# Lenouar: full site content > Private AI systems for regulated organizations that need localized intelligence, controlled workflows, auditability, and data that stays under their authority. Canonical site: https://lenouar.ae Link index: https://lenouar.ae/llms.txt Contact: https://lenouar.ae/en/contact/sales | services@lenouar.ae Location: Abu Dhabi, United Arab Emirates Last updated: 2026-07-17 # Company overview Lenouar builds private, on-premise AI systems with localized intelligence, controlled workflows, auditability, and data that stays under your authority. Your own AI. Inside your walls. Lenouar builds private, agentic AI systems for regulated organizations, with localized intelligence, compliance-native workflows, and turnkey deployment so your data never has to leave. AI isn't just about models. It's about control. Most AI tools send your most sensitive data to someone else's cloud, under someone else's jurisdiction. Lenouar keeps it inside your walls as private intelligence you own, govern, and audit end to end. - It starts with your own node.: A private AI node, the AI Appliance, deployed on-premise or in your private UAE environment with localized models and your knowledge base built in. - Put AI to work, under control.: Agents and copilots that run inside your operations with human checkpoints at every step, connected to the systems your teams already use. - Compliance, built in from the start.: Turn regulatory requirements and internal governance into working controls: evidence capture, audit trails, and risk handling that stand up to inspection. - Localized open models served with vLLM: Localized open models served with vLLM, on your own hardware, with no external API calls. - Tenant isolation, RBAC, and full audit logging: Tenant isolation, role-based access control, and a full audit trail of every request. - Hybrid deployment: Hybrid: local for sensitive tasks, cloud for heavy reasoning. You decide what runs where. # Core offerings ## Private AI Infrastructure https://lenouar.ae/en/private-ai-infrastructure On-premise AI infrastructure, private AI nodes, localized models, and source-traceable retrieval for organizations that need data to stay under their authority. Your own AI node. Inside your walls. A private AI node with localized models and your knowledge base, deployed on-premise or in your private cloud, so sensitive data never has to leave your network. Built with: vLLM, Llama, Mistral, Qwen, Gemma, DeepSeek, Phi, Hugging Face, Ollama, SGLang ### Open models, served on your hardware. We run localized open models with vLLM on the appliance, tuned for your languages and domain. Your prompts and documents are processed locally, with no external API calls. - Llama-family and other open models - An OpenAI-compatible endpoint for your apps - Nothing leaves your network ### Your knowledge, searchable and private. Connect internal documents, policies, and evidence so the system answers with source-traceable retrieval, all inside your perimeter. - Private RAG over your own documents - Source-traceable answers - Access scoped by role ### Enterprise-grade, on your infrastructure. The engineering rigour of the cloud giants, running inside your perimeter, on hardware you control. - Tenant isolation and RBAC: Strict isolation and role-based access control across every workspace and request. - Full audit logging: A complete, immutable trail of every request, ready for inspection. - Hybrid by design: Local for sensitive tasks, cloud for heavy reasoning. You decide what runs where. ### Hardware, models, and stack. Installed and supported. We supply and install the appliance on your premises, configure the model and retrieval layers, connect your systems, and support the operating system over time. - AI Node: A compact desktop-class private AI appliance for a single department or site, installed on your premises. - AI Rack: A rackmount GPU server-class appliance for organization-wide private AI, with room to scale. - Compute: 2x data-center GPUs (L40S / A100 class). - Models: Open models up to ~70B parameters. - Throughput: Around 1,200 tokens per second. - Deployment: On-premise, installed in days. ### Designed to stay in your control. - 100% On-premise deployment option - 0 External API calls for local inference - 4 Languages supported ## AI Workforce Platform https://lenouar.ae/en/ai-workforce Private AI agents, internal copilots, controlled automation, human approval gates, and audit-ready workflows connected to the systems your teams already use. An AI workforce that works inside your walls. Agents and copilots that run on your private node, connected to the systems your teams already use, with a human checkpoint at every consequential step. Nothing leaves your network. Built with: Email, SharePoint, Microsoft Teams, Slack, Google Drive, Salesforce, Jira, Confluence, ServiceNow, REST APIs ### From trigger to outcome, on autopilot. Your agents watch for the events that matter, do the work, and pause for a human before anything consequential happens. Every step is logged inside your perimeter. ### Copilots that know how your organization works. Grounded in your private knowledge base and connected to your systems, copilots answer with source-traceable retrieval and act only within the limits their role allows. - Answers traced back to your own documents - Connected to the apps and APIs your teams use - Access scoped by role, never beyond it ### See every action as it happens. Fine-grained, event-level visibility into what your agents do, who approved it, and what they touched. All captured inside your perimeter. ### Autonomy with a human in the loop. Agents move fast, but they never act past their authority. You decide what runs automatically and what waits for a person. - Approval gates: Every consequential action pauses for human sign-off before it runs. - Full audit trail: Every prompt, action, and decision is logged immutably and ready for review. - Role-based access: Agents and people see only what their role permits, and nothing more. ### Your workforce runs on your node, not someone else's cloud. Local models handle sensitive and always-on work inside your network. Heavy reasoning can burst to the cloud only when you allow it. You decide what runs where. ### Built to compound, safely. - 24/7 Always-on agents on your node - 100% Actions captured in your audit trail - 0 Sensitive data sent to third parties ## Compliance Intelligence https://lenouar.ae/en/compliance-intelligence AI governance, audit trails, evidence capture, control monitoring, and compliance-ready workflows that run on private infrastructure. Compliance that proves itself. Turn the requirements you answer to into working controls, with evidence captured automatically and an audit trail that is ready the day an inspector asks. All on your private node. Built with: ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, PCI DSS, UAE PDPL, ADHICS, CIS Controls, COBIT ### Turn requirements into working controls. Translate the obligations you carry into control-driven workflows that actually run, with ownership, due dates, and exceptions tracked in one place. - Control-driven workflows mapped to your frameworks - Ownership, due dates, and sign-off built in - Risk, exception, and CAPA handling in one place ### Everything you need to prove, in one control plane. Stop assembling compliance the week before an audit. Make it a property of how the system runs every day. - Control mapping: Map one piece of evidence to every framework it satisfies, automatically. - Automated evidence: Pull evidence from your systems on a schedule. No manual screenshots, no spreadsheets. - Continuous monitoring: Watch controls in real time and surface gaps before an audit, not after. ### Evidence that assembles itself. Connect a system once, and the layer collects the right evidence on a schedule, maps it to the controls it satisfies, and keeps an export pack ready for any auditor. - Scheduled collection from your connected systems - One artifact mapped to every control it satisfies - Inspection-ready export packs in a click ### Know where you stand, in real time. Continuous control monitoring across your controls, evidence, and findings. Always current, always inside your perimeter. ### Pulls evidence from the systems you already run. Connect your identity, ticketing, document, and infrastructure systems so evidence collects itself, all inside your perimeter and under your control. ## AI Appliances: On-Premise Private AI Hardware https://lenouar.ae/en/appliance AI appliances for private inference, on-premise deployment, localized models, private retrieval, and audit logging, installed and supported over time. Your private AI, in a box you control. Approved AI appliances, preloaded with localized models, private