Kubrius Kubrius Core · Beta
Founding partner programme

Own your intelligence.

Kubrius Core is a private AI appliance that sits in your office. Routine work routes out to a public model. Confidential work never leaves the building. And every interaction, public or private, is retained as your own searchable memory, so the system gets sharper the more your firm uses it.

Apply to be a founding partner Two firms in this first cohort. Ready to install within a week of you saying yes.
The Kubrius Core appliance sitting on a desk next to a laptop, and the same unit held in one hand.
The unit we are running Core on today. Core is a desk appliance, not a rack, not a data centre and not a second copy of your work on somebody else's infrastructure. This is a beta build we install and run alongside you.
Public route

Everyday work goes out

Drafting, summarising public material, tidying notes. Sent to an approved public model API under zero-retention terms, with EU-only processing available. Only ever work your policy has cleared as non-confidential.

Private route

Confidential work stays in

Client contracts, matter files, financials, candidate data. Processed on the appliance in your own network. No external call.

Both routes

Everything stays yours

Each interaction is retained in your own knowledge base and becomes available to the next person who needs it. The firm compounds, not the vendor.

The part nobody talks about

Your AI should get smarter on your work, not theirs.

Every time someone in your firm interrogates a contract, interprets a set of accounts or works through a tricky client problem with AI, they produce something valuable: a piece of your firm's reasoning. On a public platform, that lands on someone else's servers and improves someone else's product.

Core keeps it. Interactions are retained in your own knowledge base, indexed and attributable, so the next person asking a related question starts from what the firm already worked out rather than from a blank prompt. The longer you run it, the more it knows about how your firm actually works.

And it compounds where it should, while staying walled where it must. Knowledge bases are access-controlled and can be separated per client or per matter, so firm-wide know-how accumulates without client work bleeding across a boundary it was never allowed to cross.

YOUR PREMISES A request from your team Policy check classify and route Kubrius Core local model, on site Your knowledge bases Client A Client B Firm-wide Public model API outside your network non-confidential only confidential result retained informs the next question
One hop leaves your network, and only for work the policy has cleared. Everything else runs on site, and the result of both routes lands in knowledge bases you own, walled per client and deletable in full.

Public platform

Your people get faster. The accumulated understanding of how your firm reasons sits with the vendor, and leaves when the contract does.

Kubrius Core

Your people get faster, and the accumulated understanding stays on your side of the wall. It's an asset on your balance sheet, not theirs.

Separation and deletion

Walled by client. Deletable on demand.

The reason most "your AI learns from you" pitches fail in professional services is that they can't survive a conflicts check or an erasure request. This one is built the other way round.

Access-controlled knowledge bases

Material is held in separate, permissioned stores that can be split per client or per matter, so retrieval never crosses a boundary it shouldn't.

Information barriers hold

Work on one client's matter doesn't surface in answers on another's. The wall your conflicts policy requires is enforced in the system, not in a user's memory.

Delete a client, delete their data

Remove a client's knowledge base and their material goes with it, completely and provably. No residue baked into model weights that nobody can extract.

Which makes erasure answerable

When a client or candidate exercises their right to erasure, you have a real answer rather than "we'd have to delete the chat history" or "we'd have to retrain the model."

Where this actually is

Core is in beta. Here's the honest state of it.

The platform runs today: policy routing, public and local models, private retrieval, evidence logging and agentic workflows are all built and working together on a live appliance. What it hasn't done yet is run inside somebody else's building. That's what the founding programme is for, and we'd rather say so on the front page than in the third meeting.

Policy routing Deciding per request whether work goes to the public model or stays on the appliance.
Working
Local model execution Open-weights models running on the appliance itself, with no external API call.
Working
Private retrieval over your documents Answers drawn from your own material, with citations. Benchmarked, methodology published.
Working
Evidence and audit logging A record of what ran, on what, under which rule, and where it was processed.
Working
Agentic workflows Multi-step tasks across your own document stores.
Working
Retained knowledge base Interactions kept and reusable, so the system compounds on your firm's own work.
Working
Access-controlled, separable knowledge bases Permissioned stores, separable per client or matter, and deletable in full.
Working
Deployment in a client environment Installed and running inside a firm's own network, on their data.
Ready in a week
Hardened release, support desk, reference customers The things a mature product has. This is beta, and beta means rough edges.
Not yet
The appliance

It's a box on a desk, not a server room.

