The regulatory trigger
CBUAE outsourcing rules require the master system of record, including confidential data, to be maintained and stored in the UAE. Sharing confidential data outside the UAE needs Central Bank approval and customer consent mechanics that most "ship the PDF to a cloud LLM" products never survive.
CBUAE guidance on AI and machine learning for licensed institutions stresses governance, accountability, human oversight, data management, and responsibility for third-party AI. The compliance question is not whether the GPU is in Dubai. It is who holds the keys, who runs the weights, and whether the supervisor can still reach the evidence.
If the Central Bank asked tomorrow where this KYC pack was inferred, could you answer without naming a public model vendor?
The wedge
KYC and credit-file document intake first: classify, extract, map to the bank's schema, cite source regions, preserve originals. Exception routing and analyst assist on AgentLab come after Foundation and DocxIntel are live. A human remains on consequential decisions.
Why the cloud answer fails here
A public agent or OCR API that processes confidential customer data outside the approved perimeter collides with outsourcing and data-protection obligations before accuracy is even measured. Data residency on a vendor-operated model is residency without sovereignty.
What deployment looks like
Foundation in customer tenancy or air-gapped. DocxIntel for packs. Model Gateway on every prompt and tool call. Policy, DLP, human-in-the-loop and immutable audit in path. The customer is controller and processor. BizfyLabs LLC does not hold production data. Apache 2.0 and MIT weights on disk. The first deal can be DocxIntel only.
Controls in this workflow
These controls run on Private AI Foundation for every document ask. AgentLab, if used later, shares the same path.
- Packs stay inside the customer perimeter. Inference does not require a network path out.
- You hold the encryption keys in every tier that touches your data.
- Every document ask goes through the Model Gateway. There is no side door to a public model.
- Policy and DLP evaluate the request before weights run.
- RBAC names who may invoke which model class on which data class.
- DocxIntel writes per-field confidence and citation back to the source region. Originals are preserved.
- Consequential AgentLab actions wait for a named approver. Nothing silent-posts to your core systems.
- Immutable audit is written on the same install: who, what, which model, which policy, outcome.
- Apache 2.0 and MIT weights only. Licence text and an SBOM ship on disk per release.
What we do not claim
Not core banking. Not automatic credit decisioning. Not a guarantee of CBUAE approval. Not AML transaction monitoring as a product SKU.
The paid proof of value
Thirty to forty-five days. Fixed fee. In the customer environment. One document type. Agreed real volume. Success criteria and conversion price agreed in writing before starting. If it misses the threshold, the customer keeps the report and owes nothing further.
This is not a free trial and not a sandbox that pretends to be residency. The cable can be pulled. The packs are yours.