Skip to content
Practice what we preach

Engineering quality, in public

Hyperion's own systems, audited and tracked with the same method an engagement would apply to yours. Numbers, not slides.

Last updated: 2026-08-20

Composite audit score
9.0/ 10
from 6.0

Score from a 20-stream internal audit covering security, observability, dependency hygiene, SEO, and CI/CD.

Composite score from the audit dated 2026-05-01. Not re-scored since.

Audit progress by group

Auth & CSRF8/8 items shipped
SSRF & LLM hardening6/6 items shipped
VPS hardening9/12 items shipped
CI/CD & dependencies10/10 items shipped
Observability3/3 items shipped
SEO & GEO3/3 items shipped

Current security posture

  • State-changing admin routes validate CSRF server-side; read-only GET routes are excluded
  • Dependency advisories are gated in CI; accepted risks must be explicitly documented
  • Post-quantum SSH key exchange enabled (sntrup761x25519-sha512)
  • Mistral API region is explicit and configurable (global or EU); residency is never inferred from provider identity
  • Edge middleware admin gate + JWT pinned to HS256 + per-IP token-budget cap on chat
  • Pre-push hook runs the local gate (lint, typecheck, architecture, i18n, copy checks, unit tests) before push
  • Every GitHub Actions reference is pinned to a full commit SHA; force-push and branch deletion are blocked on main; production deploys run only after CI succeeds on main

Stack disclosure

Framework
Next.js 16 (App Router, RSC-first)
AI runtime
Mistral AI primary runtime · GLOBAL API endpoint configured (not a residency guarantee)
Hosting
OVH VPS (France) — 24 GB RAM, 12 vCPU, PM2 cluster
Locales
8 (en, fr, de, nl, el, ar, ja, zh)

Our own EU AI Act classifications

We use the same classifier an engagement would apply. Each AI-touching surface declared.

Self-classification under the EU AI Act. Article 50 transparency obligations apply from 2 August 2026. None of these systems is Annex III high-risk; none makes a decision producing legal or similarly significant effects on a person. Systems the site runs but that never process visitor input — internal authoring and outbound-research tooling — are listed here as well, so this register is the whole picture rather than the visitor-facing part of it. Dormant systems are listed and marked dormant rather than omitted. This register and section 10.bis of the privacy policy describe the same systems, in the same order, under the same identifiers. (v2026-08-20)

