Diana'sarchitecture.Nohand-waving.
A plain-language explanation of Diana's sovereign architecture — written for compliance officers, IT directors, and technical buyers who need specifics, not marketing.
DEPLOYMENT OPTIONS
Two ways to deploy. Both fully sovereign.
Diana offers two deployment models. Both guarantee that your data stays under your control. The difference is where the hardware lives.
Sovereign Cloud
Fastest to deployDiana can runs on a dedicated private server in a European data centre OVHcloud, Hetzner, or Scaleway. Your data stays on EU soil, on hardware that is dedicated exclusively to you. No shared tenancy. No data commingling. No public cloud. You do not manage the hardware — but you own everything on it.
On-Premise
Maximum controlDiana runs on hardware inside your own IT environment — your server room, your data centre, your building. Your IT team owns it. Your compliance team can audit it. Nobody else can touch it. Not Diana. Not anyone.
The intelligence layer
What is actually running inside the box.
Small Language Models
Diana's agents run on Small Language Models, AI built to run on dedicated hardware, not cloud data centres. This is what makes sovereign deployment possible. A server the size of a desktop delivers enterprise-grade AI execution, entirely inside your building.
Expert Intelligence
Generic AI knows a little about everything. Diana's specialist models know everything about one thing. Each model is built by a domain expert, encoding their methodology, frameworks, and decision logic into a model that thinks like them. Not general intelligence. Expert intelligence.
DATA FLOW
What happens when your team sends a request.
When a user sends a request to Diana, everything that follows happens inside your infrastructure. The request travels from their device to Diana's server through your internal network. Diana's orchestration engine routes it to the relevant specialist agents, Workspace Search, your domain specialist, your document specialist. Each agent reads from your local document store, processes on your hardware, and returns its output. At no point does any data leave your network. The entire process, from request to output, happens inside your walls.
What stays inside
Your documents. Your queries. Your agent outputs. Your compliance reports. Your audit logs. Every piece of data your team generates through Diana never leaves your infrastructure. Ever.
No subscription to an AI provider.
Diana does not route your requests through OpenAI, Anthropic, or any external AI service. The models run locally. There is no per-query cost, no API dependency, and no third-party AI provider with access to your data.
Technical FAQ
No. The management tunnel connects to the management controller inside the box — a separate small device. It has no pathway to the inference engine, vector database, or any client data. Your IT team can verify this by inspecting the network configuration independently.
Diana runs on Small Language Models — AI models designed to run on dedicated hardware rather than cloud data centres. Unlike ChatGPT or Copilot, which require your data to travel to a remote server, Diana's models run entirely on your hardware. They are fine-tuned on specialist domain expertise, which makes them more accurate for regulated industry tasks than general-purpose models.
Your system keeps running. The software runs on your hardware. Agents you have already deployed continue to work. You are not dependent on Diana's servers for day-to-day operation. Your data was never on our servers — it stays exactly where it always was, inside your infrastructure.
Updates are delivered through a separate management channel that has no access to your data. The update is a software package — not a data transfer. Your client data does not move during this process. Your IT team can verify this independently by inspecting the network configuration.
Sovereign Cloud puts your dedicated server in a European data centre — faster to deploy, managed infrastructure. On-Premise puts it in your building — physical control, no external dependency. Both guarantee no shared tenancy and no data commingling. The decision comes down to whether you want the hardware in your building or in a certified European facility.
Yes, and we encourage it. Your IT team can inspect the network configuration, firewall rules, management tunnel scope, and agent package verification process independently. We provide full technical documentation — architecture diagrams, network flow specifications, and security configuration guides — to every enterprise client before deployment.
It depends on the hardware configuration we select during your onboarding. A standard deployment supports small to mid-size teams comfortably. For larger organisations, additional servers are added to the same internal network. We size every deployment individually based on your team's needs.
Seen enough to move forward?
Diana is deployed through certified implementation partners who handle hardware selection, installation, and onboarding. Most deployments are live within days of the decision.