Cloud Supply Chain Hack (2025)
A threat actor exfiltrated 6 million records from a major cloud provider's SSO and LDAP systems, compromising credentials of over 140,000 companies.
Fundamentals
A language model that runs on your own servers instead of the cloud, also known as localized AI. Private, controllable, customisable and aligned with the EU AI Act.
How does it work?
Large Language Models (LLMs) are the technology behind ChatGPT, Copilot and similar tools. The difference: we install them in your infrastructure.
Leading open-source models like Gemma 4 — they compete directly with ChatGPT but run 100% on your hardware, without sending data to any external server.
A Mac Studio M3 Ultra can run various models simultaneously. No datacentre infrastructure or thousands-of-euros GPUs needed.
Fine-tuning with your documents, system prompts adapted to your sector, specialised models per department.
We do not offer downloads of protected material. We are a technical consultancy for the implementation of open-source models.
Why it matters
Documented incidents every business should know.
A threat actor exfiltrated 6 million records from a major cloud provider's SSO and LDAP systems, compromising credentials of over 140,000 companies.
Hackers gained administrative access to a leading hyperscaler in under 10 minutes by exploiting compromised credentials and escalating privileges.
Theft of authentication tokens from an AI chatbot gave direct access to CRM platforms, cloud services and corporate workspaces.
An AI agent was manipulated to breach enterprise firewalls with 200,000 automated requests, enabling access to cloud-connected systems.
The Choice
Choosing correctly matters, especially in regulated industries where data privacy is a red line.
| Feature | Cloud (ChatGPT, Copilot…) | Local (Freshlab Iberia) |
|---|---|---|
| Data privacy | Data processed on third-party servers | Data never leaves your premises |
| Operating costs | Growing monthly subscriptions | Only electricity — no recurring fees |
| Internet connection | Always required | Not required (air-gap capable) |
| EU AI Act compliance | Limited transparency, elevated risk | Full control, simplified auditing |
| Customisation | Limited to what the provider offers | Tailor-made models and tools |
| Internal knowledge | Risk when uploading sensitive documents | Secure — RAG module 100% local |
Regulation
Companies with local AI have a structural advantage under the EU AI Regulation.
Data never leaves your infrastructure. No third parties involved. Simplified audits.
Every model decision is auditable. Full inference history for regulatory compliance.
No dependency on OpenAI, Google or Microsoft policy changes. You control versions and updates.
Applications
See our complete pilot package — hardware, software, training and support included.