Frequently asked questions
What we are asked
before we start.
The questions raised in first conversations: scope, costs, references, data location, artificial intelligence and contract exit. The answers are direct, including when they are less flattering.
- FRANCE / MONACO / SWITZERLAND
- 24 QUESTIONS
Working with AIGYROS GROUP
Scope, process, references and business model — the questions asked before any commitment.
What problems does AIGYROS GROUP solve in practice?
AIGYROS GROUP designs, deploys and maintains digital environments for organisations whose data or business continuity is critical: server and network infrastructures, business applications, institutional websites, locally hosted environments and artificial intelligence systems run on site. Every engagement starts with a diagnosis of the existing environment, then covers construction, security and long-term operation.
Do you operate in France, Monaco and Switzerland?
Yes. The publisher is established in France and operates in France, Monaco and Switzerland. Most assignments are conducted remotely; on-site interventions are scheduled according to project criticality and team locations. Monaco and Switzerland are part of the commercial area of operation: AIGYROS GROUP has no establishment there.
How does a first contact work?
The first conversation lasts about forty-five minutes and is not billed. It serves to understand the environment, the constraints and the deadlines. Afterwards, two outcomes: either the need falls within our skills and we send a written proposal; or it does not, and we say so. No quote is ever sent without this conversation.
How much does an engagement cost, and how soon do we receive a quote?
We do not work from a price list: cost depends on scope, on the state of the existing environment and on the required level of criticality. A detailed priced proposal is sent within five working days of the first conversation. Engagements are split into stages with fixed scope and budget, so spending stays readable and can be stopped at each milestone.
What should we prepare for a productive first conversation?
Three things are enough to make the first conversation productive: the number of sites and users concerned, the list of business applications and software actually in use, and the known constraints — regulatory obligations, deadline commitments, recent incidents. An architecture sketch, even approximate, beats an exhaustive inventory.
Can you provide client references?
Our clients’ names are not published: many assignments concern sensitive environments and are covered by confidentiality clauses. On reasoned request, references and contacts are shared with organisations considering an engagement, with the prior agreement of the clients concerned. The Case Studies page describes the nature of the assignments conducted, without naming clients.
What distinguishes AIGYROS GROUP from an integrator or a cloud host?
Three differences. First, no commercial interest in any vendor: we resell neither licences nor cloud capacity, which keeps technical recommendations free. Second, data location, treated as an architecture decision rather than an option. Third, size: the person who runs the engagement is the one who operates it, with no service centre in between.
Can you handle operation and maintenance over time?
Yes. Maintenance can cover monitoring, updates, backup management and incident handling, with written response-time commitments proportionate to the criticality of the environment. Terms, coverage hours and service levels appear in the contract, not in a commercial annex.
What happens if we wish to change provider?
Reversibility is planned from the design stage. We document the architecture, operating procedures and access credentials, and hand them to the client on request. No technical element, identifier or script developed for the client is ever held hostage: leaving must remain possible without us.
Do you work with small organisations?
Yes, whenever the data or business continuity justifies structured support. The criterion is not the size of the organisation but the criticality of what is entrusted to us. For very small structures, we say frankly when a standard solution is enough and an engagement would be disproportionate.
Infrastructure, data and artificial intelligence
Hosting, security, local AI and information protection — the core of regulated requirements.
Where is the data you process hosted?
Location is an architecture decision taken with the client, not a suffered constraint. Three scenarios: on site, on the client’s premises; on dedicated servers leased from a European host; or in a hybrid environment, with sensitive data kept locally. We systematically document where each piece of data resides and who can access it.
What is local AI, and how does it differ from an online service?
Local AI means running models on machines controlled by the organisation, inside its network, rather than calling a service hosted by a third party. The documents analysed and the questions asked therefore never leave the organisation’s perimeter. This approach suits confidential data, client files and information covered by professional secrecy.
Can the US Cloud Act apply to our data?
The Cloud Act allows US authorities to demand access to data held by a company subject to US law, including when the servers sit outside US territory. The determining factor is therefore the operator’s control, not the hardware’s location. Choosing a host outside that regime, or operating one’s own servers, is the structural answer to this risk.
Is a specific certification required to process sensitive data?
It depends on the framework applying to the client. The public sector and operators of vital importance often reason in terms of SecNumCloud qualification or HDS approval for health data. We hold neither qualification and claim neither: we design environments that are not subject to them because they remain private, and we refer clients to qualified providers when their regulation requires it.
Can an artificial intelligence model invent answers?
Yes. A language model can produce false information with confident wording: this is called hallucination. The remedy is not to trust the model but to ground it in reference documents and to require source quotations. Each answer is then tied to an identifiable passage, and uncertainty can be flagged rather than hidden.
What does RAG mean, and what is it for?
RAG stands for retrieval-augmented generation: the system first retrieves the relevant passages from the organisation’s documents, then hands those passages to the model to draft an answer grounded in them. This method markedly reduces invented answers, makes sources verifiable and allows answers to stay within the authorised documentary perimeter.
Is our data used to train models?
No. Entrusted data serves the engagement exclusively: it is neither resold nor used to train a model for other clients. When open models are used, they run on the client’s infrastructure and their weights are not modified without the client’s explicit decision.
How do you guarantee a project stays reversible?
Every technical choice is written down, justified and documented, with an indication of what it would take to go back. We favour open formats and standard components, and avoid proprietary mechanisms that would make exit costly. Operating documentation is handed to the client as we go, not kept as leverage.
What backup strategy do you put in place?
We apply the 3-2-1 rule: three copies of the data, on two distinct media, including one off-site copy. A backup is only as good as its restore: every backup plan therefore ships with documented restore tests, not a mere check that the copy exists.
How do you approach cybersecurity?
In order of real effectiveness: mapping the existing environment and patching, access partitioning and least privilege, tested backups, monitoring of abnormal events, then user awareness. We cover these fundamentals and coordinate specialists when the required level exceeds our scope — we do not run a security operations centre.
What is the response time in case of incident?
Response time depends on the subscribed commitment, set in writing according to the criticality of the environment. A blocking outage and an evolution request are not handled the same way. Proven security incidents are treated as priority, with a rapid initial impact analysis and situation update.
What timelines should we expect for a typical project?
An infrastructure audit generally takes one to three weeks. A technical foundation overhaul spans four to twelve weeks depending on the number of sites and dependency complexity. An institutional website takes three to eight weeks. These orders of magnitude assume an available client contact and timely access.
How do you treat data seen during an audit?
The audit is covered by a confidentiality agreement signed before work begins. Technical records are reduced to what the diagnosis requires and, where possible, worked from anonymised inventories. Collected material is returned to the client and deleted at the end of the engagement, unless a legal obligation says otherwise.
Where are this website’s servers hosted?
The site is hosted by Vercel Inc., in the United States. It collects no browsing data: no cookies are set, no audience measurement is performed and fonts are self-hosted, so no request is sent to any third-party service when browsing. Processing details appear in the privacy policy.
Prendre contact
A project, a constraint, a question of control?
Tell us about your environment. We answer with analysis, not a catalogue.