Skip to main content
foundry

AutomateAI & automation

Foundry AI

AI assistants and automation for business, deployed securely

Put AI to work inside your business, securely.

AI assistants, AI workflows and controlled agents that work over your own information, designed around your data governance, with human approval where it matters and an audit trail of everything.

What it covers

  • AI assistants
  • AI workflows
  • AI agents
  • Private AI
  • Data governance
  • Model choice
  • Human approval
  • Audit trails

In the Automate pillar

Remove repetitive work with controlled automation and AI.

Every business is being told to "do something with AI". Most of what is on offer is a chat window and a hope. Foundry AI is controlled business automation: assistants, workflows and agents that work over your own information, with the model chosen and deployed to match how sensitive that information is, and with the approval steps and audit trails a serious business needs.

Three things it does

OfferingWhat it means for your business
AI assistantsInternal knowledge assistants, document assistants, customer-service assistants, operational assistants and data assistants. Each answers from your information, cites its sources, and only sees what the person asking is entitled to see.
AI workflowsA request arrives, the model understands it, retrieves what it needs, applies your business rules, updates a system, creates a task, waits for approval where required, and leaves an audit trail. Delivered on the Foundry Automation runtime.
AI agentsControlled agents that read information, retrieve data, make recommendations, interact with APIs, execute approved actions, escalate to humans and maintain audit trails. Built last, on top of assistants and workflows that have earned trust.

An AI workflow, end to end

Email arrives
  ↓  AI understands the request
  ↓  Retrieves information (only what the requester may see)
  ↓  Applies your business rules
  ↓  Updates the system of record
  ↓  Creates the task
  ↓  Human approval, where the action is consequential
  ↓  Audit trail, in a store you own

Every step is visible, every action is attributable, and the model is one component among several rather than the whole system.

AI without giving up control of your data

Different AI products and deployment models have different data retention policies, training policies, contractual protections, logging behaviour, sub-processors, data-residency options and security models. Blanket statements in either direction are wrong. What Foundry does is design the AI architecture around your data governance requirements, and let you choose where the model runs by the sensitivity of the data.

Deployment modelWhat it means for your dataWhere it fits
Enterprise AI APIs (Anthropic, OpenAI)Both state commercial API data is not used for training by default, with short default retention and zero-retention options for eligible use. The provider is a processor under contract; data leaves your environment for inference.General reasoning and drafting over minimised or non-sensitive content.
Models inside your own cloud (Azure-sold models in Microsoft Foundry; Claude on Amazon Bedrock)Runs in your subscription and region. Microsoft states prompts and completions are not available to OpenAI and not used to train foundation models; Bedrock offers regional endpoints for residency requirements. Your contract, your keys, your logs.Regulated firms that want frontier capability without a new data relationship.
AI inside platforms you already run (Microsoft Copilot)Stays within your Microsoft 365 commitments and respects existing permissions and labels.Document and email assistance in a well-governed tenant.
Self-hosted and open-weight modelsNo model provider receives anything. The whole stack becomes your responsibility, or ours on your behalf.Narrow, high-sensitivity tasks where nothing may leave the environment.

Whichever model runs, the parts Foundry controls are the same: what data is retrievable, what is sent, what is logged, who approved what, and what can be proved afterwards. That is the product.

Private AI: a managed environment for sensitive data

For organisations that need greater control, Foundry designs and runs a private AI environment: customer-controlled infrastructure, private networking, encryption, identity integration and role-based access, a private vector database and document store, model abstraction so providers can be swapped, data-retention controls, human approval workflows, policy enforcement, monitoring and audit logging. It is the second and fourth rows of the table above, engineered and operated as one environment, and it is scoped per customer rather than sold as a box.

The reference architecture

Identity ──▶ Application / API layer ──▶ AI orchestration ──▶ Model abstraction
                     │                     (rules, policy,       ┌───────┬────────┬────────┐
                     │                      PII handling)        │ Azure │ Claude │ Self-  │
                     ▼                           │               │ Bedrock│ OpenAI│ hosted │
              Human approval                     ▼               └───────┴────────┴────────┘
                     ▲               Retrieval over private
                     │               document + vector stores
                     └───────────── Logging · audit · monitoring (owned by you)

Identity decides who may ask; retrieval decides what may be seen; rules decide what may happen; approval decides what may be executed; the log records all of it. External providers are still appropriate for the right workloads, and the architecture makes that a routing decision per workflow rather than a company-wide bet.

How an engagement starts

Not with a model. With the process: which requests, which documents, which decisions, which systems, and which data classification. From that we choose the deployment model, design the retrieval boundary and the rules, build the workflow with Foundry Engineering where custom software is needed, and evaluate it against real cases before it touches a customer.

FAQ

Frequently asked questions

Remote-first / UK-wide / one team

Ready for a technology team that can build?

Thirty minutes with an engineer, not a salesperson: what you run today, what’s at risk, what should be automated, and what we’d build or wouldn’t.

30 min call / no pitch / no obligation