retrieval, and audit logging. We install them on your premises and support them over time, so your data never has to leave your network. Built with: NVIDIA, ASUS, Dell, HPE, Supermicro, Lenovo, Gigabyte, Intel, AMD, ASRock ### Choose the appliance that fits your footprint. Every appliance ships preloaded with the same private AI stack: localized models, private retrieval, tenant isolation, and audit logging. Pick the size that matches your site, and we install and support it. - AI Mini: A desk-sized appliance with unified CPU and GPU memory, for a single team, clinic or practice that needs private AI without a server room. - AI Studio: A desk-side workstation appliance for a department running several models at once, with room to grow before you move to a rack. - Compute: Unified CPU and GPU memory in a desktop chassis. - Models: Open models up to ~70B, served without quantization. - Footprint: Desk-sized. Sits in an office, not a server room. - Power: Standard office power and cooling. No rack, no raised floor. - AI Node: A compact desktop-class private AI appliance for a single department or site, installed on your premises. - AI Rack: A rackmount GPU server-class appliance for organization-wide private AI, with room to scale. - Compute: 2x data-center GPUs (L40S / A100 class). - Models: Open models up to ~70B parameters. - Throughput: Around 1,200 tokens per second. - Deployment: On-premise, installed in days. - AI Edge: An ultra-compact appliance for a single room, clinic, or branch office, where space and power are tight. - AI Cluster: A multi-node cluster for organization-wide private AI across departments and sites, with room to grow. - Compute: From a single GPU to multi-node clusters. - Footprint: Desk-side, rackmount, or full cabinet. - Capacity: From one team to the whole organization. - Support: Installed, monitored, and maintained by us. ## Forward Deployed Engineering https://lenouar.ae/en/forward-deployed-engineering We install, integrate and operate your private AI system inside your own environment. Forward deployed engineering for regulated organizations in the UAE. We don't hand over software. We make it work. Forward deployed engineering: we work inside your environment to install the stack, connect your systems, configure the workflows, and validate the audit trail before anyone calls it live. ### Most AI projects do not fail at the model. They fail in the distance between a working demo and a system your team actually uses, that your assessors accept, and that still runs the week the person who built it goes on leave. That distance is where we work. ### Inside your environment, not around it. Forward deployment means the engineering happens where the problem is: on your network, against your real documents, under your permissions model, alongside the people who will use the system every day. - Your document formats, not a clean sample set. Real scans, real templates, real inconsistency. - Your permissions model, enforced at query time, so retrieval cannot surface what a user was never entitled to open. - Your systems, connected directly: EHR, ERP, document stores and internal APIs. - Your reviewers in the loop, with checkpoints on anything carrying legal or clinical consequence. - Your audit trail, validated against the standards you are actually assessed against. ### Six stages, in order. Every deployment runs the same path. Installation is measured in days because the stack ships preconfigured. The stages that take real time are integration and validation, which is where deployments succeed or fail. - Scope: We map the workloads, data classes and language mix, and size the deployment against your real utilisation rather than a launch-week forecast. - Install: Deployment on your own infrastructure and your own network, on premises or in your private cloud. - Connect: Integration with the systems you already run, so the system reads from where your work actually lives instead of from a copy of it. - Configure: Retrieval scope, permissions, workflows and human checkpoints, tuned to how your teams operate rather than to a default template. - Validate: We confirm the audit trail answers the questions an assessor will ask, before handover rather than after the finding. - Operate: Monitoring, maintenance, patching and model lifecycle continue after go-live. Owning the system should not mean inheriting an operations problem. ### What forward deployment is not. The term gets used loosely, so it is worth being precise about what you are and are not buying. - Not staff augmentation. We are not filling seats on your org chart or taking day-to-day direction as contractors. - Not a body shop. The engagement is scoped to a deployment outcome, not to a monthly headcount. - Not a replacement for your IT function. We work alongside your team and hand over a system they can hold. - Not an open-ended retainer. Every stage has an exit criterion and a definition of done. ### When forward deployment is the right call. It fits when the constraints are real and the workload is operational. It does not fit when you mainly need a software licence and already have the platform team to run it yourself, and we will say so during scoping rather than after the purchase order. - Regulated data: Your data class cannot move freely, so the system has to come to the data rather than the other way around. - Document-heavy operations: The value sits in documents, records and repeatable workflows rather than in open-ended reasoning. - No platform team to spare: You need the system running without first hiring an inference infrastructure capability to support it. ## Almanexa: Decision Memory Engine by Lenouar https://lenouar.ae/en/almanexa Almanexa is the decision memory engine built by Lenouar. Turn what your organization has decided and learned into proven experience you own, use to ground your own agents and models, and can share with your peers. Your most valuable data is already inside your company. Almanexa turns the decisions your teams and AI systems make, and what actually happened next, into proven experience your organization owns. Reuse it internally, ground your own agents in it, and offer it to your peers if you choose. ### Models learned from the public web. The public web is running out. Scraped text tells you what somebody wrote. Your record tells you what was decided, what result was expected before anyone knew the answer, what actually happened, and who stood behind the conclusion. That verification is the part nobody can scrape, and your organization already produces it every day. ### A document is an assertion. A lesson carries its evidence. Shared knowledge bases have been tried for decades and mostly gather dust, because a document only tells you what someone believed when they wrote it, with nothing attached to say whether they turned out to be right. - The expected outcome is recorded before the result is known, so history cannot be rewritten. - When reality answers, the prediction is graded against it. Misses teach as much as wins. - What holds up becomes a lesson only after a person approves it, and the approver cannot be the author. - Answers are grounded only in approved lessons, with citations back to what supports them. - Every governance action lands on a tamper-evident, signed record you can show an auditor. ### Three things your own experience makes possible. Recording decisions is the mechanism. These are the reasons to bother. - Agents that earn their autonomy: Your agent asks before acting, receives approved lessons with their sources, and everything it decides is graded. Its own track record decides where it may act alone. You set the bar, and the evidence that it was cleared sits on the record. - Models tuned on proof, not scraped text: Real decisions, expectations recorded before outcomes, measured results and a named sign-off. That is the shape model builders prize most, and your organization owns it. Whether it is ever used that way is your decision, and the default is that it is not. - Experience that travels between peers: An approved lesson can be packaged, signed with your own key, and offered on the Almanexa Hub, free or priced, as you choose. The lesson travels. The data behind it never does. ### A new team can open at year five instead of zero. Walk any sector and you will find the same lesson being bought over and over, at full price, eighteen months apart. Nothing about it was secret and nobody was hiding it. There was simply no way for it to travel. - What leaves your organization is the approved lesson: what was learned, the conditions it applies to, and the evidence that it held. - What never leaves is everything behind it. The decisions, the numbers, the case files, the customer records, the names. - A new organization installs what