Core runs on an ASUS Ascent GX10, built on NVIDIA's GB10 Grace Blackwell superchip. No rack, no data centre, no cooling project, no procurement cycle for space you don't have. It plugs into your network and draws about as much power as a desktop PC.

Because everyday work routes out to the public model, the appliance only carries the confidential traffic — a fraction of the total. That's why it isn't the bottleneck people expect, and why you add capacity by stacking a second unit rather than replacing the first. We size it against your actual usage before anything is installed.

And so you can check our arithmetic: that appliance retails at around £4,800 including VAT. We'd rather you knew what the hardware costs than wondered what the margin was.

ApplianceASUS Ascent GX10
SuperchipNVIDIA GB10 Grace Blackwell
Unified memory128 GB LPDDR5X
AI performance1,000 TOPS
ScalingStack a second unit
LocationInside your own LAN
Second unit added when capacity needs it Kubrius Core private model, on your network ON A DESK, NOT IN A RACK
Capacity is added by stacking a second unit rather than replacing the first. Both sit on a desk or a shelf: no rack, no cooling project, and no room to find.
The arrangement

What founding partners get, and what we need back.

You get

  • Ready to install in your environment within a week of you saying yes
  • Appliance supplied, installed and maintained, with no capital outlay
  • £595 a month, all in, held for as long as you stay with it. Appliance, install, configuration and support included.
  • Your workflows built first, and real influence over version one

We need

  • One real workload, not a sandbox nobody touches
  • About forty-five minutes a fortnight of genuinely honest feedback
  • A named person inside the firm who owns it
  • Tolerance for beta, and permission to talk about it if it works

£595 a month on a twelve-month term, paid from day one, which is what makes the founding rate possible. The appliance alone retails near £4,800, so this is not a trial balloon on either side. The rate you start on is the rate you keep for as long as you stay with it, including after the beta ends and standard pricing goes up. At the end of the term you either carry on or we part company and collect the hardware. Nothing rolls on automatically, and nothing is buried in a schedule.

Fit

This is a narrow offer, deliberately.

Worth a conversation if

  • Specific work genuinely cannot go to a third-party API: client contracts with data-processing restrictions, privileged matter files, regulated or client-confidential material.
  • You are working toward ISO 42001 or 27001, or a client audit has started asking how you use AI.
  • You have somewhere between fifty and two hundred and fifty people, and no platform team to spare.
  • You can live with beta software in exchange for shaping it and a founding rate.

Not worth your time if

  • You are mainly hoping to cut AI subscription costs. At your volumes, running models locally will not beat API pricing, and we're not going to pretend otherwise. The case for Core is confidentiality, control and what you keep.
  • You need a hardened product with a support desk and a reference list. That's a fair thing to want. Come back in a year.
The obvious worry

"What happens to our data if you disappear?"

A fair question to ask any young supplier holding your confidential material, and one we'd rather answer before you ask it.

The data is yours, always

Documents, indexes and retained knowledge live on hardware in your building, in open formats, exportable at any time without our involvement.

An open stack, not a black box

Core is built on established open-source components. There is no proprietary format holding your material hostage.

Documented runbook

Founding partners get the install and operations documentation, so a competent IT supplier could keep the appliance running.

Source escrow on request

For firms that need it as a condition of purchase, we'll put the source into escrow as part of the agreement.

What we can actually show you

Evidence, rather than adjectives.

95.32%

Strict in-scope performance across a 500-question retrieval benchmark, running entirely on local models. The methodology is published in full, including where it fails and why. Read the write-up.

Behind it: twenty years in IT and DevOps building and running production infrastructure, machine-learning models in production before MLOps was a job title, and a decade inside regulated financial services where client confidentiality was never an abstraction. On a call we'll simply show you the thing running.

Apply

Put your firm forward.

Tell us enough to judge whether this is a fit. Every application gets a personal reply, including the ones that are a no.

No newsletter, no drip sequence.