Your data never has to leave your control.
Every serious conversation about AI in an enterprise reaches the same question, usually from the person whose name is on the risk register: where does our information actually go? For most platforms the honest answer is offshore, into someone else's model.
Worried about handing your business to someone else's AI?
That is exactly why Argon exists.
One stack. Four placements.
Not three products. One stack, deliberately built to be portable — plain Postgres, standard object storage, open model endpoints, containers — so moving between placements is an operational decision rather than a rebuild.
Assessment & advisory — the four modules
Programme delivery & assurance
Sovereign AI infrastructure — the layer both run on
AN AFFILIO PLATFORM
Sovereign, in South Africa
Isolated tenancy on our infrastructure in Johannesburg. The fastest way to begin, and the right placement for an assessment with a defined end.
Capacity reserved to you
Not shared and not scheduled against other engagements, still operated by us. The usual answer for a standing relationship or a regulated environment.
Inside your boundary
On your floor, inside your network, under your physical control. Nothing crosses your boundary. Available from Q1 2027.
Where you elect it
A named model provider under a data processing agreement, chosen in writing by you when capability matters more than residency. Never the default, and never applied without your instruction.
A quiet path offshore is what a security review finds. A declared one is what it accepts.
Platforms that promise data never leaves usually keep an undisclosed route to a frontier model for the hard questions. We take the opposite position: the sovereign placements are the default, the fourth exists, and it is named in your engagement rather than discovered in an audit.
Open-weight models running on the infrastructure your placement specifies. Where you have elected a named provider, that provider is identified in your engagement and bound by a data processing agreement. Nothing is routed anywhere you have not agreed to in writing.
A shared placement runs on a hardware-partitioned GPU instance with dedicated, non-overlapping physical memory. Separation between our own tenants is enforced in software — row-level security, egress policy and per-tenant routing — and we will show you how before you rely on it.
Standard components throughout — plain Postgres, S3-compatible storage, open model endpoints, OCI containers. Nothing that ties the platform to one place.
In-country processing on the sovereign placements, and a defined data lifecycle per engagement — your material removed on the terms agreed at the start, and ninety days after close-out where the engagement is silent.
Every assisted action is attributable — which model, on which evidence, producing which claim.
Which posture, and why.
The right placement depends on your regulator, your board and the sensitivity of the evidence — not on our preference. We work through it with you before anything is quoted.