its peers have validated, then makes its own decisions with that experience in the room rather than an empty one. - Members that install also publish, so lessons that survive more contexts get stronger, and lessons that stop holding get retired instead of quietly misleading someone. ### The record is yours, and it stays that way. None of this works if the ownership is ambiguous, so it is not. Almanexa is a Lenouar product and deploys the way everything else we build deploys: inside your environment, under your keys. - It lives in your environment: Runs on your own infrastructure, encrypted, with each tenant isolated. Arabic-first with full right-to-left support, built in Abu Dhabi. - Organizational use by default: A standard published pack grants another member the right to apply what you learned, and nothing more. - Training rights only if you grant them: A publisher may explicitly grant model-training rights on an offer, priced separately and recorded in the signed license. The default is always no. ### The product has its own home. Almanexa is its own brand on its own domain, with the full product story, the pricing tiers and the source-available core. Lenouar builds it and stands behind it. ## Private AI Integrations https://lenouar.ae/en/integrations Connect EHR, ERP, document stores, collaboration tools, payment systems, CRM platforms, and internal APIs to private AI workflows with scoped access and audit trails. Connect the systems you already run. Pull from and push to your EHR, ERP, document stores, and internal APIs, so your private AI works with your real data. Every connection runs inside your perimeter. ### Every connector, in one place. Browse the systems your private AI can read from and write to, all running inside your perimeter. - SharePoint: Index documents and policies for private retrieval. - Google Drive: Sync and search files across shared drives, privately. - Confluence: Ground answers in your internal wiki and runbooks. - Microsoft 365: Index Word, Excel, and OneDrive content for retrieval. - Better Auth: Track sign-up and auth events from your own app. - Supabase: Connect Supabase Auth users and sessions to your node. - Clerk: Sync identities and sessions from Clerk-managed auth. - REST APIs: Connect any internal system over a secure REST endpoint. - Webhooks: Stream events to and from your node in real time. - Data warehouse: Export structured records to your own warehouse. - Email: Read and send mail, and turn threads into tracked work. - Microsoft Teams: Post notifications and let teams act without leaving chat. - Slack: Get alerts and approvals where your team already works. - Jira: Create, triage, and update issues with human approval. - ServiceNow: Handle cases and records inside your service desk. - Stripe: Track payments and reconcile transactions against your records. - Razorpay: Sync orders and settlements for South Asia and the GCC. - Telr: UAE payment gateway for cards and local methods. - PayTabs: MENA gateway for online and recurring payments. - N-Genius: Network International gateway for UAE merchants. - Amazon Payment Services: Regional acquiring (formerly PayFort) across MENA. - Tap Payments: GCC-wide payments with local methods like KNET. - Ziina: UAE-licensed payments for fast local collection. - Make.com: Connect your node to 2,000+ apps with no-code scenarios. - n8n: Self-hosted workflow automation that runs inside your network. - Power Automate: Automate flows across the Microsoft ecosystem. - Salesforce: Read and update accounts, contacts, and opportunities. - HubSpot: Sync contacts, deals, and tickets with your workflows. ### Integrations that never leave your perimeter. Connectors run on your node with credentials scoped to exactly what they need. Nothing is brokered through an outside cloud, and every sync is logged. - Syncs execute inside your network - Least-privilege, scoped credentials - Every read and write captured in your audit trail ### A connector for every layer of your stack. Read and write where it matters, with scoped credentials and a logged trail for every sync. - Identity and access: Sync users and roles from your directory so access stays in lockstep with HR. - Documents and storage: Index files from SharePoint, Drive, and object storage for private retrieval. - Tickets and workflow: Read and update tickets, cases, and records in the service tools you already use. ### Connected, without the exposure. # Solutions ## Legal document copilot for confidential review work. https://lenouar.ae/en/solutions/legal-document-copilot A private AI workspace for contracts, policies, memos, case files, and legal archives, built with source traceability, reviewer checkpoints, and controlled deployment options. ### Legal review without data exposure Legal teams need AI for speed, but their documents are often privileged, confidential, or politically sensitive. Lenouar builds a **private legal document copilot** that runs inside the approved client environment. The system helps lawyers and reviewers work faster without turning sensitive files into public AI prompts. > The core promise is controlled augmentation: faster legal work, with the client still controlling data, access, sources, and review. ### Contract analysis and clause extraction The copilot can assist with repetitive document review tasks that usually consume senior legal time. ### High-value review tasks - Extract parties, dates, governing law, obligations, renewal terms, penalties, and missing fields. - Compare two agreement versions and highlight material changes. - Identify unusual clauses against internal playbooks. - Draft first-pass summaries, risk notes, and review checklists. - Build matter briefs from multiple documents with source links. Outputs are designed for review, not blind automation. ### Private legal knowledge search A useful legal copilot must know the organization's own material, not only general legal language. ### Sources it can search - Contract templates and clause libraries. - Prior legal opinions and approved response language. - Internal policies, delegations, and approval matrices. - Government correspondence and matter archives. - Regulatory notes, circulars, and interpretation memos. Every answer should point back to the source material that produced it. ### Human approval and matter controls Legal AI needs permission boundaries. Lenouar structures the copilot around the way legal teams actually work. ### Controls to define before launch 1. Which matters, teams, and document classes each user can access. 2. Which outputs require legal approval before use. 3. Which actions are allowed, blocked, or logged only. 4. How source citations, prompts, and reviewer decisions are retained. This keeps the system useful without making it operationally reckless. ### Deployment for government and enterprise legal teams Legal teams can deploy the copilot in different ways depending on sensitivity and scale. ### Deployment options - **Private node:** best for a contained department pilot or one legal team. - **Rack deployment:** best for high-volume archives, many users, and production-grade throughput. - **UAE-hosted model routing:** useful when the client wants local/national model infrastructure. - **Hybrid mode:** local retrieval, ingestion, redaction, and audit, with selected reasoning routed only when approved. This lets the client start small and scale without changing the operating model. ### Pilot plan for a legal copilot A strong pilot should be narrow enough to measure and sensitive enough to prove why private AI matters. ### Recommended first pilot 1. Pick one workflow, such as contract review, policy Q&A, or legal archive search. 2. Index a controlled document set with known owners. 3. Define accuracy, citation, and review requirements. 4. Test with a small legal team for 4 to 8 weeks. 