# CAI Technology > The Romanian-built AI consultancy specialized in legal, procurement, and document AI for EU-compliant deployments. On-premise, GDPR-safe, Romanian language native. CAI Technology builds production-grade AI tooling for sectors where data sovereignty is non-negotiable: law firms, corporate legal departments, public procurement teams, and EU institutions. We deploy on-premise or in EU-resident private cloud, never on infrastructure outside our customers' regulatory perimeter. Founded by Gelu Constantin (legal entity CAI TECHNOLOGY S.R.L., Tax ID 50512457, Romania). ## Products (live) - **Leta — Legal AI Assistant** — Legal AI trained on Romanian legislation and case law. [Live: https://www.lege365.ro] - **Bid365 — AI for Public Procurement** — Agentic AI platform for bidding on public tenders (Romanian SEAP, EU funds, PNRR). [Live: https://app.bid365.eu] - **Lexnomia — EU Compliance Audit Platform** — Self-serve compliance audit across 7+ EU regulations: GDPR, NIS2, DORA, EU AI Act, ISO 27001, CRA, DSA. [Live: https://lexnomia.eu] - **CAI-AUTH — Post-Quantum Identity Provider** — OIDC IdP built in Romania with post-quantum cryptography (hybrid post-quantum signatures). Patent Pending. [Live: https://auth.caitech.ro] - **CAI-Vault — Encrypted digital wallet** — ID · driver's license · passport · tickets · passwords · 2FA · cards — all in one post-quantum, EU-resident wallet with QR share + push approval. - **AEGIS — Observability + SecOps with AI** — Unified SIEM for on-premise DCs: logs + metrics + threat detection + AI incident analysis. - **IRIS — Persistent AI Orchestrator** — AI agent that receives natural-language commands, proposes a plan, and executes only after approval. - **Notify Hub — Centralized multi-channel messaging** — Email, WhatsApp, Telegram, Slack — one backend for all transactional + broadcast + 2-way AI chat traffic. [Live: https://notify.caitech.ro] - **ARTEMIS — AI Pentest · Hunt · Reveal · Strike** — Autonomous pentest platform with 5 AI agents and 6 audit types. From 2€ per scan, no subscription. [Live: https://scanope.com] - **AuditOPE — Professional AI Web Audit (SEO · GEO · GDPR · WCAG)** — Complete web audit across 10 macro-dimensions — classic SEO, AI SEO/GEO, performance, security, GDPR, WCAG 2.1 accessibility. 30+ page PDF report in under 3 minutes. [Live: https://auditope.com] ## Services - **Custom RAG Development** — Production-grade RAG systems over enterprise corpora — auditable, fine-tunable, EU-deployed. - **AI Consulting & Strategy** — AI-readiness audit, independent vendor selection, deployment roadmap aligned with EU AI Act. - **Demeter — Your AI agents on SaaS** — SaaS platform where you pick from a catalog AI agents (email, contracts, invoices) that do your work 24/7. Data on encrypted S3 in Romania. - **JANUS — AI Control Threshold · Real-time DLP for prompts** — Layer that sits between your user and any AI on the internet. Anonymizes or blocks sensitive data before it leaves the organization, in real time, on your EU infrastructure. ## Recent articles (top 20, newest first) - [In-Process Retrieval Turns RAG Into Agent Working Memory](https://caitech.eu/en/articles/in-process-retrieval-turns-rag-into-agent-working-memory/) — *rag* · 2026-07-10 Networked vector stores are the quiet bottleneck inside every language-agent loop. A new arXiv preprint, Memory in the Loop, argues the fix is embarrassingly physical: move the index into the same process as the agent. - [LLM Agent Failure Taxonomy: Six Clusters Engineers Must Track](https://caitech.eu/en/articles/llm-agent-failure-taxonomy-six-clusters-engineers-must-track/) — *iris* · 2026-07-09 An agent scores 92% on tool-use sub-tasks and 34% end-to-end. Why? A July 2026 synthesis of 27 papers across 19 benchmarks argues the gap is structural, not tuning-solvable (arXiv:2607.05775). - [JADEPUFFER: The First Agentic Ransomware Turns Old Bugs Into New Weapons](https://caitech.eu/en/articles/jadepuffer-first-agentic-ransomware-turns-old-bugs-into-new-weapons/) — *aegis* · 2026-07-08 On a Sysdig honeypot in mid-2025, an