Engineering quality, in public
Hyperion's own systems, audited and tracked with the same method an engagement would apply to yours. Numbers, not slides.
Last updated: 2026-08-26
Score from a 20-stream internal audit covering security, observability, dependency hygiene, SEO, and CI/CD.
Composite score from the audit dated 2026-05-01. Not re-scored since.
Audit progress by group
Current security posture
- State-changing admin routes validate CSRF server-side; read-only GET routes are excluded
- Dependency advisories are gated in CI; accepted risks must be explicitly documented
- Post-quantum SSH key exchange enabled (sntrup761x25519-sha512)
- Mistral inference is constrained in code to https://api.eu.mistral.ai; other hosts, aliases, unapproved models and provider fallbacks are rejected
- Owner-authorized public Mistral processing is limited to JARVIS, Search and Product Council through the EU-only adapter; deterministic fallbacks remain usable
- Edge middleware admin gate + JWT pinned to HS256 + per-IP token-budget cap on chat
- The default pre-push hook runs the complete local release gate (secrets, dependency audit, lint, typecheck, architecture, i18n, copy checks, unit tests, production build, served-route smoke, Lighthouse and browser/TLS checks) before push
- Every GitHub Actions reference is pinned to a full commit SHA; force-push and branch deletion are blocked on main; production deploys run only after CI succeeds on main
Stack disclosure
- Framework
- Next.js 16 (App Router, RSC-first)
- AI runtime
- Mistral-only, EU-endpoint, stateless runtime for allowlisted public consumers; deterministic engines remain available · https://api.eu.mistral.ai is the only permitted inference origin (not an end-to-end residency guarantee)
- Hosting
- OVH VPS (France) — 24 GB RAM, 12 vCPU, PM2 cluster
- Locales
- 8 (en, fr, de, nl, el, ar, ja, zh)
Our own EU AI Act classifications
We use the same classifier an engagement would apply. Each AI-touching surface declared.
Technical transparency register, not a legal certification. The owner has authorized the allowlisted JARVIS, Search and Product Council paths to use stateless Mistral inference through the EU endpoint. Zero Data Retention, DPA acceptance, the complete subprocessor/transfer chain and final legal classifications are not claimed verified. Other listed surfaces may be retained or dormant. Every consequential decision remains with a named human. This register and section 10.bis of the privacy policy describe the same systems, in the same order, under the same identifiers. (v2026-08-27)
Public remote AI status: owner-authorized JARVIS, Search and Product Council consumers are active through the EU-only Mistral adapter. Deterministic fallbacks remain available.
- Hyperion Brain (site assistant)Answers visitor questions about the practice and its services.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Site visitors who choose to open it
- Lawful basis:
- Art. 6(1)(f) legitimate interest in answering enquiries
- Retention:
- Conversation memory 30 days
- Controls:
- Identifies itself as an AI assistant before input is possible; no automated decision about the visitor.
- JARVIS Decision NavigatorRoutes a visitor's described product decision to the smallest fitting engagement, or to an honest no-fit result, and drafts a cited brief.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who choose to start the Navigator from /start or an in-page call to action
- Lawful basis:
- Art. 6(1)(f) legitimate interest in qualifying enquiries
- Retention:
- Conversation memory 30 days
- Controls:
- Identified as an AI assistant before any input. It recommends; it does not decide, price or contract. Contact details and booking are a separate, consented step, and operational alerts carry bounded metadata only — never the visitor's free text.
- Physical AI Product CouncilRuns three separately prompted Mistral roles to challenge and explain a deterministic Physical AI Product Flight Simulator scenario and its evidence gaps.
- Risk class:
- Awaiting operator and legal classification; Article 50 disclosure is required before interaction
- Provider:
- Active, owner-authorized stateless inference through the EU-only adapter: mistral-small-2603, mistral-medium-3-5 and mistral-large-2512.
- Affects:
- Visitors who explicitly opt in from the Flight Simulator after reading the AI and data disclosure
- Lawful basis:
- Art. 6(1)(a) consent — the visitor must explicitly request the council after disclosure
- Retention:
- No server-side council state; routine logs contain operational metadata only, not prompts or outputs
- Controls:
- Input and output moderation fail closed; schemas and exact models are allowlisted. Deterministic code is the calculation authority, the shared Mistral model family can share failure modes, and the named human is the final decision authority.
