Community
A place where researchers and innovators collaborate on EU projects.
Community
A place where researchers and innovators collaborate on EU projects.
EU sovereign AI architecture
with
Citadel.
Citadel.
An on-premise LLM orchestration. Delivered as physical hardware. Operated as managed software. Owned entirely by you.
EU sovereign AI architecture
with
Citadel.
Citadel.
An on-premise LLM orchestration. Delivered as physical hardware. Operated as managed software. Owned entirely by you.
EU sovereign AI architecture
Citadel.
Citadel.
An on-premise LLM orchestration. Delivered as physical hardware. Operated as managed software. Owned entirely by you.


What Citadel is
Tired of losing control over your tokens and sensitive data?
Citadel is a branded hardware unit, installed inside your premises, running a fully managed LLM orchestration stack. Timbi handles deployment, configuration, model training, and ongoing maintenance. You get the capability of frontier AI without any of the data risk with fully predictable pricing and complete cost transparency.
Citadel is a branded hardware unit, installed inside your premises, running a fully managed LLM orchestration stack. Timbi handles deployment, configuration, model training, and ongoing maintenance. You get the capability of frontier AI without any of the data risk with fully predictable pricing and complete cost transparency.
GRPR compliant
GRPR compliant
AI Act compliant
AI Act compliant
Multi-model orchestration
Run up to five LLMs simultaneously, routing queries to the best-suited model for each task. No single-model dependency. No performance ceiling.
Up to 5 concurrent models
Intelligent routing
Best-of-breed output
Multi-model orchestration
Run up to five LLMs simultaneously, routing queries to the best-suited model for each task. No single-model dependency. No performance ceiling.
Up to 5 concurrent models
Intelligent routing
Best-of-breed output
Private peer-to-peer VPN
Every connection to Citadel runs through a custom P2P VPN configured for your organisation. No public internet exposure. No traffic interception risk.
Custom P2P VPN
No public endpoints
Encrypted in transit
Private peer-to-peer VPN
Every connection to Citadel runs through a custom P2P VPN configured for your organisation. No public internet exposure. No traffic interception risk.
Custom P2P VPN
No public endpoints
Encrypted in transit
Custom model traininger-to-peer VPN
Models are trained on your organisation's specific prompts, documents, and workflows, so Citadel learns how your people think, operate and operates over time.
Fine-tuned on your data
Domain intelligence
Continuously improving
Full support & maintenance
Timbi manages the full stack, hardware, software, model updates, and security patches. Your team uses the capability. We keep it running.
Hardware maintenance
Model updates
Dedicated support
Full support & maintenance
Timbi manages the full stack, hardware, software, model updates, and security patches. Your team uses the capability. We keep it running.
Hardware maintenance
Model updates
Dedicated support
Who it is for
Built where data protection is non-negotiable
Legal & professional services
Client confidentiality and privileged information cannot touch public AI infrastructure.
Defence & aerospace
Classified systems, dual-use technology, and national security contexts require absolute data sovereignty.
Pharma & biotech
Proprietary compounds, clinical data, and research IP must remain inside your environment.
Engineering & deep-tech
Source code, product designs, and technical IP are your core competitive assets, protect them accordingly.
How it works
From deployment to operation in three steps
Deploy
01
Hardware installed on your premises
Timbi ships and installs a branded Citadel unit inside your infrastructure. No cloud dependency, no external connection required for core operations.
Deploy
01
Hardware installed on your premises
Timbi ships and installs a branded Citadel unit inside your infrastructure. No cloud dependency, no external connection required for core operations.
Deploy
01
Hardware installed on your premises
Timbi ships and installs a branded Citadel unit inside your infrastructure. No cloud dependency, no external connection required for core operations.
Connect
02
Private VPN configured for your team
We configure a custom peer-to-peer VPN so your team accesses Citadel securely from any authorised device, without touching the public internet.
