Managed · Sovereign · Validated

Put AI into production.
Stay in control.

Numaga is a managed, sovereign AI platform. Every AI interaction in your organisation runs through policy you can prove, not trust.

numaga · governance
  • Policy enforced on every AI interaction
  • Personal data automatically redacted (GDPR)
  • EU AI Act risk class checked
  • Immutably recorded for audit
  • Hosted in the Netherlands, no CLOUD Act
IN CONTROLdemonstrable · inspection-ready
ISO 27001 certifiedDutch sovereign hostingEU AI Act ready

Designed for the people who have to defend it — CIO · CISO · DPO · compliance & legal.

Built and run by Joël Christ & Robin van Breukelen — Meet the team

In practice

Proven where data is most sensitive.

Numaga is running a pilot with Ontdek Zorg, a home-care organisation in Gelderland. Healthcare, with special-category personal data under the GDPR, is where responsible AI is hardest. That is exactly where we put the control plane to the test.

Trusted by
  • Home care in Gelderland
  • Special-category data (GDPR Art. 9)
  • Policy and redaction on every prompt
ontdekzorg.nl

A category choice — not a product choice

Microsoft, OpenAI and Anthropic offer productivity AI. We offer a managed AI platform.

Those are different categories. Here is the difference, stated plainly.

Category 01 · Productivity AI

Microsoft 365 Copilot · ChatGPT Enterprise · Claude for Work

A chat tool for individual employees across the organisation. Designed for personal task assistance — not central governance. Runs on hyperscalers under US jurisdiction.

Buyer: end user / line of business
Category 02 · Off-the-shelf "Private GPT"

Productised chat wrappers

Multi-tenant SaaS that builds a UI around shared cloud LLMs. Functional, but self-service — no managed governance, no regulatory partnership.

Buyer: self-service teams
Category 03 · Managed AI platform

Numaga.

Single-tenant, one control plane, hosted in the Netherlands. Every prompt classified, routed, redacted, logged — by policy, not by trust.

Buyer: CIO, CISO, DPO, compliance & legal

Side by side

What each category can actually do.

The capabilities you need to be accountable for AI — and who delivers them.

Side by sideProductivity AIOff-the-shelf Private GPTNumaga.
Dutch sovereign hostingno CLOUD Act exposure
Single-tenant deploymentMulti-tenant
ISO 27001 certified supplierAt hyperscaler level
EU AI Act risk-class routingenforced as policy
Prompt scanning at the gateclassification · redaction · routing
Role-based access to knowledgeRBAC end-to-endLimited
Self-built agents & workflowsno IT ticket neededLimited
Immutable audit · 5+ year retentionTenant logs onlyBasic logging
Validation & assurance artefactsfor your audits and reviews
Interchangeable foundation modelsno vendor lock-inLimited
Managed regulatory partnershipquarterly reviews, audit support

Four things you get nowhere else

The capabilities that make this the sensible choice.

For organisations deploying AI responsibly.

01

Sovereign by default.

ISO 27001 certified. EU AI Act ready. Dutch sovereign hosting. The three certifications your CIO, CISO and DPO need — in the box, not on the roadmap.

Defensible from day one
02

Prompt scanning at the gate.

Every prompt classified, sensitive data redacted, risky content blocked — before a single token reaches a model. Confidential information, personal data, trade secrets: they never leave the perimeter.

Enforced on the control plane
03

Role-based knowledge access.

Your team sees only what it is entitled to. Policy, documentation, internal knowledge — routed by role, with end-to-end RBAC over retrieval and inference.

RBAC end-to-end
04

Self-built agents & workflows.

Your teams build their own agents and automate their own workflows — inside the same control plane, without an IT ticket.

Power without escalation

How the platform is built

Four layers. One managed service.

Layer 01

Chat & integration

Web UI, M365 add-in, Slack, API access for agents. Familiar to end users — nothing new to learn.

Layer 02 · Core

Control plane

Classification, redaction, risk-class routing, immutable audit logging, key management. The part that does not exist in productivity tools.

Layer 03

Model layer

Models are commodities; swap underlying models without rebuilding. Per-request model optimisation.

Layer 04

Sovereign infrastructure

Dutch private cloud, NL jurisdiction. No CLOUD Act exposure, no hyperscaler dependency, no telemetry hooks on the model layer.

Foundation models are commodities. The control plane is where compliance lives.

Control plane — the journey of a prompt

Six checkpoints, before a single token reaches a model.

Pick a prompt and follow it through the control plane. Every step runs before the model call — no compensation after the fact.

