Shelbyby AIfactorScope a pilot

In production since January 2026 · best4travel

Governed AI for regulated work. Your premises, your policy.

Shelby is an AI platform installed on hardware you control: models on your premises, a gateway of five controls on anything that leaves, and workload blueprints that arrive pre-governed. Proof in production since January 2026: best4travel cut cruise-quote time from 25 minutes to 3 and now generates 95% of weekly quote volume automatically.

Quote time
25 → 3 min
Volume automated
95%
In production
Jan 2026
Shelby data pathYour data starts on premises, is pseudonymised, checked by an independent egress auditor, and routed by policy to one of four tiers: on premises, EU sovereign capacity, EU-region frontier models, or global endpoints for de-identified data only.YOUR DATAstays on premises by defaultPSEUDONYMISEreversible · fail-closedEGRESS AUDITindependent model · loggedROUTEyour policy × Shelby RegisterT0on premisesT1EU sovereignT2EU frontierT3global
Global endpoints take de-identified or non-sensitive work only.

In production

Four workloads in production. Five deployments.

Quoting · Reporting from operational data · Tender clarification and QA · DORA artefact production. Each reads messy inputs and produces the document a trained person would have produced, with a person checking where it matters.

Quoting

best4travel

Named client

Ocean-cruise quoting

  • Quote time cut from 25 minutes to 3
  • 95% of weekly cruise quote volume generated automatically
  • In production since January 2026
How quoting works

Quoting

iqbranding

Named client

Branding and print quoting

  • 50 reference test cases gate every release
How quoting works

Reporting from operational data

ARM

Internal production deployment

Advanced Radio Mapping, our in-house analytics practice, has measured exhibitor visitor traffic with on-site radio sensors since 2017. Shelby turns its sensor exports into the client report.

  • Eight-section client report with visitor cohorts, for Palfinger in Las Vegas
  • Second deployment at a European motorsport event, 2026 · delivered in .docx and .pdf
  • Deduplication mismatch flagged before release
How reporting from operational data works

DORA artefact production

Irish-regulated insurer

Client under NDA

Register of Information and exit-plan build

  • AI systems recorded on the Register of Information
  • Accepted on a clean ESA validation pass
How DORA artefact production works

Tender clarification and QA

Amata Engineering

Internal production deployment

Electrical contracting, pre-award

  • 150+ tender files read across two disciplines, ~90 of them drawings
  • 250+ numbered clarifications consolidated; ~70 overlapping queries merged to ~50
  • Two working days, estimator sign-off
How tender clarification and QA works

For regulated firms, AI stalls at the governance boundary.

Your compliance function cannot approve an AI route it cannot see. Whether a given model version may process your data depends on the deployment, the endpoint and the contracting entity, and the answer changes every quarter.

Shelby arrives with the design, the governance manifest and the audit scope already written for each workload. Your risk function reviews a document, not a project. The second deployment costs less than the first.

Shelby Gateway

Five controls between your data and any model.

The Gateway runs on hardware you control. Every blueprint deploys on top of it.

  1. Reversible pseudonymisation

    An on-premises filter tokenises names, PPSNs, Eircodes, IBANs, account references and the classes you agree with us before any call leaves. Answers are re-identified on your side. If the filter fails, nothing goes out.

  2. Independent egress audit

    A second model, from a different model family and on separate hardware, inspects every outbound flow for residual identifiers and keeps a tamper-evident log of what it checked, caught and escalated.

  3. Governed fine-tuning

    Audit flags become training data only after a person labels them. Models are promoted with signatures, versions, rollback and training-data lineage.

  4. Policy routing

    Each workload class is routed by your policy, resolved against the Shelby Register: a dated evidence base of where each model version may lawfully be processed.

  5. Verified private connectivity

    Destination allowlists, private DNS, denied public egress and private endpoints, with routes verified continuously.

Where work may go

TierDestinationTypical use
T0On-premises models, on your hardwareRaw data; highest sensitivity
T1EU-sovereign GPU capacity: EU-domiciled provider, EU facilityPseudonymised personal data. The governed default
T2EU-region frontier deployments, each qualified on its documented residencyPseudonymised work, where your policy accepts hyperscaler processing
T3Global endpointsDe-identified or non-sensitive work only

Two substrates for the on-premises tier

  • Our own stack — in production. NVIDIA hardware we specify, install and tune. Every deployment to date runs this way.
  • Azure Local — in validation. Microsoft’s on-premises stack, run in a customer location or a partner-operated data centre, with disconnected operation supported. Microsoft offers it with the NVIDIA RTX PRO 6000 Blackwell Server Edition GPU — the same class we specify for production — and we are validating Shelby’s on-premises tier on it now. On either substrate the Gateway, keys and auditor run in your environment; public Azure is not a home for the Gateway, and Microsoft-hosted EU-region models remain a T2 route.

In a Microsoft estate

  • Shipping today: sign-on through Entra; SharePoint and Fabric as document sources.