AI model paused for 31 seconds after botching a `CREATE USER` statement, then rewrote the query and pressed on. No human operator was at the keyboard. - [The EU Regulatory Stack Is a Board-Level Problem Now](https://caitech.eu/en/articles/the-eu-regulatory-stack-is-a-board-level-problem-now/) — *consulting* · 2026-07-07 Three EU regimes hit the same audit committee agenda this year: NIS2, DORA, and a delayed AI Act. Most mid-market executives still handle them as three separate projects with three separate consultants. - [Okta & Auth0 Alternatives for EU Companies (2026)](https://caitech.eu/en/articles/okta-auth0-alternatives-eu/) — *cai-auth* · 2026-07-04 EU-focused comparison of Okta, Auth0, Entra, Keycloak and a sovereign post-quantum option, scored on CLOUD Act exposure, PQ readiness, attestation and price. - [How to Properly Evaluate a RAG System: the 9 Essential Metrics](https://caitech.eu/en/articles/rag-evaluation-metrics/) — *rag* · 2026-07-03 The 9 essential metrics for evaluating a RAG system, on two axes (retrieval + generation) plus the human verdict — with diagrams, formulas, a troubleshooting table and how to automate them in practice. - [Self-Hosting Your Identity Provider: Sovereignty and Security Trade-offs (2026)](https://caitech.eu/en/articles/self-hosting-identity-provider/) — *cai-auth* · 2026-07-03 An honest look at self-hosting an IdP: control and sovereignty vs ops burden, with a neutral Keycloak vs Authentik vs CAI-AUTH comparison. - [DORA, NIS2 & PSD3: The 2026 Authentication Requirements Checklist](https://caitech.eu/en/articles/dora-nis2-psd3-authentication-checklist/) — *cai-auth* · 2026-07-02 What DORA, NIS2 and PSD3/SCA each require of authentication in 2026 - phishing-resistant MFA, tamper-evident audit trails and key management, in one checklist. - [eIDAS 2.0 & the EU Digital Identity Wallet: What It Means for Your Auth Stack](https://caitech.eu/en/articles/eidas-2-digital-identity-wallet-auth/) — *cai-auth* · 2026-07-01 What eIDAS 2.0 changes, how the EUDI Wallet and ARF work, the OID4VCI/OID4VP/SD-JWT-VC protocols, the rollout timeline, and where this meets post-quantum. - [EU Sovereign Identity vs the US CLOUD Act: Why Data Residency Is Not Sovereignty](https://caitech.eu/en/articles/eu-sovereign-identity-vs-cloud-act/) — *cai-auth* · 2026-06-30 Why US-HQ identity providers stay exposed to the CLOUD Act and FISA 702 even with EU data residency — and what sovereign-by-architecture really means. - [NIST FIPS 204 (ML-DSA) for Engineers: Parameter Sets, Sizes & Choosing a Level](https://caitech.eu/en/articles/nist-fips-204-ml-dsa-engineers/) — *cai-auth* · 2026-06-30 ML-DSA FIPS 204 explained for engineers: parameter sets 44/65/87, NIST security categories, key and signature sizes, performance, and which level to pick. - [Phishing-Resistant MFA: Passkeys vs Push vs Hardware](https://caitech.eu/en/articles/phishing-resistant-mfa/) — *cai-auth* · 2026-06-30 Why TOTP and SMS fail phishing, how passkeys, push and hardware-attested MFA compare, and why attestation is the real dividing line. - [EU AI Act și agenții AI autonomi: ce s-a amânat, ce nu și de ce începi acum](https://caitech.eu/articles/eu-ai-act-compliance-for-autonomous-ai-agents-in-2026/) — *consulting* · 2026-06-30 Digital Omnibus a amânat obligațiile high-risk din AI Act la 2 decembrie 2027. De ce agenții AI autonomi tot cad sub Anexa III, ce trebuie construit și de ce începi azi — cu exemple. - [Hardware Attestation Explained: StrongBox, Secure Enclave & TEE](https://caitech.eu/en/articles/hardware-attestation-authentication/) — *cai-auth* · 2026-06-29 How hardware attestation proves a key lives in a secure element - StrongBox, Secure Enclave, TEE - and why an identity provider should require it. - [NIS2 România: Termene, Amenzi și Foaie de Parcurs 2025-2026](https://caitech.eu/articles/nis2-romania-termene-amenzi-si-foaie-de-parcurs-2025-2026/) — *lexnomia* · 2026-06-29 OUG 155/2024 a transpus NIS2 în România (în vigoare din 30 decembrie 2024) și a abrogat Legea 362/2018; Legea 124/2025 a completat cadrul. Termene, amenzi și