Connect
02
Private VPN configured for your team
We configure a custom peer-to-peer VPN so your team accesses Citadel securely from any authorised device, without touching the public internet.
Connect
02
Private VPN configured for your team
We configure a custom peer-to-peer VPN so your team accesses Citadel securely from any authorised device, without touching the public internet.



Architecture
Public LLM providers offer remarkable capability, but at a cost most companies have not fully calculated. Every prompt, every document, every piece of code you send to a cloud model is data that has left your environment. For companies with valuable IP, regulated data, or genuine competitive advantage to protect, that is not an acceptable trade-off.

Speak with our team about exploring Citadel in your environment. Book a 30-minute discovery meeting.

Speak with our team about exploring Citadel in your environment. Book a 30-minute discovery meeting.
Frequently Asked Questions
Frequently Asked Questions
The product
Security & compliance
Getting started
What exactly is Citadel?
Citadel is a branded, on-premise AI infrastructure unit, physical hardware installed inside your premises, running a fully managed LLM orchestration stack. It allows your team to run up to five AI models simultaneously without any data leaving your environment. Timbi delivers the hardware, configures the software, trains the models to your organisation's workflows, and maintains the entire system. You get enterprise-grade AI capability with complete data sovereignty.
How is Citadel different from Claude, Chat GPT or any other AI cloud provider?
When you use a cloud AI provider, every prompt, document, and piece of code you send leaves your infrastructure and enters a system you do not control or audit. Citadel runs entirely inside your building. Nothing you process is transmitted externally. The difference is not just technical, it is a fundamentally different risk posture. Citadel is for organisations that cannot afford to treat data security as a terms-of-service question.
Why to run up to 5 models simultaneusly?
Different LLMs excel at different tasks, one may be stronger at legal reasoning, another at code generation, another at summarisation. Running multiple models in parallel and routing queries intelligently means you always get the best output for each task, rather than accepting the limitations of a single model. It also eliminates dependency on any one provider and future-proofs your deployment as models evolve.
Can the model be trained on my own data?
Yes, and this is one of Citadel's most valuable features. Models are fine-tuned on your organisation's specific prompts, documents, workflows, and terminology, so Citadel develops a deep understanding of how your company thinks and operates over time. All training happens on your hardware. Your data never leaves the building at any point in the training process.
What is the P2P VPN and why does it matter?
When users need to access Citadel from outside the office, their connection runs through a custom peer-to-peer VPN configured specifically for your organisation. This allows authorised team members to connect securely without exposing Citadel directly to the public internet. There are no open public endpoints, and external access is protected through a private network layer managed by Timbi. The VPN is set up by Timbi as part of the deployment and maintained as part of your service agreement.
Is Citadel compliant with GDPR and the EU AI Act?
Yes. Because all data processing happens on your own infrastructure, you retain full control as data controller at all times, there is no third-party data processor involved in your AI operations. Citadel's AI components fall within the limited-risk category under the EU AI Act. All model outputs are explainable and auditable. Full compliance documentation is available for procurement or legal review on request.
What happens if the hardware fails?
Hardware maintenance and replacement is covered under your service agreement. Timbi provides remote diagnostics as standard and on-site support based on your tier. Enterprise clients have a dedicated SLA with guaranteed response and resolution times. In the event of a hardware failure, your data remains intact within your infrastructure, there is no dependency on any external system to recover.
Do you specialize in any particular areas?
Absolutely. In fact, many of our most successful projects are built on close collaboration with internal R&D, data science, or innovation units. We integrate seamlessly, offering fresh perspectives while respecting existing knowledge and workflows. Our role is to complement, not replace.
Citadel is currently in pilot, what does it mean?
Citadel is accepting a select number of pilot organisations ahead of its full commercial launch. Pilot partners receive a fully deployed and operational Citadel unit in exchange for structured feedback on performance, usability, and integration. Pilots are prioritised for organisations in regulated industries (legal, engineering, pharma, defence, fintech) where data sovereignty is a hard requirement. Pilot terms are agreed individually based on infrastructure requirements and deployment complexity.