- AI site searchAnswers a question typed into the site search box from the published corpus, and cites the pages the answer came from.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Visitors who use the search box
- Lawful basis:
- Art. 6(1)(f) legitimate interest in helping visitors find published material
- Retention:
- Answers are cached by query; no visitor identifier is stored with them
- Controls:
- Answer labelled AI-generated and shown with its sources. Rate-limited per client. Keyword search remains available without it.
- AI Readiness AssessmentProduces an AI-maturity score and recommendations from a questionnaire the visitor completes.
- Risk class:
- Limited risk — Art. 50(1) transparency. Not a decision with legal or similarly significant effect.
- Provider:
- Deterministic scoring logic, plus Mistral AI — see the privacy policy, section 5, for where that processing takes place for the written recommendations
- Affects:
- Visitors who complete the assessment
- Lawful basis:
- Art. 6(1)(b) performance of the requested service; contact details under the form's own consent
- Retention:
- With the CRM contact record — relationship plus 2 years
- Controls:
- Results are stated to be informational and not professional advice. Deletion on request under Art. 17.
- EU AI Act risk classifierSuggests a risk tier for a system the user describes.
- Risk class:
- Limited risk — regulatory information tool, Art. 50
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Users of the compliance tool
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Register entries per the published retention schedule
- Controls:
- Labelled as indicative, not legal advice; a human decides.
- Use-case generatorDrafts candidate AI use cases from a described context.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Users of the tool
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Not stored beyond the session
- Controls:
- Output is a draft for human selection.
- Marketplace AI agentsConfigurable AI agents that registered Marketplace users converse with to produce work for their own projects.
- Risk class:
- Limited risk — Art. 50(1) transparency
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- People who register a Marketplace account and open a conversation
- Lawful basis:
- Art. 6(1)(b) performance of the requested service
- Retention:
- Conversation memory 30 days from last activity; account data per the published schedule
- Controls:
- Each agent is labelled as an AI agent. Project context is read ownership-scoped, so one tenant's brief cannot reach another tenant's agent. Account and data deletion available in the account area.
- Lead qualification and scoringScores an inbound enquiry to prioritise a reply.
- Risk class:
- AI-assisted scoring is not production-allowlisted; operator and legal classification and DPIA screening remain open
- Provider:
- Current path: deterministic rules only. The optional stateless Mistral scorer is not in the production-consumer allowlist and has no built-in web search. LinkedIn company look-up is inactive.
- Affects:
- People who submit an enquiry or gated-content form
- Lawful basis:
- Any future AI-assisted scorer requires a separate owner decision; its proposed legal basis remains under review
- Retention:
- Scores 90 days
- Controls:
- No automated decision with legal or similarly significant effect; a human decides whether and how to reply. Object at dpo@hyperion-consulting.io.
- Outbound prospect research and scoringResearches and tiers organisations for outbound contact.
- Risk class:
- Minimal risk under the AI Act; GDPR PROFILING (Art. 14 applies — data not obtained from the person)
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place, plus public search results retrieved through SerpAPI (United States) and publicly available LinkedIn information
- Affects:
- Named individuals at prospect organisations, sourced indirectly
- Lawful basis:
- Art. 6(1)(f) legitimate interest in business development
- Retention:
- Per the published retention schedule
- Controls:
- Art. 14 notice on first contact; objection honoured immediately and the record suppressed.
- Proposal draftingDrafts a proposal outline from an enquiry.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- People who requested a proposal
- Lawful basis:
- Art. 6(1)(b) pre-contractual steps
- Retention:
- With the enquiry record
- Controls:
- Never sent without human review.
- AI-assisted article research and draftingResearches and stages English-language Insight drafts for authenticated human review; the scheduler cannot publish or distribute them.
- Risk class:
- Awaiting operator and legal classification; Article 50 content-labelling controls are retained
- Provider:
- When explicitly enabled for authenticated editorial work, Mistral AI only through the EU-only stateless adapter. The content scheduler cannot publish, and no other hosted model provider is reachable.
