Engineering quality, in public
Hyperion's own systems, audited and tracked with the same method an engagement would apply to yours. Numbers, not slides.
Last updated: 2026-08-20
Score from a 20-stream internal audit covering security, observability, dependency hygiene, SEO, and CI/CD.
Composite score from the audit dated 2026-05-01. Not re-scored since.
Audit progress by group
Current security posture
- State-changing admin routes validate CSRF server-side; read-only GET routes are excluded
- Dependency advisories are gated in CI; accepted risks must be explicitly documented
- Post-quantum SSH key exchange enabled (sntrup761x25519-sha512)
- Mistral API region is explicit and configurable (global or EU); residency is never inferred from provider identity
- Edge middleware admin gate + JWT pinned to HS256 + per-IP token-budget cap on chat
- Pre-push hook runs the local gate (lint, typecheck, architecture, i18n, copy checks, unit tests) before push
- Every GitHub Actions reference is pinned to a full commit SHA; force-push and branch deletion are blocked on main; production deploys run only after CI succeeds on main
Stack disclosure
- Framework
- Next.js 16 (App Router, RSC-first)
- AI runtime
- Mistral AI primary runtime · GLOBAL API endpoint configured (not a residency guarantee)
- Hosting
- OVH VPS (France) — 24 GB RAM, 12 vCPU, PM2 cluster
- Locales
- 8 (en, fr, de, nl, el, ar, ja, zh)
Our own EU AI Act classifications
We use the same classifier an engagement would apply. Each AI-touching surface declared.
Self-classification under the EU AI Act. Article 50 transparency obligations apply from 2 August 2026. None of these systems is Annex III high-risk; none makes a decision producing legal or similarly significant effects on a person. Systems the site runs but that never process visitor input — internal authoring and outbound-research tooling — are listed here as well, so this register is the whole picture rather than the visitor-facing part of it. Dormant systems are listed and marked dormant rather than omitted. This register and section 10.bis of the privacy policy describe the same systems, in the same order, under the same identifiers. (v2026-08-20)
- Hyperion Brain (site assistant)Answers visitor questions about the practice and its services.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Site visitors who choose to open it
- Lawful basis:
- Art. 6(1)(f) legitimate interest in answering enquiries
- Retention:
- Conversation memory 30 days
- Controls:
- Identifies itself as an AI assistant before input is possible; no automated decision about the visitor.
- JARVIS Decision NavigatorRoutes a visitor's described product decision to the smallest fitting engagement, or to an honest no-fit result, and drafts a cited brief.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who choose to start the Navigator from /start or an in-page call to action
- Lawful basis:
- Art. 6(1)(f) legitimate interest in qualifying enquiries
- Retention:
- Conversation memory 30 days
- Controls:
- Identified as an AI assistant before any input. It recommends; it does not decide, price or contract. Contact details and booking are a separate, consented step, and operational alerts carry bounded metadata only — never the visitor's free text.
- AI site searchAnswers a question typed into the site search box from the published corpus, and cites the pages the answer came from.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who use the search box
- Lawful basis:
- Art. 6(1)(f) legitimate interest in helping visitors find published material
- Retention:
- Answers are cached by query; no visitor identifier is stored with them
- Controls:
- Answer labelled AI-generated and shown with its sources. Rate-limited per client. Keyword search remains available without it.
- AI Readiness AssessmentProduces an AI-maturity score and recommendations from a questionnaire the visitor completes.
- Risk class:
- Limited risk — Art. 50(1) transparency. Not a decision with legal or similarly significant effect.
- Provider:
- Deterministic scoring logic, plus Mistral AI — see the privacy policy, section 5, for where that processing takes place for the written recommendations
- Affects:
- Visitors who complete the assessment
- Lawful basis:
- Art. 6(1)(b) performance of the requested service; contact details under the form's own consent
- Retention:
- With the CRM contact record — relationship plus 2 years
- Controls:
- Results are stated to be informational and not professional advice. Deletion on request under Art. 17.
- EU AI Act risk classifierSuggests a risk tier for a system the user describes.
- Risk class:
- Limited risk — regulatory information tool, Art. 50
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Users of the compliance tool
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Register entries per the published retention schedule
- Controls:
- Labelled as indicative, not legal advice; a human decides.
- Use-case generatorDrafts candidate AI use cases from a described context.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Users of the tool
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Not stored beyond the session
- Controls:
- Output is a draft for human selection.
- Marketplace AI agentsConfigurable AI agents that registered Marketplace users converse with to produce work for their own projects.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- People who register a Marketplace account and open a conversation
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Conversation memory 30 days from last activity; account data per the published schedule
- Controls:
- Each agent is labelled as an AI agent. Project context is read ownership-scoped, so one tenant's brief cannot reach another tenant's agent. Account and data deletion available in the account area.
- Lead qualification and scoringScores an inbound enquiry to prioritise a reply.
- Risk class:
- Minimal risk under the AI Act; GDPR PROFILING
- Provider:
- Deterministic rules on the contact form (no AI, no third-party look-up). On the gated-resource path: Mistral AI — see the privacy policy, section 5, for where that processing takes place, plus a LinkedIn company look-up and a Mistral web search.
