Qompute AI

Private AI.
Serious engineering.

Deploy private AI, test high-risk AI workflows, and strengthen the systems your business depends on. Work directly with our engineers or explore qore in private preview.

Services
Scoped engagements with stated fees, led by the founders. No product license required.
qore
Our platform for governed local AI. Private preview, by request, reviewed by a person.
Work with Qompute

Three things you can hire us to deliver.

All services and fees
01

AI security assessment and testing

You run AI systems with real authority, or are about to, and need a decision-grade view of how they can be abused and whether you would notice.

You receive
Findings, a prioritized control backlog, and a technical readout; validation of fixes when the scope includes it.
Fee basis
Three weeks, $75,000 fixed fee (USD).
02

Private-AI deployment and integration

You need AI running on data that cannot leave your boundary, on hardware you control, with identity and policy someone can answer for.

You receive
A written plan, a running installation with a configuration record, and runbooks your operators can use.
Fee basis
Scoped in writing; fixed price or capped budget. Assessment from one to two weeks.
03

Embedded security engineering

You know the problem and want it fixed, detected, and owned inside your team rather than described in a report.

You receive
Production controls and detections, validated remediation, runbooks, and a trained owner on your side.
Fee basis
Six weeks, $150,000 fixed; twelve weeks, $275,000 fixed. Coverage and incident support by agreement.

Fees in US dollars, excluding taxes. No engagement requires a qore license, and preview access is granted separately from any service fee.

How an engagement runs

Four steps. The first costs nothing and promises nothing.

Fixed offers have fixed scope and fixed fees. Everything else is scoped in writing after the first conversation.

  1. First conversationForty-five minutes with an engineer. We say whether we fit and which offer applies, or that none does. A conversation, not a free assessment.
  2. Written scopeDeliverables, dates, people, access, and the fee. Adversarial work adds signed rules of engagement. Nothing starts unsigned.
  3. The workOn your systems, with your engineers. Every decision and finding is recorded as we go.
  4. Validation and handoverProof the agreed outcome holds, deliverables your reviewers can use, and a named owner on your side.
qore · private preview

Your intelligence.
Your infrastructure.

qore runs open-weight models and agent workflows on hardware you control, with named users, tool policy, encrypted stores, and a record of what every model and agent did.

Private preview on Apple Silicon macOS, Linux server, and container. Access is by request, not a purchase; no service engagement depends on it.

qore deployment boundary A dashed rectangle marks the customer's security boundary. Inside it: operator identity, a policy engine, the agent runtime with declared tools, a local model server with encrypted stores, and the audit and run records. Outside the boundary sits an optional, administrator-enabled enrichment service reached only through an explicit tool. Nothing else crosses the line. YOUR SECURITY BOUNDARY · A HOST YOU CONTROL Operator identityNamed account · second factor Policy engineRoles · deny-wins policies Agent runtimeTimeouts · iteration cap Declared toolsAllow-list minus deny-list Local model serverOpen-weight modelsSame host Encrypted storesMemory · retrieval Run recordsTrigger · model · tool calls Audit recordsPolicy decisionsForensic logOperational log External APIOptional · opt-in Only through an admin-enabled tool OUTSIDE No hosted model No telemetry No update check
The deployment boundary, derived from the implemented architecture and simplified. Not a product screenshot.
Who does the work

Two principals on every engagement, and on the product.

Company and team

Derek Hinch

Founder and Chief Technology Officer

Founder and architect of qore. Nearly three decades across U.S. Air Force electronic warfare, Amazon cloud security, and enterprise defense. The forensic verifier who attacked the 2017 Zcash key ceremony; author of the quaternion research and qore's cryptography.

Joey Victorino

VP, Infrastructure and Security

Incident responder: nation-state intrusions and ransomware. M.S. Cybersecurity, CISSP, eleven GIAC certifications.

Tell us the problem.

We will say whether we are the right people for it, and what a scoped engagement would look like.