Example prompts
Prompt arrives· · ·
Analyse this patient record and propose a follow-up treatment.
Processing…
Optimised model
01

Classify

Sensitivity label assigned — public · internal · confidential · strict.

02

Redact

Special-category personal data masked before it leaves the perimeter — GDPR Art. 9.

03

Risk-gate

Checked against the EU AI Act risk class — prohibited use is blocked.

04

Route

The best-fitting model chosen internally based on risk and sensitivity.

05

Meter

Budgets and rate limits enforced per user and per team.

06

Log

Immutable audit record written — tamper-evident, time-synced.

Synchronous

Every step runs before the model call — no compensation after the fact.

Deterministic

Policy rules, not LLM judgement. Reproducible for inspectors.

Configurable

Routing tables, sensitivity rules and budgets tuned to your policy.

If it doesn't pass the control plane, it doesn't happen.

Dynamic model routing

Not one model. The right model — for every prompt.

Models are swapped dynamically; every prompt gets the best-fitting model for that specific request. We assemble the pool from vetted European providers.

Per-request

The decision happens on the control plane, not in the user's prompt. Users get the right model without choosing one.

Provider-independent

No vendor lock-in. If a provider's terms or jurisdiction change, we route around them overnight.

Continuously optimised

Routing rules are updated as models improve and prices fall. Your cost drops, your capacity rises.

Incoming
Every user prompt
Numaga Router
Decides per request on:
Sensitivity classTask complexityLatency budgetCost ceilingLanguageRisk class
Curated pool · EU-vetted
Model AFast · cheap
Model BDeep reasoning
Model CLong context
Model DVision · OCR
…and whatever comes nextContinuously expanded

Risk-aware routing & data classification

The EU AI Act, operationalised.

Not as a guideline — as policy, enforced on the control plane.

Risk-class routing
EU AI Act classPlatform behaviour
Prohibitede.g. social scoringBlocked on the control plane.
High riskdecision & process supportAudit · validation evidence.
Limited risktransparency requiredTransparency labels added in-line.
Minimal riskStandard routing with monitoring.
Data-sensitivity routing
SensitivityBehaviour
PublicStandard routing.
InternalIdentity + audit.
ConfidentialEU-compliant provider + redaction.
Strictly confidentialpersonal data, trade secretsStrictest provider class + redaction + long-term retention.

Audit & observability

Every interaction logged — and retrievable when you need it.

What we record

  • User, time, prompt, retrieved context, model, output — every interaction.
  • Immutable storage, tamper-evident, time-synchronised.
  • Retention: 5+ years, configurable per use-case category.

What you get out

  • Real-time console for the CIO and Data Protection Officer.
  • KPI exports, risk-event alerts, reporting on blocked attempts.
  • Inspection-ready exports — CSV or PDF — for regulators, auditors and your own security review.

Demonstrability & assurance

Built to pass your security review and audits — not to dodge them.

Assurance pack

What we bring to your review.

  • Technical specification
  • Architecture & data-flow diagrams
  • Change-control register
  • Access to audit logs & proof of data integrity
  • ISO 27001 Statement of Applicability
  • Data processing agreement & DPIA inputs
  • Supplier audit pack
  • Annual ISO 27001 statement straight to your security team.
  • Change control: customer notified before any non-trivial platform change.
  • DPIA support: data flows, processor roles and retention periods supplied for your GDPR assessment.
  • Supplier qualification: we take part in your supplier and risk-assessment process.

What's in the managed service

Three jobs, one team.

Build

Week 1–4
  • Provisioning of your single-tenant environment
  • Control plane configured to your policy
  • SSO integration with your IdP
  • RAG ingestion — policy, documentation, internal knowledge
  • Branded chat interface
  • M365 and Slack add-ins
  • Initial user training — core users first

Run

Ongoing
  • Dutch sovereign hosting — fully managed
  • 24/7 monitoring and on-call
  • Smart model routing across the selected set
  • Prompt caching and budget monitoring
  • Office-hours support with a dedicated contact
  • Monthly health reports

Govern

Quarterly
  • ISO 27001 statement to your security team
  • Quarterly compliance reviews — CIO + DPO
  • Supplier inputs for your assurance process
  • Participation in your supplier qualification
  • Audit-log archive and proof of data integrity
  • Annual access reviews and policy refresh

Pricing — usage-based

You pay for what you use.

No licence inflation, no shelfware, no headcount negotiations up front. Tiers are assigned automatically each billing cycle based on actual usage. Concrete rates follow in a tailored proposal.

