an incident ticket.

    No single point of failure

  • Price and performance

    Cheap models for cheap questions, the expensive one only where it earns its cost. Measured, not guessed.

    Caching, batching, right-sizing

  • Custom data policies

    Fine-grained rules per data class. A prompt carrying personal data never reaches a provider you have not cleared.

    Enforced at the gateway, logged

Integrations

Fits inside your existing stack.

We connect to the systems your people already work in. No ripping, no replacing, and no parallel user directory. SAP and ERP read where the data lives, Entra ID carries the rights, and thirty years of SharePoint gets indexed with its permissions intact.

Talk to us about your stack

PEXON PLATFORMYour gatewaySAPERP · S/4HANAEntra IDSSO · RIGHTSTeamsWHERE THEY WORKSharePointDOCUMENTSServiceNowTICKETSConfluenceKNOWLEDGE

Security and compliance

How we build, and what we build it to pass.

How we build

  • Identities and permissions through Entra ID, no parallel user directory
  • Permissions down to document and tenant level, enforced before the query rather than filtered after it
  • Guardrails against data exfiltration and prompt manipulation, PII detection in the stream
  • Full traceability: which model, which source, which cost, which user
  • Quality measured in operation rather than assumed
  • Infrastructure as code, reproducible, auditable, versioned

What we build it to pass

  • ISO 27001 controls as the baseline we build to — not a certificate this company holds
  • GDPR and data processing agreements
  • BaFin, MaRisk and DORA for financial services
  • NIS2 for critical infrastructure and utilities
  • EU AI Act, with your use cases classified by risk class
  • Your own group policy as the hardest instance

Credentials

What Pexon Group holds, and what this company builds to.

Held by Pexon Consulting GmbH

  • Microsoft Solutions Partner — Digital and App Innovation, Azure
  • Microsoft Solutions Partner — Infrastructure, Azure
  • Microsoft Solutions Partner — Data and AI, Azure
  • ISO/IEC 27001:2024 certified, audited by visocert
  • Google Cloud Partner
  • AWS Partner

Pexon Group, across all five companies

400+
Cloud and AI projects delivered
100+
Clients in the DACH region

The certification and the partner registrations above are held by Pexon Consulting GmbH, and both figures describe Pexon Group as a whole. This site is published by PEXON ROMANIA S.R.L., the group's AI engineering hub in Cluj-Napoca, registered in 2026: a separate legal entity, the party you contract with here, and the holder of none of them — which is what the list above means by “not a certificate this company holds”.

Why Pexon

Four things that decide it.

Segment

You are the client, not an exception

The large deployment teams are built for global enterprises, and their published references show it. We are built for companies between €50 million and €2 billion in revenue — the segment with the same problem and none of the attention.

Neutrality

We have no stack to defend

We are not selling licences underneath the engineering. Model and cloud decisions get made on your requirements and your data classification, including the answer that nothing leaves your building.

Accountability

The contract is German law

One named senior architect, German-speaking, personally accountable for delivery. Contracts, SLAs and the data processing agreement under German law, with PEXON ROMANIA S.R.L. as the contracting party.

Entry

You can start for €4,900

A two-week blueprint, not a programme approval. If it does not convince you, you have lost two weeks and a rounding error.

On determinism, the question most offerings avoid: almost every company-brain product optimises for retrieval over unstructured text. When an agent and the CFO calculate “revenue” differently, wrong answers arrive silently in board material. For regulated and industrial clients, traceability beats answer coverage — metrics come from defined sources with defined definitions, not from free-text similarity search.

How to start

Three entry points. No upfront investment in a platform.

Readiness Blueprint

For whom
You want clarity on the current state and the cost first
Content
Data landscape audit, permission model assessment, risk exposure, and a costed architecture plan. Yours to keep, whoever builds it.

2 weeks

€4,900 fixed price

Most chosen

Use-case pilot

For whom
You have a specific use case
Content
One use case in production, including the permission concept and the operating basis.

6 to 8 weeks

from €15,000 fixed price

Platform foundation

For whom
You have several AI initiatives and want to consolidate them
Content
Gateway, governance, data connectivity and cost control as a shared foundation for everything that follows.

8 to 12 weeks

Price in conversation

No upfront investment in a platform. The foundation is built underneath the first use case, not before it.

Forward deployed engineering, priced per engineer.

Once the first use case is live, capacity is the only variable. Start with monitoring and add engineers when the backlog justifies them.

  1. Monitoring

    from €3,000

    per month · no FTE

  2. 1 FTE

    €7,500

    per month · one engineer

  3. 2 FTE

    €14,500

    per month · pod of two

  4. 3 FTE

    €21,000

    per month · full pod

What you getMonitoring1 FTE2 FTE3 FTE
Availability, cost and eval monitoringyesyesyesyes
Pipeline fixes per monthup to 3unlimitedunlimitedunlimited
New sources connected per quarter12 to 34+
Named forward deployed leadshared20 %40 %dedicated
On-site days per month124
Parallel workstreams123
Monthly, month to month after the first cyclefrom €3,000€7,500€14,500€21,000

Month to month after the first cycle, and a tier change takes effect the following month. Consumption is never marked up.

Cloud consumption, model tokens and any specialised hardware are billed directly to your own accounts so you see them. No licence, no per-seat fee, no success fee, and no margin on your consumption. All prices are net and exclude VAT.

Operations

We run it, you run it, or mixed.

The operating model is switchable rather than built into the contract. You can decide again every year without touching the platform.

We run it

Full managed service with an SLA. Your IT does not carry another system.

Accountability with Pexon

You run it, we stand by

Handover, training and on-call. Your team leads, we are reachable when something breaks.

