Built in Pakistan, for institutions whose data cannot leave
Use AI without giving your data away.
Your documents stay on servers you control. Models run where you decide: your own machines, a sovereign cloud, or a frontier provider you have approved. Answers come from your own documents, cited to the section. Every request is checked against your policy and recorded before a model sees it.
with whoever owns the risk
Week 1
your documents answering staff questions
0
of your data leaves without your permission
1
installation, yours alone
6
weeks from install to enforcement
The problem
Your staff already use AI. Nothing inside can do the work, so it goes outside.
This week someone in your institution pasted work into a consumer chatbot: a facility letter, a customer record, a policy memo. Not carelessness. It was faster.
Every three days
The average employee puts sensitive material into an AI tool.
Put your own numbers in
28.7% use AI, the financial services average.
Exposure events
1 every25minutesof the working day
4,731a year
An exposure event is one piece of sensitive material put into an AI tool.
Whatever they type sits on a foreign server. The provider holds the record. You do not.
An enterprise license stops the provider training on your data. It does not change whose court can order it handed over.
The answer they wanted is usually in your circulars. Nothing inside can read those and quote the section.
Blocking the tools does not stop the work. It moves to personal phones, where you cannot see it.
So you have two problems. Data you cannot account for, and work that still has to go outside.
Cyberhaven Labs · 2026 AI Adoption & Risk Report · 222 companies: 83 exposure events per AI user a year, 28.7% adoption.
The working year, 250 days of 8 hours, is our assumption.
How it works
Answers from your own documents, with one door out.
Zyrak does the work your staff take to a chatbot today, inside your boundary. The checkpoint makes it safe to switch on.
Your boundary · one installation, yours alone · in your building or at a Pakistani operator
Four kinds of work
Ask your documents, or their team’s own assistant. Cited to the section.
Their editor’s assistant, through the same checkpoint.
Query the warehouse. Every export is checked and recorded.
Questions on a schedule. Same documents, same record.
- Classify
- Decide
- Record
Nothing is sent.
A person you name approves or declines.
The default: an open-weights model, yours to change. Anything sensitive stays here.
Whole, or redacted first, on a route your policy opened.
The record. Every decision, written before anything moves.
Everything you keep inside.None of it crosses without passing the checkpoint. Zyrak keeps no copy and no way in.
- About your customersCNICs, accounts, statements, complaints
- About your staffSalaries, appraisals, medical claims
- What you ownCredit policy, board papers, pricing, source code
- What your people knowProcedures, case notes, every question they ask
One door out
Only the question, and the paragraphs that answer it. Or run with no door out at all.
A Pakistani data center, over a private link. Nothing kept between sessions.
Outside Pakistan. Cloud contracts you already hold, your own keys. Opens only for the kinds of data your policy names.
Demo
One question, all the way through.
A compliance officer asks whether the bank has missed a deadline. She gets the answer from the bank’s own procedure, cited. On the way Zyrak removes the identifier, keeps the question off the model she picked, and writes the record.
Your boundary
- New chat
- Search
- Workspace
- Notes
Assistants
- Compliance Case Reviewer
Folders
- Complaints
- AML reviews
Chats
- Complaint from CNIC 12345-0123456-0
- Card dispute timelines
- Dormant account rules
- Q2 complaints summary
Complaint from CNIC 12345-0123456-0. She says we have missed the 15-day deadline. She called on June 3 and sent written confirmation of the disputed amount on June 11. Have we missed the working day commitment?
The identifier was removed.Customer identifiers are not approved for the frontier model, so nothing went to it. Answered on the bank’s own model.
Bank’s own modelrerouted
No. The fifteen working day commitment runs from the date the Bank receives the customer’s written confirmation of the disputed amount, and not from the date of the original telephone call1. Counting fifteen working days from June 11 gives July 2, so the substantive response is not yet late.
The register records this as the single most common cause of a missed commitment, and reports it to the Board Audit and Compliance Committee each quarter1.
Send a message…+
Illustrative data · no real institution
What the bank’s own model received
[user] Complaint from CNIC [REDACTED]. She says we have missed the 15-day deadline. She called on June 3 and sent written confirmation of the disputed amount on June 11. Have we missed the working day commitment?
What the frontier model received
Nothing. The request was never sent to it.
