AI Cube processes models and knowledge in your controlled environment. Data paths, permissions and operations are documented; in managed operations, the people involved accept a written secrecy obligation.
Companies worldwide trust WZ-IT
External AI services process client, patient or other confidential data through additional involved parties.
A DPA addresses the GDPR layer but does not alone settle necessity, secrecy obligations and the access chain under §203.
Models, knowledge sources, logs, backups and remote maintenance together form the actual data path.
In a managed service, contributing persons and any further participants must also be effectively bound to secrecy.
We configure and operate AI Cube for the agreed GDPR and Section 203 scope. This includes controlled data paths, limited permissions, documented maintenance, the appropriate DPA and written secrecy obligations for the people involved. Legal evaluation of the specific use remains with the controller and its advisers.
§203 StGB protects confidential information entrusted by clients, patients and other parties. The necessary involvement of contributing persons is permitted. What matters is that access is limited to what is necessary, the people involved are bound to secrecy and the complete data and maintenance path is controlled.
With public AI services, inputs and documents leave your own infrastructure. Whether a service is suitable in a specific case therefore depends not only on a DPA, but also on data flows, subprocessors, access permissions and the actual use.
On-premises inference, local vector search and internally operated interfaces keep technical processing in your controlled environment. This reduces external data paths and subprocessors and allows access to be limited precisely.
When we provide setup or operations as a contributing person, the people involved accept a written secrecy obligation and are instructed about the criminal consequences. Where personal data is involved, this is combined with a DPA, limited administrative rights and documented maintenance paths.
These technical and contractual building blocks form part of the agreed §203 scope:
Data-protection layer
Secrecy and instruction on criminal consequences
necessary rights, logging and controlled paths
This content is general information and not legal or tax advice. The specific implementation under §203 must be reviewed professionally on a case-by-case basis.
The local AI platform brings AI chat, knowledge spaces and local models into your network. It is configured for the agreed GDPR and §203 framework; professional-software integrations remain a clearly scoped integration service.

Delivered ready to use within 10 working days
€6,490 excl. VAT one-time
Device, setup, briefing and shipping
€349.90 excl. VAT / month
AI Cube Care · first year accompanied, then cancellable monthly
RAG, data sources, integrations, secure connectivity and custom workflows are scoped separately.
AI Cube Care keeps the device running: a monthly maintenance window, tested model updates with a rollback path, round-the-clock monitoring, ticket support and warranty handling. For confidentiality professionals we add a data processing agreement under Art. 28 GDPR and the written secrecy obligation under Section 203 (4) of the German Criminal Code, including instruction on the criminal consequences; on request remote access stays switched off by default.
Confidentiality norm, use cases and professional-software integration - profession-specific.
§203 · Case data · RAG
Case-law research, draft pleadings and case knowledge with local AI configured for a defined Section 203 scope.
Learn more§203 · DATEV · Client data
Process documents, correspondence and firm knowledge with local AI configured for a defined Section 203 scope.
Learn more§203 · Patient data · PMS
Practice knowledge, drafts and documentation with local models in the practice network.
Learn more§203 · HIS · air-gapped
Doctor's letters, tumour board, coding at volume - air-gapped in your own data centre.
Learn more§203 · Therapy data · local
Drafts, professional research and internal knowledge with local models in the practice.
Learn more§203 · Deeds · RAG
Deed drafts and register-law research - party data stays in the office.
Learn more§203 · Working papers · RAG
Working papers, IDW PS research, report drafts - client figures stay in-house.
Learn moreSovereign AI is a lifecycle, not a device purchase - and everything stays on your infrastructure.
Workshop, sizing, data classification and §203 contract framework. We understand your stack, professional software and compliance requirements before we recommend.
On-premise build on your hardware, RAG on your documents with access control, integration into your professional software, secrecy obligation + DPA.
Updates, monitoring, model upgrades and RAG maintenance as a service contract - or you operate fully yourself. Handover and knowledge transfer included.
From hardware and inference through RAG and integration to operations and security - no interface ping-pong between advice, build and operations.
On-premise deployment at your site; external integrations, updates and remote access are configured deliberately and documented.
Ollama, vLLM, Open WebUI, Qdrant - operable internally, no vendor lock-in.
DPA, written secrecy obligation and instruction of contributing persons about the criminal consequences.
For professional secrecy holders
In addition to local AI, WZ-IT can operate the related portals, open-source applications, Supabase backends and custom services in a managed cloud designed for professional secrecy holders.
Enquiry
Describe the workflow and data that should be processed locally or in a controlled environment.
Answers to the most important questions
Yes. Section 203(3) StGB permits the necessary involvement of other contributing persons. The specific use needs controlled data paths, an effective secrecy obligation and the other data-protection and profession-specific requirements.
A DPA is an important part of the GDPR layer. For secrets under §203, necessity, involved persons, secrecy obligations, access rights and further providers must also be assessed.
The organisation must define which data may be processed, who receives access and how service providers are involved within the §203 framework.
Server location is only one criterion. Provider identity, subprocessors, access rights, third-country transfers, contracts and the actual processing also matter.
AI Cube costs EUR 6,490 excluding VAT as a one-time purchase for the 1 TB version, plus AI Cube Care at EUR 349.90 excluding VAT per month; the first twelve months run with the device, cancellable monthly after that. Hardware, hardening, an agreed local model, monitoring, updates and support are included. Larger deployments are quoted per project.
A fully local or isolated deployment can be configured. Updates, external models, web search and remote maintenance are then unavailable or require controlled transfer procedures.
Common open-source LLMs (Llama, Qwen, Mistral, Gemma) on NVIDIA hardware - from the AI Cube as a GB10 appliance for a single practice to an RTX GPU server for larger institutions. No vendor lock-in.
We document data paths, roles, technical safeguards and operating responsibility. For a §203 scope, the people involved accept a written secrecy obligation and are instructed about the criminal consequences; an appropriate DPA is added where personal data is processed.
From local AI integration to architecture, data sovereignty and ongoing operations.
“WZ-IT moved our studio infrastructure from decentralised individual devices to a central platform: every site is securely connected via VPN, new devices are onboarded automatically and an entire site is provisioned from a template, without manual steps on location. What impressed me most is the breadth and depth of their knowledge: Timo and Robin are not a typical IT provider who sets up a server and leaves. The two of them think their way into highly complex infrastructure and software topics, work through every requirement we put in front of them, and build networking, provisioning and operations so that everything fits together in the end. WZ-IT is an excellent partner for complex software, network and architecture projects.”

Steve Kirchner
Managing Director, nextGYM GmbH

No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.