Skip to main content
Built for enterprise security review

Your data. Your AI. Your region.

RiskSafetyAI runs AI on infrastructure you own — your cloud account, your region, your monitoring, your content policy. Your safety data never touches an AI provider we control.

AI config · your tenant
provideryours — 9 supported
accountyour cloud · your region
monitoringyour logs — and nowhere else
cost~3c a form · hard-capped
data to usnone — structurally
the boundary

Your safety data never touches an AI provider we control.

Configured per tenant — your keys, your caps
Three answers

The three questions we get asked first

Will our data train your AI?

No

— and structurally it can’t, because we don’t operate the model. Every AI call runs on your provider account, under the data processing agreement you already hold with Microsoft, AWS, or whoever you choose. No new vendor relationship to underwrite.

Can your AI see another mine’s data?

No

Every request is bound to your tenant at four independent layers, from token validation through to the data layer. No shared index, no pooled retrieval. On the dedicated tier your database is physically separate as well.

Where does our data physically sit?

In the region you pick

Database, files and audit log together — AWS Cape Town or Azure Johannesburg for South African sovereignty. Because you also choose where inference runs, the entire path stays in one jurisdiction.

Bring your own AI

We never own the AI relationship. You do.

Most safety platforms route your data through the vendor’s AI account and ask you to trust their policy about what happens to it.

RiskSafetyAI is built the other way around. You supply the endpoint and the credential. From that moment every AI call from your organisation runs through your Azure subscription or AWS account — billed to you, logged in your monitoring, filtered by your content policy, and switched off the moment you disable the configuration.

Your bill

token spend is a line item your FinOps team can see

Your logs

every invocation lands in your Azure Monitor or CloudTrail

Your policy

your content filters and guardrails apply to every prompt

Your switch

disable the provider and AI fails closed

Don’t take our word for it. Have your cloud team watch the logs. Configure the provider, run one AI assessment, and confirm the invocation appears in your own monitoring — and nowhere else.

YOUR INFRASTRUCTUREyour subscription · your region · your credentialRiskSafetyAIBuilds the request,scoped to your tenantPrompt + your dataYour AI endpointAzure OpenAI · Bedrock· self-hosted modelInference runsYour bill · your logs· your policyResponse onlyStored in your regionDatabase, files andaudit log togetherDisable the configuration and AI fails closed.
The request path, describedRiskSafetyAI builds an AI request scoped to your tenant and sends it out to an AI endpoint you own — Azure OpenAI, AWS Bedrock, or a self-hosted model inside your network. Inference runs entirely inside your infrastructure: your subscription, your region, your credential. The token spend is billed to you, the invocation is logged in your monitoring, and your content policy filters the prompt. Only the response returns to RiskSafetyAI, and the result is stored in the region you chose, with database, files and audit log together. Disable the configuration and AI fails closed.

Policy requires no outbound internet at all? Point us at a self-hosted model inside your network — one of nine supported AI providers. That configuration has no external AI path whatsoever.

AI cost

You set the ceiling. AI spend cannot cross it.

The real question behind “what does the AI cost?” is usually “what happens when it runs away?” It can’t — and not because we promise it won’t. Four controls are built into how the platform runs.

1

A hard monthly cap

Set a monthly AI budget per site. When it’s reached, the platform stops making AI calls and falls back to standard rules. The cap is a ceiling, not a warning threshold.

2

Off unless you turn it on

Automated review is opt-in, per site and per form type. All twenty-seven AI capabilities enable and disable independently — you pay for what you switched on and nothing else.

3

The cheap engine does the heavy lifting

High-volume automated review runs on the most cost-efficient model tier. The more capable, more expensive tier is reserved for occasional deliberate authoring tasks.

4

Never in the critical path

AI runs in the background, decoupled from form submission and offline sync. It cannot slow down, block or break the work your crews depend on — and if it’s paused, nothing stops.

AI assessment costs in the order of 3 cents per form. Less than printing the paper form it replaces.

Indicative, at current provider pricing — and easy to size yourself: multiply by your own daily form volume. There is no per-user fee and no platform uplift on inference; you pay your AI provider directly, at their rate.

Indicative monthly AI cost by site throughput. Confirmed against your real volumes in discovery. Illustrative, at ±R18.5/$ — your provider bills in USD.

Around 25 forms/day

a small site or a single crew

≈ R450 (~$23)

Around 100 forms/day

a typical operating site

≈ R1 700 (~$90)

Around 400 forms/day

a large or high-compliance site

≈ R6 700 (~$360)

The relationship is linear and shallow. Ten times the forms is ten times a small number — and whatever figure you land on, your monthly cap is still the ceiling.

Expect a one-off spike in the first month while your existing procedures and documents are ingested. That happens once, then effectively stops — it’s a setup cost, not a running cost.

The cap never breaks the platform. Reach your monthly ceiling and AI simply pauses; every form, inspection, permit and report keeps working on standard rules for the rest of the month. No surprise invoice, no service interruption.

AI hosting

Two ways to run it. Both in your cloud account.

The AI provider account is always yours. Your subscription, your billing relationship, your region, your kill switch. What you choose is who does the work of setting it up and keeping it running.

There is no AI markup, because we never resell inference.

Where it runs

Identical either way
Managed by us

Your Azure or AWS tenant

Managed by you

Your Azure or AWS tenant

Who configures it

Managed by us

We do — provisioning, model selection, tuning, monitoring

Managed by you

Your cloud team

Who pays the AI vendor

Identical either way
Managed by us

You, directly at cost

Managed by you

You, directly at cost

Who holds the kill switch

Identical either way
Managed by us

You

Managed by you

You

Best for

Managed by us

Teams without spare cloud engineering capacity

Managed by you

Teams with an established cloud practice and their own governance

Or point us at a self-hosted model inside your own network — no per-use AI fees at all, and no external AI path.

Where we manage the AI in your tenant, we operate under a least-privilege service principal scoped to the AI resource alone, issued by you and revocable by you at any time. We never hold standing access to anything else in your subscription.

Deployment and residency

Three ways to run it

Multi-tenant SaaS

we operate it, you consume it. Fastest to live.

Dedicated single-tenant

your own database and instance, in the AWS or Azure region you choose.

On-premise / private cloud

entirely inside your estate, on your VMs or Kubernetes.

Same codebase in all three. Same features, same audit trail, same AI options — the choice is about isolation and who operates the infrastructure, not about capability. Regional hosting addresses POPIA, GDPR, UK GDPR, the Australian Privacy Act, and UAE and KSA PDPL residency obligations.

Give this to your enterprise architect

We maintain a full architecture document — tenant isolation, identity, encryption, AI data flow, deployment models, integration surface. Ask for it and we’ll send it to your IT lead before we meet, then walk them through it in the session. If it doesn’t stand up to their reading, we’ve saved you a meeting.

Book a demo