Winglo Buildcustom agent program

Your data stays where it is. The agent comes to it.

We build a custom AI agent for one job in your business, deploy it inside your own infrastructure, and hand you the keys. It runs in your EU cloud, on your accounts, under your compliance boundary. We never hold your data — because we never have it.

Fixed price6 weeks to a working agentBuilt by the team behind winglo.ai

Winglo

Outside the line.
We build it, you hold it.
no data
no copies
no standing access
Your compliance boundary eu-central-1 · your cloud account · your keys
Four AI employees, running inside your wallsdial at L1
M
Max
Marketing

Campaign work against your own CRM and content, drafted for your approval.

L1 · approve each action
N
Nova
SEO

Reads your site and analytics in place. Never publishes without a reviewer.

L1 · approve each action
A
Aria
Operations

Runs the recurring task on your schedule, against records that never move.

L1 · approve each action
S
Sarah
Creative

Produces in your voice, from your brand system, stored in your own buckets.

L1 · approve each action
Your documentsnever copied out
Your databaseread scope you set
Model gatewayyour keys · EU · no-training
Approval queueyour people decide
Audit logyour logging stack

Everything above sits in infrastructure you already own and already had signed off. Nothing in this diagram is a promise we ask you to trust — it is an architecture your own team can verify on day one.

§ 01 · the real blocker

You already tried this once. It didn't ship.

Someone on your team built something impressive. A demo that made the room go quiet. Then it went to review, and it never came back. Nine months later it's a parked page in Notion.

Legal asked

Where does the data actually go, who processes it, and which sub-processor sees what. Nobody had a clean answer, so the answer became no.

Security asked

What does it do on a bad day. Not the happy path — the day it's confidently wrong in front of a customer. Silence.

The DPO asked

Which vendor's certifications are we now leaning on, and where are they. You were being asked to inherit somebody else's compliance posture.

And then nobody asked

It quietly stopped being on the agenda. No decision was ever made. That's how most AI projects die — not rejected, just never resolved.

None of those are AI problems. They're architecture problems. So we changed the architecture instead of the pitch.

§ 02 · the program

Six weeks. One job. Running in your tenant.

We don't sell a discovery phase that ends in a slide deck. Week one starts in your cloud account. By week six the agent is doing real work and your team knows how to run it without us.

Week 0
Scoping day

We pick one job worth automating

A day with the people who actually do the work. We map the task, find where it breaks, and decide together whether an agent is the right answer. Sometimes it isn't, and we'll say so — that's a cheaper day than a bad build.

You walk away with
  • A scoped use case, written down
  • The accuracy bar it must clear
  • A fixed price, or an honest no
Weeks 1–2
Build

Deployed inside your infrastructure

Your cloud, your identity provider, your model keys, your logging. We work in a repo you own from the first commit. Your engineers are in the channel, reading the code, asking questions. Nothing is a black box you inherit later.

You walk away with
  • Agent live in your environment
  • Scoped, revocable connections
  • Everything in your own repo
Weeks 3–4
Shadow run

It drafts. Your people decide. We count.

The agent does the job for real, but nothing it produces goes out without a human approving it. Meanwhile we measure: how often it's right, how often it escalates, how often a reviewer changes something. Guesswork becomes a number.

You walk away with
  • Measured accuracy on real cases
  • Escalation and edit rates
  • Every failure written into the tests
Weeks 5–6
Handover

You turn the dial up, not us

With four weeks of evidence, you decide how much rope to give it. Then we hand over the repo, the runbook, the test suite, and the on-call notes — and we train the person who owns it after we're gone.

You walk away with
  • Repo, runbook, test suite
  • A named internal owner, trained
  • An agent still running if we vanish
§ 03 · guardrails

Everyone says "human in the loop." Ask them what it means.

Usually it means a person is blamed when the model is wrong. We build the boundaries into the agent instead, and hand you the tools to prove they hold — including the ones you can use to catch us.

It cites, or it escalates

Every answer points to the document, record, or row it came from. If the agent can't ground its answer, it doesn't improvise — it hands the question to a person. There is no third option.

It does one job and refuses the rest

A general assistant fails in general ways. Yours is scoped to a single task, and asking it for anything outside that scope gets a refusal, not a creative attempt.

