Platform and custom – from one source, in your own tenant.
For large enterprises, critical infrastructure, and the public sector: deepsight cloud as the standard platform plus custom projects for everything beyond it. Custom models, DPA, DPIA, and SSO (Microsoft Entra ID) included, on-premise on request – procurement-ready from the first conversation.
Three walls that enterprise programs regularly run into.
We have worked with large enterprises, insurers, and public authorities since 2019. The issues are remarkably consistent – and they share the same root cause: platform and custom are procured separately and owned separately.
Standard SaaS does not make it past IT security.
US hosting, shallow SSO, no VPC, no audit log streaming. The tool pitch ends in the vendor onboarding questionnaire – and nothing moves forward.
A custom boutique does not scale beyond the pilot project.
Tailor-made, but with no platform underneath. Three quarters later, a mini system sits on a server that nobody updates anymore.
Two contracts, two DPAs, two roadmaps.
A platform vendor plus a custom agency – with your own IT in between, translating. Who is responsible for what? In practice: nobody.
Platform plus custom. One contract, one tenant, one team.
deepsight cloud is the standard platform with twelve modules. Custom projects add everything the standard does not cover – embedded in the same tenant, under the same DPA, with the same user and permission management.
The platform underneath your solution.
Auto-coding, topic clusters, tracking, surveys, slide factory, RAG bot – booked modularly, in your own EU tenant. Updates and methods hotline included.
- 12 modules – à la carte
- SSO – Microsoft Entra ID (OIDC)
- Audit logs – SIEM integration via setup
- Quarterly releases – pinning via setup
- Methods hotline – 24 h SLA
Everything beyond that – built on the same stack.
HRIS sync, custom scales, industry-specific code frames, autonomous agents, on-premise deployments. Full-stack in one team – data science, backend, frontend.
- SAP, Workday, Salesforce, ServiceNow
- Custom models & fine-tuning (EU GPU)
- On-premise & air-gapped deployments (on request)
- Multi-agent systems, RAG, contract analysis
- Handover documentation, no vendor lock-in
Three hosting models. You choose what your IT security signs off on.
Public, private, on-premise – all three with the same feature set and the same models. Switching between models is possible without losing code frames or wave-over-wave comparisons.
EU Public Cloud
Frankfurt - multi-tenancy
Up and running fast, full feature set. The right model for most scenarios – even under a strict GDPR interpretation.
- Region
- DE-FRA – EU-only
- Tenant
- Logically isolated
- SLA
- 99.9 % – penalty-backed
- Onboarding
- ~ 2 weeks
Private VPC
Dedicated tenant - BYO KMS
Your own Kubernetes namespace in our EU infrastructure, your own encryption keys (customer-managed), separate network, dedicated GPU pool for custom models.
- Region
- DE-FRA – single-tenant
- Keys
- BYO KMS – HSM optional
- SLA
- 99.95 % – penalty-backed
- Onboarding
- ~ 4–6 weeks
On-prem & air-gapped
Your data center - on request
Complete deployment in your infrastructure – available on request. For public authorities, defense, and critical infrastructure. An air-gapped variant without any internet outbound is possible.
- Infra
- K8s – OpenShift – VMs
- Models
- Hosted locally
- Updates
- Signed air-gap bundles
- Onboarding
- ~ 8–12 weeks
Six building blocks your IT security cannot get around.
The foundation is built into the product – SSO, audit logs, role and tenant separation. Everything beyond that – SIEM integration, your own keys, release pinning – we set up as part of your deployment. One scope, one contract, no add-on price list.
Single Sign-On (Microsoft Entra ID)
Login via OpenID Connect with Microsoft Entra ID (Azure AD), including multi-tenant setups. Users are provisioned automatically on first login, gated by your organization's allowed email domains. SSO can be enforced – configured by your IT, directly in the org settings.
Audit logs & SIEM integration
Every action logged in an audit-proof trail – user, tenant, module, data point. We set up the integration with your SIEM (Splunk, Sentinel, ELK) as part of your deployment.
Encryption & key management
TLS 1.3 in transit, AES-256 at rest – standard in every tenant. Customer-managed keys via your KMS are part of the dedicated setup; with them in place, we are technically unable to decrypt your data.