The record · seq 23 · chain e1255c63 · exportable
- Identity verifiedH. Siddiqui
Compliance · SSO - Classifieddata_classes
[customer_pii]
detections 1 - Redacteddecision sanitize
redactions 1
mode enforce - Reroutedcustomer_pii/
external_general
block · lift none
answered on the local model - Retrieved & citedComplaints Register v2.1
Section 2 · stored
without identifiers - Recordedhash-linked
exportable
Nothing crossed your boundary
The rules
The rules you are measured against.
Settled
-
In force · January 2023
Keep material work in Pakistan. Sending it abroad needs State Bank approval, case by case.
-
Approved · July 2025
Adopt AI with safeguards and human oversight.
-
Adopted · February 2026
Sovereign infrastructure. Governed AI. Human accountability.
-
Today
Draft · not yet in force
National Data Governance Policy 2026
For federal public bodies and their contractors. Sensitive data stays in Pakistan. Keys may have to stay under Pakistani jurisdiction. Prove compliance, do not assert it.
How Zyrak answers the State Bank’s cloud framework, clause by clause.
- Material work stays in Pakistan unless the regulator approves otherwise.E.2 · Permissible arrangements
- What moves is inspected first, and you control what can be copied out.P.8 · Data security
- Keys generated by you and held by you.Q.4 · Key management
- One record per request, exportable, for your auditor and the regulator.H, J · Oversight, right to audit
Compared
What you already have does half of this.
Your security team calls it shadow AI. Stopping it is half of Zyrak. The other half does the work your staff went outside to get. Each tool below does one half at most.
What you may already have
What it does, and what it does not
A consumer chatbot
Yes: Does the workNo: Stops what leaves
Answers well, but not from your circulars, not under your law, and with no record you hold.
Copilot, enterprise edition
Yes: Does the workNo: Stops what leaves
Keeps your prompts out of training, but every prompt runs on foreign servers, under foreign law.
Microsoft’s in-country processing for Copilot, as announced November 4, 2025 and revised April 3, 2026.
- By the end of 2026
- AustraliaIndiaUAEUnited KingdomUnited States
- In 2027
- Canada
- In 2028
- Japan
- Regional only
- EU and EFTA countries
- Not named
- Pakistan
If Pakistan joined the list, your data could sit in a Karachi data center, on hardware a US company owns, and a US court could still order it handed over.
On June 10, 2025, Microsoft France’s director of public and legal affairs told a French Senate inquiry, under oath, that he could not guarantee French public-sector data would never be passed to the US government without French consent. It had never happened, he added.
The State Bank’s cloud framework requires a bank to get exactly that guarantee from its provider, in the contract. Ask Microsoft to show the clause.
A firewall that inspects AI prompts
No: Does the workYes: Stops what leaves
Stops what leaves, but does none of the work, and the tool it guards is abroad.
An enterprise assistant inside your network
Yes: Does the workNo: Stops what leaves
Inherits your permissions, but never reads the question: a CNIC in the prompt reaches the model as typed.
A clerk sees only what a clerk could already open. So does Zyrak: it grants every document set to named groups and checks the grant on every question.
Nothing scans the reply on the way back. Nothing decides which model may see the case, and nothing records what was removed or where the request went.
An agent platform
Yes: Does the workNo: Stops what leaves
Builds the workers, but nothing decides what an agent may see or send.
Zyrak
Yes: Does the workYes: Stops what leaves
Answers from your own documents inside your boundary, and nothing leaves without passing the checkpoint.
The pilot
Start with one department.
We take a few institutions as design partners: a scoped pilot on non-critical work, and acceptance criteria you set. We build what your reviewers ask for. Start with the team that has the clearest need and the most sensitive data. Adding a team is a settings change, and each team can have its own daily usage limit.
-
Week 1
Installed and answering. Inside your boundary, connected to your directory, one department’s documents loaded. Staff start asking.
-
Weeks 2 to 5
In use, watched. Staff work as usual. The policy records what it would have decided and blocks nothing.
-
Week 6
Enforcement, when you say so. You read the record: what would have been refused, what redacted, what needs changing. Then you turn it on.
Contact
Talk to us.
Thirty minutes with whoever owns the risk. Tell us what you are dealing with, and we will tell you whether we can help.