
Thomas Underhill
Product & Eng Leader (AWS, VMware, HashiCorp, NGINX) · Adjunct Professor
Your team built something that worked. Then privacy, security or compliance looked at where the data would go, and it stopped. That was a year ago, maybe two, and it now feels settled rather than pending. It usually is not. Almost every objection in this category turns out to be about one deployment model rather than about AI, and that is a solvable problem once somebody says out loud which objection it actually was.
We take the objection your organization actually raised and map it to the specific technical control that answers it. Data egress, retention, training on your inputs, subprocessor chains, residency, a missing agreement, auditability. Each one has a named answer. Then we decide whether running it inside your own perimeter is the right answer for your situation, and if it is, roughly what that costs in hardware and in staffing. If it is not the right answer, you find that out in an hour rather than a quarter.
A written summary covering four things:
1. The objection-to-control mapping for your specific case
2. A view on self-hosting, with the reasoning rather than the conclusion
3. A cost envelope, hardware and staffing, where it applies
4. The named next step, and the person who has to agree to it
It is written to be forwarded without editing. That is the point of it. The conversation is useful; the document is what changes something after you close the laptop.
Send me two things twenty four hours ahead.
1. The workflow you want to run, in a paragraph.
2. The objection, in the words the objector actually used. Not your summary of it. Their words.
That is the whole input. It means we spend the hour on your problem rather than on discovery, and it is the difference between a useful session and a pleasant one.
I will not tell you self-hosting is the answer when it is not. A fair share of the time the honest finding is that your volume does not justify it, that the constraint is contractual rather than technical, or that the vendor agreement you already hold covers more than anyone realized. Those are all good outcomes for an hour, and you should hear them in an hour.
Engineering and security leaders in healthcare, financial services, government and legal whose AI project was approved on the technology and stopped somewhere else. It works just as well if you are the person who stopped it and wants a defensible route to yes.
I build and operate AI systems in places where you have to prove things: that the data never left, that the model did what you say, that a person approved the action. Twenty five years in enterprise software before that, in senior roles at PayPal, Oracle, VMware, HashiCorp, F5 and AWS, running SOC 2, PCI-DSS, FedRAMP and NIST 800-53 as engineering programs rather than paperwork.
One sixty minute session and one written summary. No open-ended follow-up is included, and none is implied. If there is a larger piece of work here, we will both know by minute forty, and I will quote it separately rather than letting it happen by accident.
$350
USD
Sixty minutes on your blocked project, plus a written control mapping in two working days.