- Affects:
- Readers of the published corpus
- Lawful basis:
- Art. 6(1)(f) legitimate interest in publishing
- Retention:
- Published indefinitely until retracted
- Controls:
- The generated revision is stored as a durable draft in Admin → Blog. Only an interactive authenticated human can approve the exact revision; that decision is bound to the review ledger before publication. A claim gate blocks client and track-record assertions at the write boundary.
- Attachment text extraction (contact and assessment forms)Reads a brief or deck the visitor chooses to attach and returns a short summary, so the visitor does not have to retype it.
- Risk class:
- Awaiting operator and legal classification; Article 50 disclosure is required before use
- Provider:
- Retained Mistral OCR and summarisation path through the EU-only adapter; disabled because it is not in the production-consumer allowlist
- Affects:
- Visitors who choose to attach a file; no upload is required to contact the practice
- Lawful basis:
- Art. 6(1)(a) consent — the visitor initiates the upload; the form works without it
- Retention:
- The file is not stored: it is held in memory for the call and never written to disk or object storage. Only the text the visitor chooses to send is kept, as part of their enquiry.
- Controls:
- Stated at the point of collection before a file is chosen. Type and magic-byte verification, a page cap and a structural PDF inspection run before anything reaches the provider; the summary is shown to the visitor and can be edited or removed before submission.
- AI Lab public demonstrationsHands-on demonstrations of model behaviour — vision, document OCR, speech, prompt-injection and evaluation — so a visitor can judge the practice's technical claims instead of taking them on trust.
- Risk class:
- Awaiting operator and legal classification; Article 50 disclosure is required before use
- Provider:
- Retained Mistral capabilities through the EU-only adapter; remote vision, OCR and speech remain disabled because they are not in the production-consumer allowlist
- Affects:
- Visitors who open a demonstration and supply an input
- Lawful basis:
- Art. 6(1)(a) consent — every demo is opened and fed by the visitor
- Retention:
- Inputs are not stored; they are processed for the response and discarded.
- Controls:
- Each demo is labelled as an AI demonstration. Per-demo rate limits and a spend circuit-breaker bound abuse; image inputs pass a moderation check before dispatch. Outputs are illustrative and make no decision about the visitor.
- JARVIS industrial demonstrations (plant audit, defect inspection, CSV maintenance)Show how a vision or tabular model reads an industrial scene, a part photograph or a maintenance log, as a worked example of the practice's method.
- Risk class:
- Awaiting operator and legal classification; demonstrations are not safety components or professional assessments
- Provider:
- Retained Mistral path through the EU-only adapter; these remote demonstrations remain disabled because they are not in the production-consumer allowlist
- Affects:
- Visitors who run a demonstration
- Lawful basis:
- Art. 6(1)(a) consent — the visitor starts the demonstration
- Retention:
- Uploads are not stored; they are processed for the response and discarded.
- Controls:
- Labelled as a demonstration and not a professional assessment. Own rate-limit bucket so demo traffic cannot exhaust the contact form's quota; image moderation and a spend circuit-breaker before dispatch.
- Homepage campaign personalisationRewrites a page headline to match the marketing campaign the visitor arrived from.
- Risk class:
- Minimal risk
- Provider:
- Mistral AI — see the privacy policy, section 5, for where that processing takes place
- Affects:
- Nobody at present — built, but no page currently mounts it
- Lawful basis:
- Art. 6(1)(f) legitimate interest in relevant marketing copy — no personal data is processed
- Retention:
- Generated copy cached for 24 hours per campaign tuple; nothing about a visitor is stored
- Controls:
- Listed here although dormant, so this register describes what the site can do and not only what it did today. Re-mounting it requires no new personal data.
Recent activity
Last 5 changes shipped to production.
a52c413dfix: normalize deployment copy checks2026-08-0277194efffeat: launch Physical AI decision engineering platform2026-08-029d32b1a2fix(seo,cta): route the definition page at the offer2026-08-01c4de7b42docs,refactor: fold strategy onto the canonical Product System2026-08-01bdbec568docs(strategy): sequence the transformation around 39 gaps2026-08-01
Want this level of transparency for your AI systems?
An engagement ships this same dashboard — composite score, group progress, EU AI Act classification, security posture.