Engineering data that can't leave the EU.
Don't send it to someone else's model.
Private LLM hosting on a dedicated machine in EU-Central, for aerospace and defense engineering teams working with technical documentation that carries export-control, IP, or program-security obligations.
Not export-control advice, and not a claim of compliance with any defense-industry security standard. ITAR and EAR are US regimes; GPUwerk is a Czech company with no US parent entity, and we are not positioned to advise on whether a given dataset is export-controlled, under which regime, or what that means for your processing choices. GPUwerk has not pursued any defense-specific certification of this platform, and this page is not evidence of one. It describes GPUwerk's infrastructure and contractual commitments only. Whether a given engineering dataset may be processed here at all is a determination for your own export-control counsel and security office, made before any data moves.
Two kinds of exposure, one shared answer
Technical documentation on a defense or aerospace program can carry export-control obligations on top of ordinary IP concerns, and a security clearance regime that has opinions about which vendors and jurisdictions may touch it. Both raise the same infrastructure question before anything else: where does the model actually run, and who operates the machine.
"A drawing set or test report is tied to program-level access controls"
Even where a document isn't formally export-controlled, program security requirements often restrict which systems and personnel may process it. On a GPUwerk instance, the machine is assigned to your organisation alone, in EU-Central. GPUwerk operates the machine but, under the data processing agreement, does not access your content except at your request for support or where a legal obligation requires it. This is a description of infrastructure, not a determination that a given use satisfies your program's access-control requirements; that determination is yours to make.
"A shared US-hosted AI vendor raises jurisdiction questions before content even matters"
Where data is processed, and under what legal jurisdiction, is often the first question a program security officer asks, independent of what the data actually contains. GPUwerk runs on hardware operated by a Czech entity in EU-Central, with no US parent entity in the corporate chain, which is a materially different starting point from a US-headquartered AI vendor. Whether that starting point satisfies a specific program's requirements is still your determination to make.
"Engineers already paste specs and test data into consumer AI tools"
Asking a public AI tool to summarise a test report or draft a section of technical documentation is common, and rarely reviewed for what program-specific detail rode along with it. A sanctioned alternative on your own instance, same chat interface, keeps that workflow off third-party infrastructure entirely. See the private ChatGPT setup →
What's actually in the contract
For your security office, export-control counsel, or program lead to review directly. This is a description of infrastructure, not a certification or export-control determination.
| Question | Answer |
|---|---|
| Where does it run? | EU-Central, on a dedicated single-tenant machine assigned to your organisation |
| Who operates it? | PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity. |
| Who can reach the instance? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the underlying machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Does GPUwerk determine export-control status for us? | No. We are not export-control counsel, and this page is not advice. That determination, and any resulting processing restriction, is your organisation's own responsibility before data ever reaches this or any infrastructure. |
| Is the platform certified against a defense security standard? | No, and we don't claim it is. Any certification of this infrastructure as part of a program's security envelope would be your organisation's own scope of work, using documentation we can provide on request. |
| Does GPUwerk read technical documentation processed on the instance? | No. We host the hardware and, under the DPA, do not access, read, copy, index or analyse workload content. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Data on termination? | Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating, since it isn't reversible. |
Questions we get from aerospace and defense engineering teams
Is GPUwerk cleared for ITAR- or EAR-controlled technical data?
We don't make that claim, and we're not the right party to make it. ITAR and EAR are US export-control regimes; GPUwerk is a Czech company (PRINT IT! SE) with no US parent entity, and whether a given piece of technical data is controlled at all, and what that means for where it may be processed or by whom, is a determination for your own export-control and legal counsel, not something an infrastructure vendor can certify. This page is not export-control advice.
Does GPUwerk hold any defense-specific security certification?
No. We haven't pursued certification against any national or NATO defense-industry security standard, and this page is not evidence of one. What we can describe is the infrastructure itself: EU-Central location, dedicated single-tenant machine, an Article 28 DPA. Whether that infrastructure is adequate for a specific program's security requirements is a determination for your own security office.
Where physically does the instance run?
EU-Central, operated by PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic, with no US parent entity. We can confirm physical location and operating entity on request; we don't publish a rack-level address.
Do you sign a DPA?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.
Related pages
Put the technical documentation on hardware your own team controls.
Talk to the people who run the racks, or start with a pilot and a practical rollout plan.
Talk to us Deploy an instance