Questions

Frequently asked questions

Straight answers about deployment, security, cost, and how we work — including the things we will not do.

Positioning

What exactly does Sigmatic Labs do?

We implement enterprise AI systems. Architecture, infrastructure, integration, security, and operations — from assessment through production and ongoing operation. We are an engineering firm, not a strategy consultancy or an agency.

Are you an AI agency?

No. We do not produce AI-generated content, images, or marketing material. We build production software systems.

Do you build chatbots?

A conversational interface is occasionally the right front end for a system we build. It is never the project. Most of our work is retrieval systems, agents, and AI integrated into existing enterprise workflows — much of it with no chat interface at all.

Do you resell models or platforms?

No. We hold no reseller agreements and take no vendor commissions. It is the only way our architecture recommendations are worth anything.

How are you different from a large systems integrator?

Scale and incentive. We staff small senior teams — the architects who design the system build it. And because we have no platform to sell, we can recommend against a technology without it costing us anything.

Deployment & architecture

What is "private AI"?

AI systems where inference runs on infrastructure you control and your data never reaches a third-party processor. Four boundaries have to hold: network, storage, identity, and telemetry. A deployment that satisfies three of four is not private.

Can you deploy in a fully air-gapped environment?

Yes. Air-gapped deployment changes model update logistics, monitoring, and dependency management significantly — those are engineering problems with known solutions, and they need to be designed for from the start rather than retrofitted.

Are open models good enough for enterprise work?

For retrieval, extraction, classification, summarization, and most agentic workflows, yes. For the hardest reasoning tasks, frontier models still lead. We evaluate against your actual workload rather than against benchmarks, because benchmark rank rarely predicts performance on a specific enterprise task.

Do we need to buy GPUs?

Not necessarily. Options include reserved cloud GPU capacity in your tenant, colocated hardware, or existing on-premise capacity. We model the options — purchase is one outcome, not the assumption.

Do you work in cloud environments?

Yes, regularly — Azure OpenAI, Bedrock, Vertex, and hyperscaler infrastructure. Private deployment is our specialty because it is where clients are most stuck, not because it is always the answer.

Security & compliance

How do you ensure our data is not exposed?

On a private deployment, architecturally: there is no external processor in the data path. We document the controls enforcing each boundary and produce the evidence your security team and auditors require.

Is our data used to train models?

No. On a private deployment there is no third party with access to train on. Where a managed API is used, we configure and verify no-retention and no-training terms and document them.

How do you handle prompt injection?

Architecturally, not by prompt engineering. Treat retrieved content as untrusted input, constrain tool access with least privilege, gate consequential actions, enforce entitlements at the retrieval layer, and test adversarially before release. Defenses that live entirely in the system prompt are not defenses.

Which compliance frameworks do you work under?

We align AI governance to NIST AI RMF and ISO/IEC 42001, and design to the sector frameworks our clients operate under — HIPAA, HITRUST, GLBA, SR 11-7, CMMC 2.0, NIST SP 800-171, ITAR, FedRAMP, and CJIS among them.

Will you sign an NDA or BAA?

Yes to an NDA, before any detailed technical discussion. We will also sign a BAA where PHI is in scope.

Engagement & cost

How do engagements start?

Almost always with an AI Readiness Assessment. It is fixed-fee, time-boxed, and produces a roadmap you own — executable by us, by another firm, or by your own team.

What does an implementation cost?

It depends on deployment model, integration surface, and security requirements. We provide a fixed-fee assessment first precisely so the implementation estimate is grounded in your actual environment rather than in assumptions.

How long from assessment to production?

For a scoped first use case, it depends on data readiness, integration complexity, and your security review timelines. Security review is the most frequently underestimated component, and we plan around it rather than discovering it.

Do you operate systems after launch?

Yes. Ongoing LLMOps and operations, or a structured handover to your team with runbooks and training. Both are legitimate outcomes; we will recommend which fits your staffing.

Do you do staff augmentation?

No. We scope engagements to outcomes with defined artifacts and acceptance criteria.

What we will not do

We do not resell models or platforms, and we take no vendor commissions. We do not run pilots with no path to production. We do not do staff augmentation. We are not an AI content agency and we do not build chatbots as a product.

We will tell you when a managed API is the right answer, and we have.

Question not answered here?

An engineer reads every enquiry — this is not a sales queue. Typically a response within one business day.

We will sign your NDA before a detailed technical discussion.