What Shelby is

  • A platform, not a model. Language models running on your premises, with governed routes to external capacity when your policy allows it. Every route speaks the OpenAI-compatible API standard, so models run on your hardware or with any provider behind one interface.
  • The Gateway. The five controls on this page, running on hardware you control, between your data and any model.
  • Blueprints. A library of workload control baselines — quoting, reporting, tender QA, DORA artefacts — each arriving with its governance manifest and acceptance tests written.
  • Deployed by AIfactor. We install it, tune it to your corpus and hand your compliance function the evidence. You operate it; overflow routes to governed EU capacity.

What Shelby is not

  • Not anonymisation. Pseudonymised payloads are treated as personal data unless an assessment shows otherwise.
  • Not your lawful basis, DPIA or transfer mechanism. It supports them; it does not replace them.
  • Not a certified DLP guarantee. Detection is statistical; residual risk is measured and reported per entity class.
  • Not a cloud service. The gateway, keys and auditor run in your environment.

The 30-day pilot

Acceptance criteria fixed before kickoff.

The pilot ends against objective tests in the statement of work, evaluable by your compliance function as well as your engineers.

Offline pilot

No cloud contract. Your data never leaves the premises. Proves detection by entity class, re-identification integrity, the auditor and fail-closed controls, with routing simulated.

Governed-egress pilot

Adds approved external routes. Proves model quality, residency behaviour and private network paths against your own provider accounts.

Example acceptance criteria

  • recall ≥ 0.95 on high-sensitivity identifiers
  • F2 ≥ 0.90 aggregate
  • zero egress of seeded canary identifiers
  • fail-closed behaviour verified
  • P95 latency and throughput measured

What a pilot delivers

Three use cases are named in the statement of work before anything is installed, and each is measured against your own current baseline — the time, cost and error rate of the workflow as it runs today — not against a vendor benchmark.

  1. Week 1

    Install and connect. Hardware on premises, corpus indexed, access controls in place, and the baseline for each use case measured and signed off with your team.

  2. Weeks 2–3

    The three use cases run alongside your existing process. Every output is scored against the acceptance criteria; discrepancies are logged and reviewed, not smoothed over.

  3. Week 4

    The evidence pack is assembled and walked through: measured results against baseline, per-criterion pass or fail, audit-log extracts, and a production sizing recommendation.

You keep the evidence pack whether or not you proceed. It is written to be read by your compliance function, your auditor and your board — not only by engineers.

  1. Pilot

    A pair of NVIDIA DGX Spark units on your premises, loaned for the pilot or purchased.

  2. Production

    RTX PRO 6000 Blackwell-class servers running the same software, sized from pilot measurements — on your premises or in an Irish partner-operated data centre.

  3. Overflow

    Work beyond your estate goes out pseudonymised, policy-routed and privately connected to governed EU capacity.

Fixed fee €25–50k, set by corpus scope. No hardware purchase required.

For partners

You host, connect and operate. We bring the blueprint, the pilot and the evidence pack.

Shelby fits managed service providers, network operators and data-centre operators who own the client relationship and the infrastructure it runs on.

Where it sits

On the client’s premises or in an Irish partner-operated data centre. The Gateway, keys and auditor stay in the client’s environment either way: the partner runs the racks and the connectivity; access, keys and the audit trail stay with the client.

Over your network

Private connectivity across your own network fits the verified-private-connectivity control: destination allowlists, private DNS, denied public egress, routes verified continuously.

Beside a productivity assistant

Where a client is rolling out a general productivity assistant, Shelby takes the workloads whose data should not go to one. The two run side by side.

Evidence your client can read

The Shelby Register records, per model version, where it may be processed and under which retention regime.

Partner pilot format Bring three client opportunities. Each is scoped as its own 30-day pilot, acceptance criteria fixed before kickoff.

Discuss a partnership

Who it is for

Organisations that hold sensitive data and answer to a regulator or a client.

Insurers, brokers and MGAs

Quoting, bordereaux and management reporting, DORA artefact production, invoice processing and client-money reconciliation.

Mortgage and credit intermediaries

Application handling and document checks, kept to preparation, never scoring.

Contractors and MEP firms

Tender clarification and QA from drawing sets, and progress reporting.

Public bodies

Casework preparation, records handling and reporting, kept on premises with a tamper-evident audit trail.

Enterprises

The same blueprints at department scale. Runs beside a general productivity assistant and takes the work that assistant should not see.

Research · Amata Consulting imprint

The regulation, read closely.

The work behind Shelby’s controls, published for compliance teams, policymakers and peers.

Team

Four people, from the switchroom to the model.

Silviu Preoteasa

Strategy and product

Product strategy, financial modelling and architecture decisions.

Daryll Collins

Engineering and delivery

MEP engineering, client delivery and field operations.

Jochen Cuntz

Systems integration

APIs, data pipelines and agent orchestration. Wires blueprints into your systems.

Marian Cursaru

Security architecture

Infrastructure hardening, network operations and the security posture regulated buyers need.

Scope a pilot

Tell us which workflow you want off your team’s desk.

We reply with a draft scope: the blueprint, the data boundary and the acceptance tests. Or write to hello@aifactor.ie.

We use what you enter only to reply — privacy notice.