  • Hyperion Brain (site assistant)
    Answers visitor questions about the practice and its services.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Site visitors who choose to open it
    Lawful basis:
    Art. 6(1)(f) legitimate interest in answering enquiries
    Retention:
    Conversation memory 30 days
    Controls:
    Identifies itself as an AI assistant before input is possible; no automated decision about the visitor.
  • JARVIS Decision Navigator
    Routes a visitor's described product decision to the smallest fitting engagement, or to an honest no-fit result, and drafts a cited brief.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Visitors who choose to start the Navigator from /start or an in-page call to action
    Lawful basis:
    Art. 6(1)(f) legitimate interest in qualifying enquiries
    Retention:
    Conversation memory 30 days
    Controls:
    Identified as an AI assistant before any input. It recommends; it does not decide, price or contract. Contact details and booking are a separate, consented step, and operational alerts carry bounded metadata only — never the visitor's free text.
  • AI site search
    Answers a question typed into the site search box from the published corpus, and cites the pages the answer came from.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Visitors who use the search box
    Lawful basis:
    Art. 6(1)(f) legitimate interest in helping visitors find published material
    Retention:
    Answers are cached by query; no visitor identifier is stored with them
    Controls:
    Answer labelled AI-generated and shown with its sources. Rate-limited per client. Keyword search remains available without it.
  • AI Readiness Assessment
    Produces an AI-maturity score and recommendations from a questionnaire the visitor completes.
    Risk class:
    Limited risk — Art. 50(1) transparency. Not a decision with legal or similarly significant effect.
    Provider:
    Deterministic scoring logic, plus Mistral AI — see the privacy policy, section 5, for where that processing takes place for the written recommendations
    Affects:
    Visitors who complete the assessment
    Lawful basis:
    Art. 6(1)(b) performance of the requested service; contact details under the form's own consent
    Retention:
    With the CRM contact record — relationship plus 2 years
    Controls:
    Results are stated to be informational and not professional advice. Deletion on request under Art. 17.
  • EU AI Act risk classifier
    Suggests a risk tier for a system the user describes.
    Risk class:
    Limited risk — regulatory information tool, Art. 50
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Users of the compliance tool
    Lawful basis:
    Art. 6(1)(b) performance of the requested service
    Retention:
    Register entries per the published retention schedule
    Controls:
    Labelled as indicative, not legal advice; a human decides.
  • Use-case generator
    Drafts candidate AI use cases from a described context.
    Risk class:
    Minimal risk
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Users of the tool
    Lawful basis:
    Art. 6(1)(b) performance of the requested service
    Retention:
    Not stored beyond the session
    Controls:
    Output is a draft for human selection.
  • Marketplace AI agents
    Configurable AI agents that registered Marketplace users converse with to produce work for their own projects.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    People who register a Marketplace account and open a conversation
    Lawful basis:
    Art. 6(1)(b) performance of the requested service
    Retention:
    Conversation memory 30 days from last activity; account data per the published schedule
    Controls:
    Each agent is labelled as an AI agent. Project context is read ownership-scoped, so one tenant's brief cannot reach another tenant's agent. Account and data deletion available in the account area.
  • Lead qualification and scoring
    Scores an inbound enquiry to prioritise a reply.
    Risk class:
    Minimal risk under the AI Act; GDPR PROFILING
    Provider:
    Deterministic rules on the contact form (no AI, no third-party look-up). On the gated-resource path: Mistral AI — see the privacy policy, section 5, for where that processing takes place, plus a LinkedIn company look-up and a Mistral web search.
    Affects:
    People who submit an enquiry or gated-content form
    Lawful basis:
    Art. 6(1)(f) legitimate interest in prioritising enquiries; disclosed at collection
    Retention:
    Scores 90 days
    Controls:
    No automated decision with legal or similarly significant effect; a human decides whether and how to reply. Object at dpo@hyperion-consulting.io.
  • Outbound prospect research and scoring
    Researches and tiers organisations for outbound contact.
    Risk class:
    Minimal risk under the AI Act; GDPR PROFILING (Art. 14 applies — data not obtained from the person)
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place, plus public search results retrieved through SerpAPI (United States) and publicly available LinkedIn information
    Affects:
    Named individuals at prospect organisations, sourced indirectly
    Lawful basis:
    Art. 6(1)(f) legitimate interest in business development
    Retention:
    Per the published retention schedule
    Controls:
    Art. 14 notice on first contact; objection honoured immediately and the record suppressed.
  • Proposal drafting
    Drafts a proposal outline from an enquiry.
    Risk class:
    Minimal risk
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    People who requested a proposal
    Lawful basis:
    Art. 6(1)(b) pre-contractual steps
    Retention:
    With the enquiry record
    Controls:
    Never sent without human review.
  • Automated article generation and publishing
    Researches, drafts, translates and publishes insight articles.
    Risk class:
    Limited risk — Art. 50(4) AI-generated content labelling
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place. For English long-form drafting only, the OpenAI Codex command-line tool (United States) may also be used.
    Affects:
    Readers of the published corpus
    Lawful basis:
    Art. 6(1)(f) legitimate interest in publishing
    Retention:
    Published indefinitely until retracted
    Controls:
    Every article carries an AI-disclosure label. The label asserts human review ONLY where a reviewer is recorded; otherwise it states the article was not individually reviewed. A claim gate blocks client/track-record assertions at the write boundary. The Codex path is off unless explicitly enabled, runs read-only and ephemeral with web search off, and a build-time dependency rule permits only the content-authoring module to reach it — visitor and lead data cannot.
  • Attachment text extraction (contact and assessment forms)
    Reads a brief or deck the visitor chooses to attach and returns a short summary, so the visitor does not have to retype it.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place — OCR followed by one summarisation call
    Affects:
    Visitors who choose to attach a file; no upload is required to contact the practice
    Lawful basis:
    Art. 6(1)(a) consent — the visitor initiates the upload; the form works without it
    Retention:
    The file is not stored: it is held in memory for the call and never written to disk or object storage. Only the text the visitor chooses to send is kept, as part of their enquiry.
    Controls:
    Stated at the point of collection before a file is chosen. Type and magic-byte verification, a page cap and a structural PDF inspection run before anything reaches the provider; the summary is shown to the visitor and can be edited or removed before submission.
  • AI Lab public demonstrations
    Hands-on demonstrations of model behaviour — vision, document OCR, speech, prompt-injection and evaluation — so a visitor can judge the practice's technical claims instead of taking them on trust.
    Risk class:
    Limited risk — Art. 50(1) transparency
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Visitors who open a demonstration and supply an input
    Lawful basis:
    Art. 6(1)(a) consent — every demo is opened and fed by the visitor
    Retention:
    Inputs are not stored; they are processed for the response and discarded.
    Controls:
    Each demo is labelled as an AI demonstration. Per-demo rate limits and a spend circuit-breaker bound abuse; image inputs pass a moderation check before dispatch. Outputs are illustrative and make no decision about the visitor.
  • JARVIS industrial demonstrations (plant audit, defect inspection, CSV maintenance)
    Show how a vision or tabular model reads an industrial scene, a part photograph or a maintenance log, as a worked example of the practice's method.
    Risk class:
    Limited risk — Art. 50(1) transparency. Not Annex III: these are demonstrations, not a safety component and not an input to any decision about a person.
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Visitors who run a demonstration
    Lawful basis:
    Art. 6(1)(a) consent — the visitor starts the demonstration
    Retention:
    Uploads are not stored; they are processed for the response and discarded.
    Controls:
    Labelled as a demonstration and not a professional assessment. Own rate-limit bucket so demo traffic cannot exhaust the contact form's quota; image moderation and a spend circuit-breaker before dispatch.
  • Homepage campaign personalisation
    Rewrites a page headline to match the marketing campaign the visitor arrived from.
    Risk class:
    Minimal risk
    Provider:
    Mistral AI — see the privacy policy, section 5, for where that processing takes place
    Affects:
    Nobody at present — built, but no page currently mounts it
    Lawful basis:
    Art. 6(1)(f) legitimate interest in relevant marketing copy — no personal data is processed
    Retention:
    Generated copy cached for 24 hours per campaign tuple; nothing about a visitor is stored
    Controls:
    Listed here although dormant, so this register describes what the site can do and not only what it did today. Re-mounting it requires no new personal data.
Try the classifier

Recent activity

Last 5 changes shipped to production.

  1. a52c413dfix: normalize deployment copy checks2026-08-02
  2. 77194efffeat: launch Physical AI decision engineering platform2026-08-02
  3. 9d32b1a2fix(seo,cta): route the definition page at the offer2026-08-01
  4. c4de7b42docs,refactor: fold strategy onto the canonical Product System2026-08-01
  5. bdbec568docs(strategy): sequence the transformation around 39 gaps2026-08-01

Want this level of transparency for your AI systems?

An engagement ships this same dashboard — composite score, group progress, EU AI Act classification, security posture.

Engineering Quality, in Public | Hyperion Consulting