Accountability shared

You run it alone

Full documentation, operations handbook, runbooks. No residual contract, no tie back to us.

Accountability with you

Included in the managed service

  • Availability and quality monitoring
  • Model and version maintenance
  • Cost reporting per business unit
  • Security updates
  • Development of new use cases
  • Defined response times

Inside the engagement

Eight weeks, four stages, one result in production.

  1. Weeks 1 to 2

    Set up

    Access, target picture, permission concept, alignment with information security.

  2. Weeks 3 to 5

    Build

    Open up the sources, preparation, retrieval, first usable version.

  3. Weeks 6 to 7

    Measure and sharpen

    Specialist evaluation with your test users, quality tuned against their verdict.

  4. Week 8

    Handover

    Production release, documentation, cost model, decision paper for your committees.

Who comes from us

  • Platform architect. Owns architecture, security and the alignment with your IT.
  • AI engineer. Builds retrieval, prompts, evaluation and the application.
  • Data engineer. Opens up the source systems, builds preparation and indexes.

What we need from you

  • One business contact with decision authority. Not a steering committee that meets fortnightly.
  • Access to the source systems of the first use case. Read access is enough to start.
  • A session with information security in week 1. Before we build, not after.
  • Two or three test users from the business unit. They judge the evals; nobody else can.
  • Feedback within 48 hours. That is the only hard dependency in the plan.

The team

You get the people who build it.

Not the proposal of a partner you never meet. The people in the first call are the people on the project, and they are still there in month nine.

Noel Dinger, Managing Director
Noel Dinger
Managing Director
David Manita, Lead AI Architect
David Manita
Lead AI Architect
Constantin Budin, AI Architect
Constantin Budin
AI Architect
Phillip Pham, Data Architect
Phillip Pham
Data Architect

Procurement and legal

The questions that decide it.

Do the engineers work on site with us?

The forward deployed lead works on site or hybrid by agreement. For regulated programmes we offer a dedicated engineer four days a week. The delivery team works in your time zone and inside your tools, whether that is Jira, GitHub or GitLab.

What does it cost to start, and what comes after?

A two-week readiness blueprint is €4,900 at a fixed price. One use case in production is a fixed price from €15,000 over six to eight weeks. After that, operations are priced per engineer: from €3,000 a month for monitoring alone, €7,500 for one engineer, €14,500 for two and €21,000 for three. All prices are net and exclude VAT.

We already have Microsoft and Copilot.

Keep it where it is enough. Copilot is a licence per head for standard cases. What we do is the work that has to run on your own data, inside your own governance, with a consumption cost you control. Azure AI Foundry is a construction kit rather than a finished platform, and we build on it rather than against it.

Who owns the code, pipelines and prompts?

You do. Code, data pipelines, prompts and documentation are yours, and usage rights to sprint output transfer on payment of the first invoice. Generic building blocks we bring with us — connectors, masking pipelines, eval harnesses — remain ours and are licensed to you perpetually for this deployment.

Where does our data sit and who has access?

Everything runs inside your Azure, AWS or GCP tenant, using your identities, in your regions, on your cost centre. Our engineers work with named accounts under your identity provider, scoped to the sources in the current sprint. Access is logged and revocable by you at any time.

What if we want to run it ourselves afterwards?

That is the goal, and it is stated in the engagement plan. Handover begins in month two: runbook, architectural decision records, and shadowing until your team ships changes without us. There is no residual contract and no tie back to us.

What costs come on top?

Cloud consumption, model tokens and any specialised hardware, billed directly to your own accounts so you see them. Travel for on-site days is agreed in advance. No licence, no per-seat fee, no success fee, and no margin on your consumption.

Can we change or end it monthly?

Yes. Operating agreements run month to month after the first cycle, and a change of tier or operating model takes effect from the following month. That is possible because the runbook and the operations handbook are always current and always with you.

Who is the contracting party, and under which law?

The contracting party is PEXON ROMANIA S.R.L., registered in Cluj-Napoca. Contracts, service levels and the data processing agreement are governed by German law, which is what procurement in this market is set up to review. Those are two separate facts: the counterparty is Romanian, the law is German.

Why a mid-sized firm rather than a large one?

Because you get the people who build it, not the proposal of a partner you never meet. And because the dependency risk is contractually excluded: full code and infrastructure transfer, a documented exit clause, operable without us at any time. For a nine-figure group programme that needs board-level air cover, we are the wrong partner, and we will say so in the first call.

Blog and resources

What we learned building this, written down.

Engineering notes and case studies from the work above. Published in English.

More engineering notes and the full case-study index:Browse the blog

Browse by topicClaudeData foundationPrivate AI

Data first.
Then AI.

Built inside your tenant, documented, operated. With a bill your CFO can defend and an audit trail your CISO signs.

How to start

Not a sales call. An architecture call.

Thirty minutes with the architect who would actually run the engagement. You leave knowing whether this fits and what the first source should be. If your pilot is still a pilot, the problem is probably reachable.

Noel Dinger, Administrator and Managing Director

Noel Dinger

Administrator and Managing Director
PEXON ROMANIA S.R.L.

Calea Dorobanților 14–16, Etaj 2, Ap. 62
400117 Cluj-Napoca
Județul Cluj, Romania

Phone
+49 151 61417242
Email
info@pexon.com
Web
pexon.com
Trade register
J2026044460002
CUI
55218135
VAT
RO55218135

How the call runs

  1. Thirty minutes, with your IT and the business unit together
  2. We review the current state and name the first source
  3. You get your sovereignty level classified, in writing
  4. If it does not fit, we say so in the call, not in a proposal