A test suite you own and can run

Roughly 120 real cases from your business, with expected outcomes. Not a demo — a suite you run yourself before any change ships, for as long as the agent lives.

Every decision leaves a trace

What it saw, what it concluded, what it did, who approved. In your logging stack, in your retention policy, in a format your auditor accepts.

Autonomy is a dial, not a promise

You don't have to choose between "a human checks everything forever" and "we hope it behaves." You start at the left, and you move right when the numbers earn it. Most clients sit at L2 within a quarter. Turn the dial below — the four employees in the diagram above move with it.

At this settingNothing leaves the building without a person sending it.
§ 04 · verification

What your team gets on day one, before you sign anything.

The architecture only helps if the people who blocked the last project can check it themselves. So the artefacts they need arrive first, not at the end.

01

Deployment and network diagram

Every component, every egress path, every credential and where it is stored. Drawn against your own account structure, not a generic reference architecture.

AnswersSecurity review · "what does it talk to?"
02

DPIA notes and records of processing

A draft assessment written for your DPO, listing the processing, the lawful basis, and the sub-processors — of which, inside the boundary, there are none.

AnswersDPO · "whose certifications are we leaning on?"
03

Access-review and break-glass evidence

Named engineers, time-boxed grants, and the log format each session lands in. Bring it to your next access review and it should pass without a footnote.

AnswersInternal audit · "who can reach production?"
04

A test run your engineers execute themselves

The suite runs in your CI, on your data, with your credentials. The output is a number your team produced — not a demo we drove.

AnswersEngineering · "how do we know it works?"
§ 05 · what we build

Five shapes we've already solved.

We're not a blank canvas, on purpose. Each of these has been built before, which is why we can fix the price and the timeline. Your version is configured to your data, your rules, and your definition of good.

internal knowledgeAAria

Answers from your own documents

Your policies, contracts, specs, and wikis, answerable in plain language with a link to the source. The onboarding question your senior people answer eleven times a month.

Cites the clause, or says it doesn't know
inbound qualificationMMax

Every lead read, scored, routed

Reads the form, the email, the enrichment, and your CRM history. Scores against your real criteria and routes it. Drafts the reply for a human to send.

Never emails a prospect unapproved
document reviewAAria

First pass on the paperwork

Contracts, invoices, claims, supplier forms. Extracts the fields, checks them against your rules, flags what's off and why. Your reviewer starts at the exceptions.

Flags for a human · never decides alone
reportingNNova

The weekly report, written by Monday

Pulls from the systems you already use, writes the numbers up in your voice, and says what changed and what to look at. The same pattern that runs on winglo.ai — in your tenant.

Every figure traceable to its source
support triageSSarah

Sorted and drafted before anyone opens it

Classifies, prioritises, pulls the account context, and drafts a reply grounded in your help docs. Your agent edits and sends instead of starting cold.

Escalates anything angry or unusual
something else?

Tell us on the scoping call

If it's close to one of the five, we'll price it in the same week. If it's genuinely new, we'll tell you honestly whether it should be your first build or your third.

Book a scoping call

We say no to a lot. Anything that needs to make an irreversible decision without a person, anything where being wrong isn't recoverable, and anything where you can't tell us what a good answer looks like. Those aren't agent problems yet.

§ 06 · ownership

Line by line, who holds what.

Most vendors keep this vague. Here it is as a table you can forward to procurement before you forward it to your boss.

Item You own / control Winglo
Infrastructure Your cloud account, your region, your network. AWS, Azure, GCP, or your own datacentre. We deploy into it. We host nothing.
Your data Never leaves your boundary. Not for training, not for debugging, not for support. No copies. No standing access.
Model calls Your API keys, your EU endpoints, your contract with the model provider, your no-training terms. We configure it and pick the model for the job.
Prompts & config In your repository, readable, editable, yours to change without asking us. We wrote them. You keep them.
Test suite Yours permanently, including every failure we found and fixed along the way. We build it and keep adding to it while you're on a retainer.
Logs & audit trail Your logging stack, your retention rules, your export. We see health metrics only — never payloads.
The runtime Licensed to you annually. Source available to your engineers under the agreement. This is the part we own and keep improving. It's how we make money.
Support access You grant it, time-boxed, per incident. You can see every session in your own logs. Break-glass only. Named engineer. No permanent keys.
If you leave Keep running the last version you have, indefinitely. Nothing switches off. You stop getting updates, new models, and our support. That's all.
§ 07 · what it costs

Fixed price. No day rates.

