For banks, ministries and hospitals whose data cannot leave
AI that never leaves your perimeter.
The work your staff already paste into consumer AI, done inside your perimeter, cited and recorded.
Your perimeter
Your people
Credit risk · Compliance · Engineering · Operations
Your infrastructure
GPU pools · storage · in-country data centre
Shadow AI
Your staff are already using AI.
This week someone in your organisation pasted work into a consumer chatbot. A draft contract, a customer record, a policy memo. Nobody was being careless. It was faster, and nothing inside the building could do it.
82%
of that pasting runs through accounts the organisation does not control. That is shadow AI: now the single largest uncontrolled channel for corporate data leaving the building.
LayerX · Enterprise AI and SaaS Data Security Report 2025
Institutions reach for four answers. All four fail.
One request
One request, from question to record.
Five questions decide whether a system like this passes review. Here they are, against the record of one request.
Your perimeter
01 · Signed in
Credit Risk · Chenab Commercial Bank ✓ Signed in
02 · Answered, with citations
What is our maximum unsecured exposure to a single SME borrower, and when was that limit last revised?
◆ Zyrak · answered from your documents
Your ceiling for unsecured exposure to a single SME borrower is PKR 25 million1. The limit was last revised on 14 May 2026, when ALCO reduced it from PKR 40 million following the Q1 concentration review2.
Illustrative data · no real institution
03 · Recorded & sealed
0 bytes crossed your border.
Weights local · immutable log · exportableOne request, three moments of the same screen. A demo tenant; the answer cites the institution's own documents, and one record like this exists for every request.
The five questions
Who was permitted to ask it, and where could it go?
Identity verifiedA. Rehman · Credit Risk · SSO
Classified & routedInternal · on-soil route
What did it read to produce the answer?
Retrieved & citedCredit Policy Manual Section 7.3 · ALCO Minutes, 14 May 2026
Which model answered this query?
Model answeredZYRAK-CORE-2.4 · GLM-5.2 open weights · local
Can that record be exported for an auditor?
RecordedImmutable log · exportable
Can one department be isolated from another?
Workspace isolatedCredit Risk only
What it does
Three kinds of work, governed identically.
Everything below runs inside the same shell. The user is identified, the request is classified and routed, sources are cited, and the whole exchange is recorded. The images on this page are one platform wearing different jobs.
Ask your documents.
Assistants that read your own policies, case files and records, and answer with citations down to the section and page. A user can check the claim. An auditor can trace it.
Automate the work.
Agents that act inside the systems you already run, through open MCP and OpenAPI connectors. Every tool call lands in the same audit trail as everything else.
Give your developers AI.
Institutions ban cloud coding assistants because source leaves the estate. Here the model sees only the repository it is scoped to, and the session is recorded like any other.
Where it runs
Your infrastructure, or on-soil infrastructure we arrange.
Zyrak is software, not a facility. It runs on servers you already own, inside your existing perimeter, air-gapped if your network demands it. If you would rather not host it, we arrange on-soil infrastructure with operators we work with. Either way the weights, the data and the record stay on Pakistani soil.
We sell no hardware and no compute, so we have no reason to steer you towards any particular home. It deploys under your name, and for institutional buyers the source is held in escrow: if we fail as a company, your deployment and its code do not fail with us.
Contact
Thirty minutes with whoever owns the risk.
We would rather understand what you are dealing with than read you a specification.
hello@zyrak.pk · Islamabad, Pakistan