Release pinning & stability
Quarterly releases announced via release notes. For regulated environments, we agree on release windows and version pinning as part of your setup – compliance reviews run without models changing underneath you.
Multi-tenancy & BU separation
We set up group structures with separate tenants per business unit together with you – data, code frames, reports, and user management separated, with an aggregated group-level view on request.
Procurement-ready
DPA (Art. 28 GDPR), TOMs, DPIA template, TIA, ISO 27001 SoA. We actively support your vendor onboarding questionnaire.
Evidenced. Not asserted.
What we hold today, what we are actively building, what we map for you. Ask for the security whitepaper – 60 pages, no marketing.
Six setups that actually combine cloud and custom.
What fails the vendor questionnaire with a standard SaaS and falls asleep after three quarters with a pure custom boutique – works here, because platform and custom sit under the same contract.
Group-wide employee survey
38,000 employees, 14 BUs, 6 languages – one wave, one audit trail, automatic manager cuts per team with k-anonymity from n=5.
Cloud – HR moduleVoice of customer across 11 markets
Multi-language CX program at an insurer. Open-ended NPS answers are coded in their original language, topics remain comparable across countries.
Cloud – CX moduleContract analysis agent (on-prem)
Major bank, air-gapped deployment. A multi-agent system extracts clauses from 240k contracts and writes structured fields back into the DMS.
Custom – on-premRAG knowledge platform for a public authority
Federal authority, 1.4M internal documents. Semantic search, chat, auto-summaries – hosted in the authority's own data center, without external LLM APIs.
Custom – government data centerTracking program – 9 waves per year
Mid-sized hospital group. Patient and employee tracking with wave-over-wave comparison, manager reports automatically delivered as PowerPoint – via slide factory.
Cloud – trackingHRIS sync with SAP SuccessFactors
Industrial group, nightly master data sync. Survey reports are delivered along the SuccessFactors org structure – without manual mapping edits.
Custom – SAP integrationSix weeks from briefing to a productive pilot.
We know the stations – security, data protection, purchasing, works council, business. We deliver the right documents to each of these stations, without you having to ask for them.
Briefing & NDA
A 60-minute session with your IT security and business team. Mutual NDA from day 1.
DiscoverySecurity review
Whitepaper, DPA draft, TOMs, ISO SoA, vendor questionnaire – answered.
InfoSecPilot tenant
Tenant provisioned in EU-FRA, user onboarding, anonymized data upload.
TechPilot wave
Code frame, first topic clusters, manager cut. Results review with your business team.
PilotRoll-out plan
Scope custom building blocks, prioritize BUs, finalize MSA and SoW.
ScaleWe chose deepsight because we got the cloud platform and the custom HRIS setup under one contract – with one DPA, one SIEM connection, one point of contact. Three competitors wanted to sell us three contracts. That was settled after the first security review.
Six questions that always come up in the vendor questionnaire.
Answers without marketing. Full versions in the security whitepaper. Whatever is missing here, we answer by email within 24 hours.
Is our data used for model training?
No. Tenant data never leaves the tenant – not even for training. Models run either locally in the EU tenant or via EU Azure with a no-training clause. Contractually fixed.
Who has operational access to our data?
By default, nobody on our side. Privileged access only on demand and approved by you – every access lands in the audit log, and with a SIEM integration in place, directly in your system. With customer-managed keys in the dedicated setup: no access without your keys.
What does the exit look like?
You can export at any time – raw data, code frames, reports, audit logs – in open formats (CSV, JSON, SPSS). No proprietary format, no vendor lock-in. We provide handover documentation.
Which SLA applies – including custom building blocks?
Cloud standard: 99.9 % with contractual penalty. Private VPC: 99.95 %. Custom building blocks fall under the same SLA if they are deployed through our pipeline.
How do updates fit compliance reviews?
Quarterly releases announced via release notes. Version pinning – models and code frame logic – is agreed as part of the enterprise setup. During an active audit, nothing changes underneath you.
What happens in a security incident?
Notification within 24 h, RCA within 72 h, RTO 4 h, RPO 15 min. The BCM plan is part of the contract. You receive a raw log extract for your own investigation.
Bring your vendor questionnaire. We will walk through it live.
One session, two sides – your IT security and your business team. We answer vendor questions, show you the tenant, and sketch the custom building blocks. By the end, you will know whether we make it through your procurement.