5. Decide whether to scale to a department workspace, a rack deployment, or a hybrid government-grade setup. ## Healthcare compliance intelligence for ISO and internal controls. https://lenouar.ae/en/solutions/healthcare-compliance A private AI layer for healthcare policies, evidence, remediation, and audit readiness, built for clinics, hospitals, and medical groups that cannot expose sensitive data. ### Healthcare compliance and AI readiness Healthcare teams want AI, but they also answer to patient-data sensitivity, regulatory expectations, internal policies, audit evidence, and operational risk. Lenouar helps healthcare organizations deploy AI as a controlled compliance workflow, not as a loose chatbot. The system can keep documents, prompts, evidence, and audit history inside the approved environment. ### Evidence management for audits Audit preparation usually breaks down because evidence is scattered across teams, folders, tools, and email. ### The compliance layer can help teams - Map requirements to owners and evidence. - Search policies, SOPs, controls, and prior audit material. - Draft evidence summaries with source references. - Identify missing or stale documentation. - Prepare internal audit packs for review. This is designed to reduce last-minute audit pressure and improve consistency. ### Policy, SOP, and control search Staff should be able to ask controlled questions against approved internal material. ### Example questions - Which SOP applies to this incident type? - What evidence is required for this control? - Which policy owner should review this exception? - What changed between the current policy and the previous version? - Which open remediation tasks affect this department? Answers can be limited by role and backed by source links. ### Incident, CAPA, and remediation workflows Healthcare compliance is not only search. It is follow-through. Lenouar can connect AI assistance to incident notes, CAPA drafts, evidence requests, remediation owners, and approval steps. The system can prepare the work, but humans remain responsible for decisions and sign-off. ### Useful workflow outputs - CAPA draft with source context. - Remediation checklist. - Control owner task list. - Evidence request summary. - Management reporting note. ### Private deployment for patient-data-sensitive environments Healthcare deployments can run on a private node, private cloud, rack server, or hybrid model. The local layer can handle retrieval, embeddings, indexing, redaction, audit logging, and routine AI tasks. If external or UAE-hosted model routing is allowed, Lenouar can enforce routing rules so sensitive data is handled according to the agreed policy. ### Healthcare compliance pilot scope A practical first deployment should focus on one compliance domain. ### Recommended starting points 1. Regulatory readiness evidence map. 2. Internal policy and SOP assistant. 3. Incident and CAPA drafting workflow. 4. ISO control evidence tracker. 5. Audit pack preparation for one department. The pilot should measure answer quality, evidence quality, time saved, and staff adoption. ## Private internal knowledge base for policies, SOPs, and operational answers. https://lenouar.ae/en/solutions/internal-knowledge-base Turn scattered internal documents into a governed AI assistant that answers from approved sources, respects access rules, and keeps organizational knowledge under control. ### Enterprise knowledge that stays private Most organizations already have the knowledge they need. The problem is that it is scattered across SharePoint, Google Drive, email, PDFs, policies, portals, and old folders. Lenouar builds a private knowledge assistant that lets employees ask questions and receive source-traceable answers from approved material, without sending internal files to uncontrolled public AI tools. ### Source-traceable answers Trust depends on traceability. The assistant should show where an answer came from and whether the source is current. ### What good answers include - The direct answer in plain language. - Source documents and sections used. - Confidence boundaries where the answer is incomplete. - Follow-up actions when a human owner must decide. - Permissions respected at query time. This makes the knowledge base useful for real work, not just demos. ### HR, IT, operations, and compliance knowledge A private knowledge base can start in one department and expand into a shared operating layer. ### Common knowledge domains - HR policies, benefits, onboarding, and employee handbooks. - IT helpdesk guides, access procedures, and system runbooks. - Compliance policies, controls, and evidence instructions. - Operations SOPs, escalation paths, and playbooks. - Sales, delivery, and client service material. Each domain can have its own owners, access rules, and update workflow. ### Connectors to existing tools The assistant should connect to tools the organization already uses rather than forcing a full content migration. ### Integration targets - Email and shared mailboxes. - SharePoint and Microsoft Teams. - Google Drive and shared folders. - Jira, Confluence, and service desks. - Internal APIs and databases. Lenouar can index the right content while preserving the system of record. ### Permission-aware retrieval Private knowledge is only useful if the assistant respects access boundaries. Users should not receive answers from documents they cannot access. Lenouar structures retrieval around role-based access, document ownership, tenant boundaries, and audit logging so the assistant behaves like an enterprise system rather than a generic chatbot. ### Knowledge base launch plan Start with a document set where answer quality can be judged clearly. ### A focused rollout 1. Choose one knowledge domain with a clear owner. 2. Remove duplicates and outdated documents. 3. Define access rules and source freshness rules. 4. Test questions from real employees. 5. Expand after accuracy and governance are proven. ## Private document intelligence for extraction, routing, and review. https://lenouar.ae/en/solutions/document-intelligence Automate document intake, classification, extraction, summarization, and approval workflows while keeping sensitive files inside the approved environment. ### Document workflows with AI control Document-heavy teams lose time on intake, manual reading, copy-paste extraction, routing, and status tracking. Lenouar builds private document intelligence workflows that automate the repetitive parts while keeping review, access control, and audit history in place. ### OCR, classification, and field extraction The system can process structured and unstructured documents across scans, PDFs, forms, contracts, letters, and spreadsheets. ### Document processing steps - OCR and text extraction from scans and PDFs. - Document classification by type, department, urgency, or risk. - Field extraction for names, dates, IDs, amounts, obligations, and missing items. - Summary generation for reviewers. - Validation against rules or reference documents. The goal is reliable workflow support, not uncontrolled automation. ### Approval routing and exception handling A useful document workflow does not stop at extraction. It knows what should happen next. ### Examples - Route high-risk documents to a reviewer. - Send missing fields back to an intake owner. - Create a task when evidence is incomplete. - Prepare an approval pack for finance, legal, HR, or compliance. - Write approved structured data back to an internal system. Every consequential action can pause for human approval. ### Private processing for sensitive files Document intelligence often touches confidential or regulated data. Lenouar can run ingestion, retrieval, extraction, and audit logging on private infrastructure. This is especially useful for healthcare records, legal files, government correspondence, HR files, procurement packs, and financial documentation. ### Connect to the systems of record The workflow can connect to existing tools without replacing them. ### Common integration points - Shared folders and document stores. - Email inboxes and intake addresses. - ERP, CRM, EHR, or case management APIs. - Ticketing and approval systems. - Compliance evidence repositories. Lenouar keeps the source system as the system of record and adds the AI workflow layer around it. ### Document automation pilot The best pilot is a recurring document process with visible manual effort. ### Good first candidates 1. Vendor document review. 2. Contract intake and extraction. 3. Healthcare compliance evidence collection. 4. HR onboarding files. 5. Finance approval packs. 