How long does the deployment take and what does it involve?
From contract or pilot agreement to a fully operational system, deployment typically takes four to six weeks. This covers hardware shipping and installation, P2P VPN configuration, initial model setup and configuration, and a handover session with your team. Organisations with complex infrastructure or multi-site requirements are scoped individually during the initial consultation.
The product
Security & compliance
Getting started
What exactly is Citadel?
Citadel is a branded, on-premise AI infrastructure unit, physical hardware installed inside your premises, running a fully managed LLM orchestration stack. It allows your team to run up to five AI models simultaneously without any data leaving your environment. Timbi delivers the hardware, configures the software, trains the models to your organisation's workflows, and maintains the entire system. You get enterprise-grade AI capability with complete data sovereignty.
How is Citadel different from Claude, Chat GPT or any other AI cloud provider?
When you use a cloud AI provider, every prompt, document, and piece of code you send leaves your infrastructure and enters a system you do not control or audit. Citadel runs entirely inside your building. Nothing you process is transmitted externally. The difference is not just technical, it is a fundamentally different risk posture. Citadel is for organisations that cannot afford to treat data security as a terms-of-service question.
Why to run up to 5 models simultaneusly?
Different LLMs excel at different tasks, one may be stronger at legal reasoning, another at code generation, another at summarisation. Running multiple models in parallel and routing queries intelligently means you always get the best output for each task, rather than accepting the limitations of a single model. It also eliminates dependency on any one provider and future-proofs your deployment as models evolve.
Can the model be trained on my own data?
Yes, and this is one of Citadel's most valuable features. Models are fine-tuned on your organisation's specific prompts, documents, workflows, and terminology, so Citadel develops a deep understanding of how your company thinks and operates over time. All training happens on your hardware. Your data never leaves the building at any point in the training process.
What is the P2P VPN and why does it matter?
When users need to access Citadel from outside the office, their connection runs through a custom peer-to-peer VPN configured specifically for your organisation. This allows authorised team members to connect securely without exposing Citadel directly to the public internet. There are no open public endpoints, and external access is protected through a private network layer managed by Timbi. The VPN is set up by Timbi as part of the deployment and maintained as part of your service agreement.
Is Citadel compliant with GDPR and the EU AI Act?
Yes. Because all data processing happens on your own infrastructure, you retain full control as data controller at all times, there is no third-party data processor involved in your AI operations. Citadel's AI components fall within the limited-risk category under the EU AI Act. All model outputs are explainable and auditable. Full compliance documentation is available for procurement or legal review on request.
What happens if the hardware fails?
Hardware maintenance and replacement is covered under your service agreement. Timbi provides remote diagnostics as standard and on-site support based on your tier. Enterprise clients have a dedicated SLA with guaranteed response and resolution times. In the event of a hardware failure, your data remains intact within your infrastructure, there is no dependency on any external system to recover.
Do you specialize in any particular areas?
Absolutely. In fact, many of our most successful projects are built on close collaboration with internal R&D, data science, or innovation units. We integrate seamlessly, offering fresh perspectives while respecting existing knowledge and workflows. Our role is to complement, not replace.
Citadel is currently in pilot, what does it mean?
Citadel is accepting a select number of pilot organisations ahead of its full commercial launch. Pilot partners receive a fully deployed and operational Citadel unit in exchange for structured feedback on performance, usability, and integration. Pilots are prioritised for organisations in regulated industries (legal, engineering, pharma, defence, fintech) where data sovereignty is a hard requirement. Pilot terms are agreed individually based on infrastructure requirements and deployment complexity.
How long does the deployment take and what does it involve?
From contract or pilot agreement to a fully operational system, deployment typically takes four to six weeks. This covers hardware shipping and installation, P2P VPN configuration, initial model setup and configuration, and a handover session with your team. Organisations with complex infrastructure or multi-site requirements are scoped individually during the initial consultation.