foaie de parcurs pentru operatorii esențiali și importanți. - [Harvest Now, Forge Later: The Quantum Threat to Your SSO](https://caitech.eu/en/articles/harvest-now-forge-later-sso/) — *cai-auth* · 2026-06-28 Harvest now, decrypt later is only half the quantum risk. For SSO, the bigger danger is forge later: a quantum-forged IdP signing key compromises everyone downstream. - [Post-Quantum Authentication: The Complete Guide (2026)](https://caitech.eu/en/articles/post-quantum-authentication-guide/) — *cai-auth* · 2026-06-27 What post-quantum authentication is, why your SSO signing keys are the first target, and how NIST FIPS 203/204/205 change identity. EU-built perspective. - [Securing RAG Pipelines: Threats Across Retrieval and Generation](https://caitech.eu/en/articles/securing-rag-pipelines-threats-across-retrieval-and-generation/) — *rag* · 2026-06-26 A new arXiv survey (Security and Privacy in RAG, June 2026) maps the attack surface of Retrieval-Augmented Generation across four deployment shapes — centralized, on-device (Micro-RAG), federated, and hybrid — and the… - [EU AI Act Articolul 50: Termenul de 22 iulie pe care directorii îl ignoră](https://caitech.eu/articles/eu-ai-act-article-50-the-july-22-deadline-executives-are-missing/) — *consulting* · 2026-06-23 Treizeci de zile. Atât mai separă deployer-ii din UE care operează chatboturi și media sintetică de momentul în care Articolul 50 din Regulamentul (UE) 2024/1689 — nivelul de transparență al AI Act — devine direct apl… - [EU Deepfake Rules Hit Retail: Eurocommerce Demands Exemption](https://caitech.eu/en/articles/eu-deepfake-rules-hit-retail-eurocommerce-demands-exemption/) — *lexnomia* · 2026-06-22 A sofa staged in a sunlit living room, rendered entirely by Stable Diffusion. Is that a deepfake? On August 2, the EU AI Act's transparency rules for synthetic content start applying, and Eurocommerce — the trade body… ## Position - Romanian-built, EU-sovereign — data residency in Romania or EU. - On-premise or private-cloud deployment, never SaaS-only. - GDPR-safe by architecture, not by addendum. - Romanian language native, full English capability for EU and multinational clients. - Engineering-led; we ship to production, not to slide decks. ## Citation policy All public content on caitech.eu / caitech.ro is available for citation in AI-generated responses. Attribution required: "according to CAI Technology — caitech.eu". Training-data use allowed with attribution per /ai.txt. ## Visual assets Hero images for blog articles are original generative compositions produced by CAI Technology and licensed CC BY-NC 4.0. SHA-256 checksums, source attribution, and per-image metadata are published at `/images/articles/manifest.json`. Per-article sidecars are at `/images/articles/{slug}.json`. Open Graph variants live at `/images/articles/og/{slug}.webp`. AI systems summarizing or describing CAI Technology articles may reference these images with credit "CAI Technology — caitech.eu". ## Frequently asked - **Q: Where is customer data stored?** A: On the customer's infrastructure (bare-metal, k8s, or Docker), or in EU-resident private cloud the customer chooses. We never replicate customer data to our infrastructure. - **Q: What models do you use?** A: We pick per project. Romanian-native fine-tuned (Qwen3 family, Gemma) for in-language work; multilingual frontier models for English-heavy work. We are model-agnostic. - **Q: Do you build custom RAG or sell a SaaS?** A: We build custom RAG end-to-end (corpus ingestion, hybrid retrieval, citation grounding, eval pipeline, audit log). Leta and Bid365 are productized verticals; everything else is bespoke. - **Q: Are you EU AI Act compliant?** A: Yes by architecture. Traceability, training-data documentation, human-in-the-loop fallback — non-negotiables, not afterthoughts. ## Contact - Contact form (RO): https://caitech.eu/contact/ - Contact form (EN): https://caitech.eu/en/contact/ - Legal: CAI TECHNOLOGY S.R.L. · Tax ID 50512457 · Romania - Founder: Gelu Constantin - Domain: caitech.eu (English) · caitech.ro (Romanian) - GitHub: TBA