6. Government correspondence triage. ## Private AI operations for ministries, authorities, and public-sector teams. https://lenouar.ae/en/solutions/government-operations Deploy AI copilots and workflow agents for policy, legal, service, and administrative work with data residency, auditability, and controlled model routing. ### Government AI inside approved boundaries Government and semi-government teams need AI, but not uncontrolled SaaS adoption. Documents, policies, legal files, internal decisions, and service workflows need a stronger operating model. Lenouar builds private AI systems that can run on-premise, in a private UAE environment, or in a hybrid architecture with approved local model routing. ### Policy, legal, and administrative document work Public-sector work is document-intensive and often bilingual. AI can help when the system is built around governance and review. ### Useful workflows - Policy and circular search. - Legal document review and summarization. - Internal memo drafting support. - Request and case triage. - Evidence packs for governance teams. - Arabic and English document summaries with review checkpoints. ### UAE-hosted models and private infrastructure Lenouar does not need to compete with national AI infrastructure providers. The stronger position is complementary. ### Deployment patterns - Use UAE-hosted model infrastructure for selected reasoning tasks. - Keep sensitive ingestion, retrieval, redaction, and audit locally. - Deploy a private node or rack where on-premise control is required. - Route tasks based on data class, department policy, and approval rules. This gives the client flexibility without losing governance. ### Operational agents with approval paths Government AI should assist workflows, not create hidden decisions. Agents can prepare work, collect context, draft outputs, and update internal systems only within approved boundaries. Consequential actions can stop for a named reviewer, and every step can be logged. ### Auditability for public-sector AI For government buyers, auditability is not decoration. It is part of the reason to use a private operating layer. The system can retain prompts, sources, model routing decisions, reviewer approvals, tool calls, and output history so the organization can explain how AI-assisted work was produced. ### Public-sector starting scope A good first deployment should avoid trying to automate a whole authority at once. ### Strong first scopes 1. Legal and policy document copilot. 2. Internal knowledge assistant for staff procedures. 3. Government correspondence summarization and triage. 4. Compliance evidence and governance reporting. 5. Controlled agent workflow for one administrative process. ## Enterprise AI agents with human approval and audit trails. https://lenouar.ae/en/solutions/enterprise-ai-agents Agentic workflows that watch events, prepare work, call internal tools, and pause for approval before consequential actions, built for regulated teams. ### Agents built for real operations Enterprise agents should not behave like uncontrolled bots. They need clear triggers, permissions, tools, fallback behavior, and human checkpoints. Lenouar designs AI agents as operational workflows that can work inside the organization's own environment and connect to the systems teams already use. ### Event triggers, tool calls, and approvals A governed agent workflow usually follows a simple pattern. ### Agent operating loop 1. An event happens, such as a ticket, document, email, or system update. 2. The agent retrieves the approved context. 3. The agent prepares a recommendation, draft, or action. 4. A human approves, edits, or rejects the output where required. 5. The system records the action, source context, reviewer, and result. This is automation with operating controls, not AI left alone. ### Department agent examples The same private agent layer can serve multiple teams with different permissions. ### Examples - Support agent that drafts replies and updates tickets after approval. - HR onboarding agent that checks missing documents. - Finance agent that prepares reconciliation notes. - Compliance agent that collects evidence and flags gaps. - Legal agent that summarizes documents and prepares review packs. - Operations agent that triages incidents and assigns follow-up tasks. ### Permissions and guardrails Each agent needs a boundary. It should know what it can read, what tools it can call, what actions it can prepare, and when it must stop. Lenouar defines these boundaries before implementation so the agent fits the organization's risk appetite and approval culture. ### Private node or hybrid agent runtime Agents can run on a private node for sensitive, routine, and always-on work. For occasional heavier reasoning, the workflow can route to approved external or UAE-hosted models if policy allows. The agent runtime, retrieval layer, tool permissions, and audit logs remain under the operating model Lenouar configures. ### The first agent to build The best first agent is narrow, repetitive, and easy to evaluate. ### Selection criteria - The workflow happens often. - Inputs are reasonably structured. - A human owner already reviews the outcome. - Time saved can be measured. - Risk can be controlled with clear approval gates. This creates momentum without overpromising full autonomy. # Industries ## Private AI for enterprise operations. https://lenouar.ae/en/industries/enterprise Lenouar helps organizations turn AI from scattered experiments into a controlled operational layer for internal knowledge, documents, approvals, and cross-functional work. ### Move beyond public chat and unmanaged AI pilots. Enterprise teams need the productivity of AI without exposing contracts, board papers, HR files, customer records, or internal procedures to tools they cannot govern. Lenouar positions AI as infrastructure your organization can control, monitor, and improve over time. - Private AI perimeter: Keep sensitive work inside approved infrastructure, with clear boundaries for which systems, documents, and users the AI can access. - Role-aware access: Separate executive, legal, finance, HR, operations, and delivery knowledge so AI assistance follows the same trust model as the business. ### AI for the internal work that slows teams down. Most organizations do not need novelty AI. They need reliable help with document review, knowledge retrieval, evidence collection, approvals, reporting, and follow-up across the systems people already use. - Knowledge and document work: Search policies, contracts, procedures, proposals, meeting packs, and internal files with source-traceable answers and review gates. - Approvals and handoffs: Turn repeatable operational steps into human-supervised workflows across departments, from intake to review to final action. ### A practical private AI layer for growing organizations. Lenouar is built for organizations that are too serious for uncontrolled SaaS AI, but do not want to build a hyperscale AI platform themselves. We scope the use case, deploy the stack, connect the right systems, and support the operating model. - Node, rack, or private cloud: Start with a focused private AI node, scale to rack-class infrastructure, or deploy in a private hosted environment depending on sensitivity and volume. - Connected enterprise systems: Connect approved tools such as Microsoft 365, SharePoint, Teams, Jira, Salesforce, ServiceNow, internal APIs, and document repositories. - Enterprise AI Agents: A specific solution for human-supervised agents connected to internal systems and business processes. - Integrations: Connect the systems your teams already use so AI can support real work, not another isolated interface. - AI Appliances: Turnkey private AI hardware installed on-premise and supported as part of the broader operating model. ## Private AI for government and semi-government operations. https://lenouar.ae/en/industries/government Lenouar helps public-sector and government-adjacent teams deploy controlled AI for policy, legal, correspondence, service, and internal knowledge workflows while keeping governance and review at the center. ### AI for sensitive work needs a stronger operating model. Government teams handle policy files, legal interpretations, citizen and business correspondence, internal procedures, and leadership briefings. Lenouar designs private AI environments that support productivity without bypassing approval, accountability, or data controls. - Approved boundaries: Define which documents, departments, users, and workflows the AI can access, and keep sensitive work inside the agreed environment. - Audit-ready assistance: Log prompts, sources, reviewer decisions, and workflow actions so AI support can be inspected instead of hidden. ### Support Arabic and English document-heavy teams. Public-sector work depends on circulars, policies, memos, service requests, legal notes, and procedural documents. Lenouar helps teams search, summarize, compare, route, and prepare these materials with source-traceable outputs and review checkpoints. - Arabic and English workflows: Support bilingual search, summaries, internal drafts, and document comparison while preserving source references for review. - Policy and correspondence support: Prepare briefings, triage requests, collect context, and summarize long files without replacing formal approval paths. ### Private AI that can fit public-sector constraints. Lenouar can support on-premise appliances, private hosted environments, hybrid routing, and optional local or national model strategies depending on the sensitivity, procurement model, and operational requirements of the organization. - On-premise or private hosted: Deploy close to the data for sensitive workflows, or use a private UAE-hosted setup where that better fits the operating model. - Local model optionality: Route selected workloads to approved local, national, open-source, or