Day rates reward us for going slowly, so we don't use them. You get a number before we start, and we carry the risk of the estimate being wrong.

Week 0
€3,500

Scoping day. Credited in full against the build if you go ahead. If we tell you not to, you keep the map and owe nothing more.

One day · fully credited
First agentmost start here
from€18,000

Fixed price, six weeks, live in your infrastructure. Includes the test suite, the runbook, and training your internal owner.

6 weeks · fixed scope · your tenant
Each one after
from€9,000

The second agent is cheaper because the hard part is already standing in your environment. The fourth is cheaper still.

Same guardrails · shorter build
Runtime licence
from€1,200/mo

The guardrail and orchestration layer, kept current with model releases. Includes support and quarterly test reruns.

Annual licence · billed monthly

One honest caveat: you also pay your own model provider directly, usually €150–900 a month depending on volume. We'd rather you see that bill than have us mark it up quietly.

§ 08 · what clients say
placeholder copy
The build passed security review before it passed our own demo.Placeholder · quote to be supplied
Our DPO signed it off in a week, which has never happened here.Placeholder · quote to be supplied
We own the repo, so the second agent took a fortnight.Placeholder · quote to be supplied
§ 09 · the awkward questions

The ones you'd ask on the call anyway.

We already pay for Copilot. Why would we pay for this?

Copilot is a very good assistant sitting next to a person. It waits to be asked, it doesn't know your rules, and it doesn't own an outcome. What we build does one specific job in your business, on a schedule, against your data, with a measured accuracy number and an audit trail. If a person still has to start every task, keep the assistant. If you want the task to arrive already done, that's a different thing.

Couldn't our own engineers build this?

Probably, yes — the first 80% in about two weeks. The last 20% is what takes six months: the evaluation harness, the refusal behaviour, the escalation logic, the observability, and the boring work of finding the forty ways it breaks on real data. We've paid for that learning already. And we build it in your repo, so your engineers own it afterwards rather than becoming dependent on us.

What happens the first time it's confidently wrong?

It happens. The question is what it costs. At L0 and L1 a person catches it before it leaves the building, which is exactly why we start there. Then the case goes into your test suite so that specific failure can't recur. What we won't tell you is that it never hallucinates — anyone who tells you that is either lying or hasn't shipped anything.

If you can't see our data, how do you support it?

The agent ships health telemetry — latency, error rates, escalation counts, test results. Metrics, never content. When something needs a human, you grant time-boxed access to a named engineer, and the session is logged in your own systems where you can read it afterwards. No permanent credentials, no shared admin account, nothing that would fail your own access review.

Do you have SOC 2 or ISO 27001?

Not yet — those programmes are underway. Here's why it matters less than it usually would: the agent runs inside your environment, under the certifications you already hold, with data that never enters our systems. You aren't being asked to extend your compliance boundary to include us. If your security team wants to verify that claim rather than take our word for it, we'll walk them through the deployment before you sign anything.

How is this related to winglo.ai?

Same team, two ways in. The platform is agents we run for you, hosted in the EU, from €39 a month — the fast path if you want reporting and marketing agents running this week. Build is for when the work is specific to your business or the data can't leave your walls. Most clients end up using both.

Six weeks sounds fast. What's the catch?

Scope. Six weeks buys one job done properly, not a platform. If you want three agents, that's three engagements, and the second and third are faster. The projects that overrun are always the ones where nobody could agree on what a good answer looks like — which is exactly what the scoping day exists to catch.

§ 10 · start here

Bring us the task nobody wants to do on Mondays.

Thirty minutes, no deck. You describe the job, we tell you whether it's a good first build, a bad one, or something you should solve without AI at all. We've talked people out of builds before and we'll do it again — a bad first project poisons the next three.

If it looks like a fit, you'll have a fixed price and a scoping date within two working days.

Three things to have ready
  1. The job. One task, one team, done the same way every week.
  2. Where the data lives, and which cloud you're in.
  3. What "good" looks like — how you'd know the agent did it right.

We reply within one working day. If you'd rather send your security questionnaire first, do that — we'd rather answer it early than late.