- Affects:
- People who submit an enquiry or gated-content form
- Lawful basis:
- Art. 6(1)(f) legitimate interest in prioritising enquiries; disclosed at collection
- Retention:
- Scores 90 days
- Controls:
- No automated decision with legal or similarly significant effect; a human decides whether and how to reply. Object at dpo@hyperion-consulting.io.
- Outbound prospect research and scoringResearches and tiers organisations for outbound contact.
- Risk class:
- Minimal risk under the AI Act; GDPR PROFILING (Art. 14 applies — data not obtained from the person)
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place, plus public search results retrieved through SerpAPI (United States) and publicly available LinkedIn information
- Affects:
- Named individuals at prospect organisations, sourced indirectly
- Lawful basis:
- Art. 6(1)(f) legitimate interest in business development
- Retention:
- Per the published retention schedule
- Controls:
- Art. 14 notice on first contact; objection honoured immediately and the record suppressed.
- Proposal draftingDrafts a proposal outline from an enquiry.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- People who requested a proposal
- Lawful basis:
- Art. 6(1)(b) pre-contractual steps
- Retention:
- With the enquiry record
- Controls:
- Never sent without human review.
- Automated article generation and publishingResearches, drafts, translates and publishes insight articles.
- Risk class:
- Limited risk — Art. 50(4) AI-generated content labelling
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place. For English long-form drafting only, the OpenAI Codex command-line tool (United States) may also be used.
- Affects:
- Readers of the published corpus
- Lawful basis:
- Art. 6(1)(f) legitimate interest in publishing
- Retention:
- Published indefinitely until retracted
- Controls:
- Every article carries an AI-disclosure label. The label asserts human review ONLY where a reviewer is recorded; otherwise it states the article was not individually reviewed. A claim gate blocks client/track-record assertions at the write boundary. The Codex path is off unless explicitly enabled, runs read-only and ephemeral with web search off, and a build-time dependency rule permits only the content-authoring module to reach it — visitor and lead data cannot.
- Attachment text extraction (contact and assessment forms)Reads a brief or deck the visitor chooses to attach and returns a short summary, so the visitor does not have to retype it.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place — OCR followed by one summarisation call
- Affects:
- Visitors who choose to attach a file; no upload is required to contact the practice
- Lawful basis:
- Art. 6(1)(a) consent — the visitor initiates the upload; the form works without it
- Retention:
- The file is not stored: it is held in memory for the call and never written to disk or object storage. Only the text the visitor chooses to send is kept, as part of their enquiry.
- Controls:
- Stated at the point of collection before a file is chosen. Type and magic-byte verification, a page cap and a structural PDF inspection run before anything reaches the provider; the summary is shown to the visitor and can be edited or removed before submission.
- AI Lab public demonstrationsHands-on demonstrations of model behaviour — vision, document OCR, speech, prompt-injection and evaluation — so a visitor can judge the practice's technical claims instead of taking them on trust.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who open a demonstration and supply an input
- Lawful basis:
- Art. 6(1)(a) consent — every demo is opened and fed by the visitor
- Retention:
- Inputs are not stored; they are processed for the response and discarded.
- Controls:
- Each demo is labelled as an AI demonstration. Per-demo rate limits and a spend circuit-breaker bound abuse; image inputs pass a moderation check before dispatch. Outputs are illustrative and make no decision about the visitor.
- JARVIS industrial demonstrations (plant audit, defect inspection, CSV maintenance)Show how a vision or tabular model reads an industrial scene, a part photograph or a maintenance log, as a worked example of the practice's method.
- Risk class:
- Limited risk — Art. 50(1) transparency. Not Annex III: these are demonstrations, not a safety component and not an input to any decision about a person.
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who run a demonstration
- Lawful basis:
- Art. 6(1)(a) consent — the visitor starts the demonstration
- Retention:
- Uploads are not stored; they are processed for the response and discarded.
- Controls:
- Labelled as a demonstration and not a professional assessment. Own rate-limit bucket so demo traffic cannot exhaust the contact form's quota; image moderation and a spend circuit-breaker before dispatch.
- Homepage campaign personalisationRewrites a page headline to match the marketing campaign the visitor arrived from.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Nobody at present — built, but no page currently mounts it
- Lawful basis:
- Art. 6(1)(f) legitimate interest in relevant marketing copy — no personal data is processed
- Retention:
- Generated copy cached for 24 hours per campaign tuple; nothing about a visitor is stored
- Controls:
- Listed here although dormant, so this register describes what the site can do and not only what it did today. Re-mounting it requires no new personal data.
Recent activity
Last 5 changes shipped to production.
a52c413dfix: normalize deployment copy checks2026-08-0277194efffeat: launch Physical AI decision engineering platform2026-08-029d32b1a2fix(seo,cta): route the definition page at the offer2026-08-01c4de7b42docs,refactor: fold strategy onto the canonical Product System2026-08-01bdbec568docs(strategy): sequence the transformation around 39 gaps2026-08-01
Want this level of transparency for your AI systems?
An engagement ships this same dashboard — composite score, group progress, EU AI Act classification, security posture.