Trading data on a shared API is a leak waiting to happen.
Put it on your machine instead.
Private LLM hosting on a dedicated machine in EU-Central, for firms that need contractual and technical control over where inference on client financial data actually happens.
Not a compliance claim. This page describes GPUwerk's infrastructure and contractual commitments. DORA and MiFID II impose obligations on financial entities, not on infrastructure vendors as a badge they can hold. Whether your use of this infrastructure satisfies those obligations is for your own compliance and risk functions to determine.
The control questions that actually matter
Confidentiality in financial services usually comes down to who can see the data and where the machine sits, not the model.
"Client and trading data leaves the EU"
It doesn't. The hardware is physically in EU-Central and operated by PRINT IT! SE, a Societas Europaea registered in Prague. No US parent, no US region, no US-incorporated entity in the chain. That's a fact about the rack, not a settings toggle.
"A per-token API means the vendor sees every prompt"
On a dedicated instance, the model runs on hardware assigned to you alone. GPUwerk operates the machine but, under the data processing agreement, does not access your content except at your request for support or where a legal obligation requires it. There's no third party sitting between your traders and the model.
"Analysts use consumer AI tools for research"
A sanctioned alternative on your own instance, same chat interface, keeps that workflow off shared infrastructure without pushing it to personal accounts. See the private ChatGPT setup →
For your risk and compliance review
Frameworks like DORA and MiFID II are relevant to how your firm manages ICT risk and client information; check your own obligations under them against what follows.
| Question | Answer |
|---|---|
| Where is data physically processed? | EU-Central, on a dedicated single-tenant machine assigned to your firm |
| Who operates it? | PRINT IT! SE, a Societas Europaea registered in Prague, Czech Republic. No US parent entity. |
| Who can access instance content? | Through the instance itself, only holders of your SSH keys; password login is disabled fleet-wide. GPUwerk keeps infrastructure administrator access to the machine, as on any hosted service, and under the DPA does not use it on your content except at your request for support or where a legal obligation requires it. |
| Is GPUwerk DORA compliant? | Not a claim we make; DORA obligations sit with your firm. We can support your own ICT third-party risk assessment with documentation on request. |
| Sub-processors for the workload? | None, listed at /legal/sub-processors |
| DPA (GDPR Art. 28)? | Published at /legal/dpa, no charge |
| Data on termination? | Container and workspace volume deleted from the node, then the node is sanitised before reassignment. Filesystem deletion, not a cryptographic erase; export what you need before terminating. |
Questions we get from financial firms
Is GPUwerk DORA compliant?
We don't make that claim. DORA is a regulatory obligation on financial entities themselves, including how they manage ICT third-party risk, and it isn't a certification a vendor holds. What we can tell you is where the hardware sits, who operates it, and what's in the contract; whether that satisfies your firm's DORA obligations is an assessment for your compliance team to make, not us.
Where does trading or client data get processed?
On a dedicated single-tenant machine in EU-Central, assigned to your firm alone. GPUwerk operates the hardware and, under the data processing agreement, does not access, read, copy, index or analyse workload content except at your request for support or where a legal obligation requires it.
Do you sign a DPA?
Yes, a standard GDPR Article 28 DPA is published at /legal/dpa at no charge, and there are no sub-processors for instance workloads.
Does GPUwerk train on our data?
No. GPUwerk runs infrastructure, not models. Data processed on your instance is handled by software you install, behind SSH keys only you hold, and under the DPA we do not access that content except as described above.
Related pages
Get the architecture in front of your risk team.
Talk to the people who run the racks, or start with a pilot and a practical rollout plan.
Talk to us Deploy an instance