Lite

100K
tokens / user · month

Occasional users — quick lookups, document Q&A, light drafting.

Most users

Regular

1.5M
tokens / user · month

Daily users — research, drafting, analysis, regular interaction.

Power

4M
tokens / user · month

Heavy users — agents, long-running workflows, deep research.

One-off · onboarding

Sovereign deployment, control plane configured to your policy, SSO integration, RAG ingestion, branded chat interface, M365 and Slack add-ins, initial training. One fixed amount at the start — then only usage.

How tier assignment works

Every user starts on Regular. At the end of each billing cycle each user moves to the tier matching their actual usage — no manual review, no over-provisioning.

Overage

Usage above the tier cap is billed per million tokens at a fixed, pre-agreed rate.

Typical mix

~60% Lite · 30% Regular · 10% Power. Most users sit light — you don't pay for heavy capacity nobody uses.

How we work together

A partnership in four phases.

Phase 01

Exploration

Technical deep-dive, security review, scope and policy established together.

Phase 02

Proof of value

Sovereign deployment plus a pilot cohort on a bounded use case.

Phase 03

Decision point

Evaluate together and decide to scale.

Phase 04

Rollout

Broaden to your full organisation; usage-based billing goes live.

Ongoing — quarterly reviews · agent onboarding · model refresh

Frequently asked

Short and concrete.

The questions CIOs, CISOs and DPOs ask first — answered honestly.

What is Numaga?

Numaga is a managed, sovereign AI platform: a single control plane through which every AI interaction in your organisation runs on policy you can demonstrate, not on trust. It is single-tenant, hosted in the Netherlands, ISO 27001 certified and built around the EU AI Act. Numaga is a product of Replikate.

Where is Numaga hosted?

Numaga runs on a Dutch sovereign private cloud, fully under Dutch jurisdiction. There is no exposure to the US CLOUD Act, no hyperscaler dependency and no telemetry on the model layer. Every environment is single-tenant: your data never shares infrastructure with other customers.

How does the control plane work?

Every prompt passes six checkpoints before a single token reaches a model: Classify (sensitivity label), Redact (mask personal data, GDPR Art. 9), Risk-gate (EU AI Act check), Route (best-fit model), Meter (budgets and rate limits) and Log (immutable audit record). Each step is deterministic and synchronous — policy rules, not LLM judgement, reproducible for inspectors.

How does Numaga help with the EU AI Act?

Numaga operationalises the EU AI Act as policy on the control plane, not as a guideline on paper. Prohibited uses such as social scoring are blocked; high-risk use gets audit and validation evidence; limited-risk use gets transparency labels. Every decision is logged immutably, so you can show regulators exactly what happened.

Is Numaga ISO 27001 certified?

Yes. Replikate, the company behind Numaga, is ISO 27001 certified. With every engagement Numaga provides an assurance pack — technical specification, data-flow diagrams, ISO 27001 Statement of Applicability, data processing agreement and DPIA inputs — plus an annual statement directly to your security team.

How is Numaga different from Microsoft Copilot, ChatGPT Enterprise or Claude?

It is a difference of category, not product. Copilot, ChatGPT Enterprise and Claude for Work are productivity AI: chat tools for individual employees, on hyperscalers under US jurisdiction. Numaga is a managed AI platform: one central control plane with classification, redaction, risk routing and immutable audit — built for central governance, not individual task help.

What does Numaga cost?

Numaga is usage-based: you pay for actual token consumption, not licences or seats. Each billing cycle, users are automatically placed in a tier — Lite, Regular or Power — based on real usage. A one-time onboarding fee applies on top. Concrete rates follow in a tailored proposal.

What does an engagement look like?

In four phases: exploration (technical deep-dive and security review), proof of value (sovereign deployment plus a pilot cohort on one use case), a joint decision point, and rollout across the whole organisation. Quarterly compliance reviews, agent onboarding and model refresh then run continuously. The Build phase typically takes weeks 1 to 4.

Shall we begin?

We're ready. Are you?

An introduction, a technical deep-dive with your CIO/CISO and DPO, and an honest answer to whether a managed AI platform fits you.

Prefer that we reach out? Leave your details.

No obligation · reply within 1 business day

Visit
Graafseweg 274 · 6532 ZV Nijmegen
Certified
ISO 27001 · Dutch sovereign infrastructure
Robin van Breukelen

Robin van Breukelen

Founder
robin@replikate.nl(06) 23 22 59 42