commercial models based on policy, cost, and capability. - Government Operations: A specific solution for policy search, legal review, correspondence triage, and auditable internal workflows. - AI Workforce: Human-supervised agents and copilots for internal service operations, routing, drafting, and follow-up. - Compliance Intelligence: Governance workflows for evidence, controls, policy review, audit logs, and management oversight. ## Private AI for healthcare organizations. https://lenouar.ae/en/industries/healthcare Lenouar helps clinics, hospitals, and healthcare groups use AI around sensitive clinical and operational information without losing control of patient data, evidence, or accountability. ### Healthcare AI has to work inside real governance. Medical teams want faster answers, better documentation, and less administrative drag. Leadership still has to protect patient confidentiality, clinical accountability, audit evidence, and local data expectations. Lenouar designs private AI around that operating reality. - Patient-data boundaries: AI access can be scoped by role, department, source system, and approved knowledge set, so sensitive records are not treated like general chat content. - Accountability by design: Prompts, sources, approvals, outputs, and follow-up actions can be logged for internal review, compliance teams, and management oversight. ### Practical AI for document-heavy healthcare operations. The strongest healthcare use cases are not generic chatbots. They are controlled assistants for policies, SOPs, incident notes, audits, evidence requests, internal knowledge, and operational handoffs across sites. - Policy and SOP intelligence: Help staff find the right protocol, policy owner, exception path, or evidence requirement from approved internal material. - Audit and incident readiness: Support compliance teams with source-traceable summaries, evidence coordination, incident follow-up, and CAPA preparation without replacing human sign-off. ### Built for clinics, hospitals, and multi-site groups. Lenouar can deploy private AI on-premise, in a UAE-hosted environment, or as a hybrid model depending on the sensitivity of the workflow, the maturity of your IT estate, and how your teams already work. - Private AI infrastructure: Run localized models and retrieval close to the data, with deployment choices that match clinical risk, data residency, and operational constraints. - Connected to existing systems: Connect approved repositories such as policy libraries, shared drives, incident records, and internal knowledge bases without turning AI into another uncontrolled silo. - Healthcare Compliance: A specific workflow for evidence, controls, remediation, and audit readiness in healthcare environments. - Private AI Infrastructure: The deployment layer for localized models, retrieval, logging, and controlled access to sensitive data. - AI Workforce: Human-supervised agents and copilots for operational work across departments and sites. ## Private AI for legal teams and confidential document work. https://lenouar.ae/en/industries/legal Lenouar helps law firms, in-house legal teams, and document-heavy organizations use AI for review, research, drafting support, and matter knowledge without weakening confidentiality or control. ### Legal AI must respect privilege, confidentiality, and review. Legal teams handle contracts, disputes, board papers, regulatory correspondence, and matter files that cannot be treated like ordinary productivity content. Lenouar designs private AI around access control, source traceability, audit history, and human legal judgment. - Confidential by default: Deploy AI inside an approved private environment so sensitive legal documents are not pasted into unmanaged public tools. - Controlled legal review: Keep approvals, citations, reviewer notes, and output history visible so legal work remains accountable and defensible. ### Turn legal archives into useful, source-traceable knowledge. Legal value often sits across past opinions, contract templates, clause positions, correspondence, policies, and matter folders. Lenouar helps organize that knowledge into a controlled assistant that can retrieve, compare, summarize, and explain from approved sources. - Matter and clause memory: Search prior matters, clause libraries, playbooks, templates, and internal positions with permission-aware retrieval. - Review support: Support contract intake, comparison, red flag summaries, obligation extraction, and response preparation before lawyer review. ### A practical AI layer for legal service delivery. The best legal AI programs start with repeatable work: intake, triage, document review, approval packs, evidence preparation, and internal knowledge requests. Lenouar helps legal teams deploy these workflows without turning AI into an uncontrolled parallel system. - Legal workflow automation: Route requests, prepare review packs, draft first-pass notes, and coordinate handoffs across legal, compliance, procurement, and leadership. - Human judgment preserved: Use AI to prepare and accelerate work while final interpretations, negotiations, filings, and external positions stay with qualified reviewers. - Legal Document Copilot: A private copilot for confidential document review, clause extraction, summarization, and drafting support. - Internal Knowledge Base: A controlled assistant for internal legal playbooks, policies, templates, precedents, and approved positions. - Private AI Infrastructure: The deployment layer for localized models, private retrieval, access controls, and audit logging. # Frequently asked questions ## How is a private AI system different from ChatGPT or a public cloud API? Public AI tools send your prompts and documents to someone else's cloud, under someone else's jurisdiction. Lenouar runs the models inside your own environment, so your data stays under your control and never has to leave your network. ## Where does our data go? Does anything leave our network? With an on-premise deployment, inference runs on your own hardware and nothing is sent to an external API. You decide exactly what, if anything, is ever allowed to leave your perimeter. ## Do you provide the hardware, or do we? Both options are supported. We can supply and install a preloaded AI appliance on your premises, or deploy onto hardware you already own. Either way, the stack is installed, configured, and supported by us. ## Which models can run on-premise? We serve localized open models (such as Llama-family models) with vLLM, tuned for your languages and domain. Models can be updated or swapped as stronger open models become available. ## How do you handle regulatory compliance requirements? Compliance is built in: control-mapped workflows, automatic audit trails, and evidence capture that stand up to inspection. This makes it easier to demonstrate conformance during audits rather than scrambling after the fact. ## Can it integrate with our existing systems? Yes. The platform connects to EHR/EMR, ERP, document stores, and internal APIs, with new connectors added regularly. Agents and copilots work inside the tools your teams already use. ## Can we start small and scale later? Yes. Many organizations begin with a single use case or a hybrid setup: local for sensitive tasks, cloud for heavy reasoning, then expand from there. You control what runs where, and scale as confidence grows. ## What core services should an AI automation partner in the UAE provide? A serious partner should cover the full lifecycle: private AI infrastructure (on-premise or private cloud), models localized for Arabic and English, secure integration with your existing systems, and controlled automation with human approval gates and audit trails. It should also provide governance aligned with UAE regulations, plus installation, training, and long-term support. Lenouar delivers all of these from Abu Dhabi as turnkey private AI systems. # Blog ## UAE PDPL and AI: what the 2027 deadline actually requires Published: 2026-09-04. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/uae-pdpl-ai-compliance-guide Everyone quotes 1 January 2027. Far fewer can say what it rests on. How the PDPL applies to AI systems, which articles matter, and what to fix first. Key takeaways: - The UAE PDPL (Federal Decree-Law No. 45 of 2021) never uses the word AI. It governs the personal data your AI system processes, which is why it applies to almost every deployment. - 1 January 2027 is the compliance date most advisers now quote, but it sits downstream of the Executive Regulations, which had still not been published at the time of writing. - Four provisions do most of the work for AI: Article 21 (impact assessment), Article 18 (automated decisions), and Articles 22 and 23 (cross-border transfer). - Prompts, retrieval indexes, embeddings and inference logs are personal data whenever they contain it. Most AI programmes scope the model and forget the logs. - Running inference inside the UAE removes the transfer question instead of documenting it. That is the difference between a control and a paper trail. ### Does the UAE PDPL apply to AI systems? Yes. The PDPL does not regulate AI as a technology, but it governs the processing of personal data, and an AI system that reads, stores or infers from personal data is carrying out processing. Obligations including impact assessment, lawful basis, data subject rights and cross-border transfer rules all apply to that processing path. ### Is 1 January 2027 a legally fixed PDPL deadline? It is the date most UAE advisers cite, but it is a projection rather than a date stated in the law. The PDPL provides a six-month adjustment period once the Executive Regulations are published, and those regulations had not been published at the time of writing. Plan against the date while recognising that it may move. ### Can we use a public cloud AI service and still comply with the PDPL? It is possible, but it depends on where processing occurs and on your transfer basis under Articles 22 and 23. If prompts, retrieval data and logs leave the UAE for a jurisdiction without an adequacy determination, you must rely on one of the narrow grounds in Article 23. Deploying inference in-region, or on private infrastructure, removes the transfer analysis rather than depending on it. ### Are prompts and inference logs considered personal data? They are personal data whenever they contain it, which in enterprise deployments is most of the time. Prompts routinely carry retrieved document content, and observability tooling often captures full request and response payloads by default. Both need to appear in your data inventory with a defined retention period. ### When does the PDPL require a Data Protection Impact Assessment for AI? Article 21 requires an assessment before processing that uses modern technologies posing a high risk to the privacy of data subjects, including systematic evaluation of personal aspects through automated processing such as profiling, and processing of large volumes of sensitive personal data. Most enterprise AI deployments meet at least one of those thresholds. ## ADHICS v2 and AI: what Abu Dhabi healthcare providers must control Published: 2026-09-04. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/adhics-v2-ai-governance ADHICS does not need an AI clause to govern your AI. Where deployments actually fail assessment, and why the 24-hour notification window is the real test. Key takeaways: - ADHICS v2 took effect in August 2024, replacing the 2019 standard, and applies to every Abu Dhabi entity that creates, processes, stores or transmits patient data, including IT vendors handling PHI on a provider's behalf. - It uses a three-tier control model (Basic, Transitional, Advanced) and shortens the incident notification window to 24 hours. - ADHICS does not need an AI clause to govern your AI. An AI system is an information asset processing health information, so the existing control families attach to it directly. - The controls AI deployments most often fail are asset inventory, third-party management, access control, logging and secure development, not anything model-specific. - Published summaries of ADHICS v2 disagree on the number and naming of control domains. Work from the DoH control catalogue, not from a blog post, including this one. ### Does ADHICS v2 apply to AI systems used in healthcare? Yes. ADHICS governs the security of health information rather than specific technologies, so an AI system that creates, processes, stores or transmits patient data falls within scope as an information asset. The standard's control families for asset management, access control, third-party security, logging and secure development apply to it directly. ### When did ADHICS v2 come into effect? ADHICS v2.0 took effect in August 2024, replacing the 2019 version of the standard. It applies across the Emirate of Abu Dhabi to healthcare facilities, payers, and service providers handling patient data, including IT vendors processing PHI on a regulated entity's behalf. ### What is the ADHICS breach notification timeframe? Version 2 requires notification to the Department of Health within 24 hours, shortened from the longer window in the previous version. For AI deployments this is demanding, because scoping a disclosure inside a day requires per-query logging tied to authenticated identity and retained long enough to investigate. ### How many control domains does ADHICS v2 have? Published third-party summaries disagree, with some listing eleven domains and others twelve, using different names. Because control references are checked during assessment, take the domain structure and control identifiers from the current Department of Health control catalogue rather than from secondary summaries. ### Does a small clinic deploying AI face lighter ADHICS obligations? Control depth scales through the Basic, Transitional and Advanced tiers, but the tier is determined by the type and size of the entity, not by the individual system. A smaller entity has a lower required depth across all of its assets, including AI, and that depth increases if the organisation grows into a higher tier. ## On-premise vs cloud AI in the UAE: how to choose Published: 2026-09-04. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/on-premise-vs-cloud-ai-uae Four deployment models, not two. Start with the transfer question, then the utilisation curve. An honest account of what each option costs you. Key takeaways: - The choice is not on-premise versus cloud. It is a spectrum of four deployment models, and most regulated teams are best served by one of the two in the middle. - Answer the cross-border transfer question first. It eliminates options faster than any cost model and it is the one constraint you cannot engineer around later. - On-premise economics are driven by utilisation, not by workload size. A busy cluster beats per-token pricing; an idle one is the most expensive option on the list. - On-premise costs you model freshness and elasticity, and it hands you an operations burden. Any vendor who does not say so is selling, not advising. - We build and install private AI appliances, so read the trade-offs below with that in mind. They are the ones we walk clients through before recommending anything. ### Is on-premise AI cheaper than cloud AI? Only at high utilisation. Owned hardware converts a variable per-token cost into a fixed capacity cost, so it wins when the hardware stays busy and loses badly when it sits idle. Model the realistic utilisation curve including power, cooling, spares and engineering time before comparing against metered pricing. ### Does the UAE PDPL require AI to run on-premise? No. The PDPL does not mandate on-premise deployment. It restricts transferring personal data outside the UAE, under Articles 22 and 23, which means processing must either stay in-country or rely on a valid transfer basis. In-region hosting and private tenancy can both satisfy that requirement without owning hardware. ### Are open-weight models good enough to replace frontier models? For document extraction, classification, retrieval, summarisation and structured workflow tasks, current open-weight models are generally sufficient in production. For difficult open-ended reasoning, leading proprietary models still hold an advantage. Match the deployment choice to the actual workload rather than to the benchmark headline. ### What is the difference between in-region cloud and private tenancy? In-region managed services keep processing inside a UAE data centre but run on shared infrastructure operated by a foreign provider under their terms. Private tenancy dedicates infrastructure to you, typically with network isolation and customer-managed keys, which gives stronger control over retention and access while still avoiding hardware ownership. ### What operational capability do we need to run AI on-premise? At minimum: GPU and driver maintenance, model serving and version upgrades, capacity planning, monitoring, patching and backup. Most mid-market organisations do not have this in-house at the start, which is why a managed appliance model, where the vendor operates the stack inside your facility, is often the practical middle path. ## Self-hosting Falcon and Jais on your own hardware with vLLM Published: 2026-09-04. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/self-hosted-llm-deployment-vllm Choosing an Arabic-capable open model, sizing for the KV cache rather than the weights, and the three vLLM flags that carry most of the tuning. Key takeaways: - Two open-weight families now make Arabic-capable self-hosting practical in the UAE: Falcon-H1 from TII and Jais 2 from Inception, Cerebras and MBZUAI. - vLLM is the default serving engine for a reason. PagedAttention removes KV cache fragmentation and continuous batching keeps the GPU busy between requests. - Size the hardware for KV cache, not for weights. Weights are a fixed cost you can calculate in a minute; the cache is what decides your real concurrency ceiling. - Three flags carry most of the tuning: --tensor-parallel-size, --gpu-memory-utilization and --max-model-len. The third is the one teams forget, and it is usually why serving fails to start. - The model is perhaps a fifth of the work. Authentication, permission-aware retrieval, logging and change control are what turn a running endpoint into a system you can operate. ### What is the best open-weight LLM for Arabic in 2026? The two leading open-weight options for Arabic are Falcon-H1 from the Technology Innovation Institute in Abu Dhabi and Jais 2 from Inception, Cerebras and MBZUAI. Falcon-H1 performs strongly across its size range on Arabic evaluations, while Jais is Arabic-first by design and built to handle Arabic and English in parallel. Evaluate both against your own documents, since domain vocabulary dominates real accuracy. ### What is PagedAttention in vLLM? PagedAttention manages the key-value attention cache in fixed-size blocks allocated on demand, rather than reserving a contiguous worst-case block per sequence. This applies the idea of virtual memory paging to attention, largely eliminating cache fragmentation and allowing substantially more concurrent sequences on the same GPU. ### How much GPU memory do I need to self-host an LLM? Budget roughly two bytes per parameter for weights at 16-bit precision, so a 30 billion parameter model needs about 60 GB before anything else. Then add the KV cache, which scales with concurrency and context length and is usually what limits you. Load-test at target concurrency with realistic context lengths rather than sizing from the weights alone. ### Why does vLLM fail to start with an out-of-memory error? The most common cause is that the model's default maximum context length cannot fit in available memory alongside the weights. Set --max-model-len to the context length your workload actually requires, which is typically far below the model maximum. Adjusting --gpu-memory-utilization can also help on dedicated hardware. ### Can self-hosted models satisfy UAE data residency requirements? Yes. Serving open-weight models such as Falcon-H1 or Jais on infrastructure located in the UAE keeps inference, prompts and logs in-country, which removes the cross-border transfer analysis required under Articles 22 and 23 of the PDPL. Residency alone is not full compliance, since access control, logging and impact assessment obligations still apply. ## Introducing the Lenouar AI Appliance Published: 2026-05-22. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/introducing-the-lenouar-ai-appliance Private AI hardware we install on your premises, preloaded with localized models, permission-aware retrieval and audit logging. Four tiers, one stack. Key takeaways: - The Lenouar AI Appliance is private AI hardware we install inside your facility, preloaded with localized models, private retrieval, tenant isolation and audit logging. - Four tiers cover the range from a single clinic room to a multi-site organisation: AI Edge, AI Node, AI Rack and AI Cluster. - The node and rack class runs two data-center GPUs of L40S or A100 class, serves open models up to roughly 70 billion parameters, and delivers around 1,200 tokens per second. - Hardware comes from vendors your procurement team already approves: NVIDIA, Dell, HPE, Supermicro, Lenovo, ASUS, Intel and AMD among them. - We install it, monitor it and maintain it. Owning the hardware should not mean inheriting an operations problem. ### What is the Lenouar AI Appliance? It is a private AI system delivered as hardware installed inside your own facility, preloaded with localized model serving, private retrieval, tenant isolation and audit logging. Lenouar installs it, connects it to your internal systems, and maintains it over time, so data never leaves your network. ### Which appliance tier do we need? AI Edge suits a single room, clinic or branch with tight space and power. AI Node serves a department or single site. AI Rack covers organisation-wide deployment with room to scale. AI Cluster spans multiple departments and sites. All four run the same software stack, so the choice is about footprint and capacity rather than capability. ### What hardware is the appliance built on? The appliances are built on data-center hardware from established vendors including NVIDIA, Dell, HPE, Supermicro, Lenovo, ASUS, Gigabyte, Intel, AMD and ASRock. The node and rack class uses two data-center GPUs of L40S or A100 class, serving open models up to roughly 70 billion parameters at around 1,200 tokens per second. ### Do we need our own engineers to run it? No. Lenouar installs, monitors and maintains the appliance, including patching, model upgrades and capacity review. That is deliberate, because the organisations that most need private AI are usually the ones without a platform engineering team to run inference infrastructure. ### How long does installation take? Physical installation is measured in days, because the stack ships preconfigured. The timeline is driven by integration and validation work: connecting internal systems, setting retrieval scope and permissions, configuring workflows, and confirming the audit trail meets the standards you are assessed against. ## Compliance Intelligence: proof that assembles itself Published: 2026-05-04. Updated: 2026-09-04. URL: https://lenouar.ae/en/blog/compliance-intelligence-is-here Map ten frameworks to one control set, pull evidence from the systems you already run, and keep the audit trail current. All on your private node. Key takeaways: - Compliance Intelligence turns the frameworks you answer to into working controls, captures evidence automatically, and keeps an audit trail ready before an inspector asks for it. - It maps across ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, PCI DSS, UAE PDPL, ADHICS, CIS Controls and COBIT, so a control implemented once satisfies every framework that requires it. - Evidence is pulled from the systems you already run rather than collected by hand in the weeks before an audit. - It runs on your private node. Compliance evidence is among the most sensitive data an organisation holds, and it should not be the thing you send to a third-party SaaS. - The value is not the dashboard. It is that the answer to "prove it" stops being a project. ### What is Compliance Intelligence? It is a control plane that maps regulatory frameworks to the controls you actually operate, collects supporting evidence automatically from your existing systems, and monitors control state continuously. It runs on your private infrastructure, so evidence never leaves your network. ### Which compliance frameworks does it support? It maps across ISO 27001, SOC 2, GDPR, HIPAA, NIST CSF, PCI DSS, UAE PDPL, ADHICS, CIS Controls and COBIT. UAE PDPL and ADHICS are treated as primary frameworks rather than as additions to a US-centric control library. ### How does automated evidence collection work? It connects to the systems that already hold the proof, including identity providers, ticketing systems, infrastructure tooling and document stores, then collects, timestamps and retains that evidence continuously. When an audit period is defined, the evidence pack is assembled from what has already been gathered rather than collected retrospectively. ### Why does compliance software need to run on-premise? A compliance evidence repository describes every control you operate and, by implication, every gap. That concentration makes it unusually sensitive. Running it on your own infrastructure keeps it inside your network and avoids the cross-border transfer analysis that a foreign-hosted platform would require under UAE PDPL Articles 22 and 23. ### Does it replace our compliance team? No. It removes the manual evidence-gathering work that consumes most of a compliance team's time, so the team can spend it on control design, risk assessment and remediation. The judgement calls remain human, and under frameworks such as ADHICS they are expected to be. # Positioning notes - Lenouar is not a generic chatbot vendor. - Lenouar is not positioning itself as a national-scale cloud provider. - Lenouar focuses on turnkey private AI systems, operational workflows, governance, and deployment support. - Public website content is safe to cite. Client systems, client data, and private deployments are not public sources.