Account numbers, balances, and dispute details.
Not the kind of thing to send to a shared API.
Private LLM hosting on a dedicated machine in EU-Central, for retail and commercial banking operations running customer service drafting, fraud review support, or document processing on account-level data without routing it through a third-party AI vendor.
Not legal advice. This page describes GPUwerk's infrastructure and contractual commitments. It is not an opinion on your regulatory obligations as a bank or credit union, and it is not a claim of any specific certification. Check with your own legal, risk, or compliance team before deciding what can run where. This page is about retail and commercial banking operations, not investment management; see private LLM hosting for wealth management for that.
Where an LLM fits into day-to-day banking operations
This is about the operational side of a bank: branches, contact centers, and back-office document handling, not portfolio management or trading.
Customer service
Drafting responses to account inquiries, summarizing a call or chat transcript for the next agent, or answering routine questions about products and fees. The underlying conversation usually includes account numbers, balances, and identifying details, all of which are the exact kind of data that shouldn't sit in a shared vendor's logs.
Fraud review support
Summarizing a flagged transaction history or drafting the narrative section of a case file for a human reviewer to check. The model doesn't make the fraud determination, a reviewer does, but the transaction data it works from is exactly the data a bank has the strongest reason to keep off shared infrastructure.
Document processing
Extracting structured fields from loan applications, KYC documents, or account-opening paperwork so a human doesn't retype them. These documents routinely carry government ID numbers, income data, and other sensitive identifiers, which is why a dedicated single-tenant instance is worth the extra operational effort over a shared endpoint. See the private AI support ticket triage guide →
On certifications and compliance frameworks
GPUwerk has not published PCI-DSS, SOC 2, ISO 27001, or any other formal certification, and this page makes no claim that hosting on GPUwerk satisfies any specific banking regulation. What GPUwerk provides is a dedicated single-tenant machine, a published GDPR Article 28 DPA with no sub-processors for instance workloads, and a documented answer to who can reach the machine and what happens to data on termination. If your compliance program requires a specific framework, that gives your risk team a concrete starting point to assess against your own requirements rather than a substitute for the assessment itself.
What's actually in the contract
For your compliance lead or IT lead to review directly.
| Question | Answer |
|---|---|
| Where does it run? | EU-Central, on a dedicated single-tenant machine assigned to your institution |
| Who operates it? | PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity. |
| Who can reach the instance? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the underlying machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Does GPUwerk see customer or transaction data? | No. We host the hardware and, under the DPA, do not access, read, copy, index or analyse workload content. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Certifications? | None published (no PCI-DSS, SOC 2, or ISO 27001 claimed). Assess against your own compliance requirements. |
| Data on termination? | Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating, since it isn't reversible. |
| Pricing | Spark-1x from $0.79/hour on demand, billed per minute; Spark-2x from $1.79/hour. A customer-requested stop holds the reservation at 75% of the running rate. See /pricing for full detail. |
Questions we get from banking teams
Can a bank run customer account data through an LLM?
That depends on where the model runs and who can reach it, not the model itself. On a GPUwerk dedicated instance in EU-Central, the machine is assigned to your institution alone and reachable only through your SSH keys; GPUwerk does not access, read, copy, index or analyse what runs on it except at your request for support or where a legal obligation requires it. Whether a specific use of customer account data meets your regulatory obligations is for your own compliance and legal team to confirm.
Is GPUwerk PCI-DSS or SOC 2 certified?
GPUwerk has not published PCI-DSS, SOC 2, or similar certifications. If your compliance program requires a certified provider or a specific control framework, a dedicated single-tenant instance with a published DPA and no sub-processors gives you a documented starting point to assess against your own requirements, not a substitute for that assessment.
Do you sign a DPA covering customer account and transaction data?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.
Does GPUwerk train on our data?
No. GPUwerk runs infrastructure, not models. There is nothing for GPUwerk to train on, since we do not access instance content except as described in the DPA.
Related reading
Private LLM hosting for financial services · Private LLM hosting for wealth management · Private AI for support ticket triage
Related pages
Keep account data and case files off someone else's servers.
Talk to the people who run the racks, or start with a pilot and a practical rollout plan.
Talk to us Deploy an instance