industries · Telco

NIS2 and communications secrecy, with the traffic on your own network

Operator-scale volume and operator-grade sovereignty: voice and interactions at near-zero marginal cost, on EU infrastructure with an on-premise option and zero logs.

compliance

Compliance, built into the stack.

Every regulatory demand mapped to a platform capability that ships built in, with nothing to configure.

NIS2

Directive (EU) 2022/2555 · national transposition under way in Spain

RequiresTelcos are essential entities: cybersecurity risk management, incident reporting and supply-chain risk, including the AI provider.

HelmcodeAn auditable EU provider with a dedicated or on-premise option: fewer moving parts in your supply chain and a documented, resilient stack.

Communications secrecy

Secrecy of communications (Art. 18.3 Constitution / telecoms law)

RequiresCustomer communications cannot pass through an opaque third-party API.

HelmcodeZero logs by architecture and EU-only inference; on-premise keeps traffic and content inside your network.

GDPR

Regulation (EU) 2016/679

RequiresTraffic and customer data demand minimization and control over transfers, at operator volume.

HelmcodePrompts and responses are never stored or used to train models, processed only on EU infrastructure.

This page is an informational overview, not legal advice. For your obligations and the risk classification of each system, consult qualified legal counsel. AI Act Guide →

how the supply chain gets assessed

What NIS2 makes you ask a supplier.

Article 21(2)(d) of NIS2 makes supply chain security a duty for every essential and important entity, and in 2024 the Commission spelled out what that means in practice. ENISA then wrote the implementation guidance, with the authorities for secure electronic communications among those consulted. Four of its criteria describe an inference provider.

01

Lock-in is a security criterion

Point 5.1.2(d) puts the ability to diversify sources of supply and limit vendor lock-in among the criteria for selecting a supplier, and the guidance measures it by open and interoperable standards, open data formats and proprietary features. Portability stops being a commercial preference.

02

Jurisdiction and ownership are on the list

Among the criteria to weigh, the guidance names the supplier’s legal jurisdiction, whether it is itself regulated under NIS2 or the Cyber Resilience Act and where, and its corporate ownership. That is the sovereignty question arriving as a cybersecurity criterion rather than as a sales pitch.

03

Open source may not be a supplier at all

The guidance says open source communities and projects may not count as direct suppliers where the only relationship is a standard copyright licence. It does not make the risk vanish, it moves it: your register lists whoever you actually contracted, and the code stays open to inspection.

04

The register is yours to keep

Point 5.2 asks for an up-to-date register of direct suppliers with contact points and the ICT products and services each one provides, and the policy reviewed at least annually. Nobody sells you that. What a supplier can do is be simple enough to describe in one line of it.

ENISA · European Union Agency for Cybersecurity "Technical implementation guidance on cybersecurity risk management measures", version 1.0, June 2025, written with the NIS Cooperation Group and the Commission. It elaborates the Annex to Commission Implementing Regulation (EU) 2024/2690, which details Article 21(2) for the digital infrastructure and ICT service management entities in its scope. The guidance itself is non-binding, and ENISA offers it as useful to other entities too. read the report →

use cases

Your most common use cases.

The cases with the most traction in the sector, each with its own page in detail.

Recommended open models.

A starting point per task type. The full guide maps 80 cases to the open model for each one.

Whisper large-v3MIT · STT in Helmcode
Transcription at scale; pair with Kokoro for the full open voice pipeline.
DeepSeek V4 FlashMIT · 1M ctx in Helmcode
Support, summaries and analysis at operator volume, on a flat rate.
Llama 4 ScoutLlama · 10M ctx
Extreme context for long transcripts and session-wide analysis.

in progressWe are distilling and quantizing these open models into small, tightly specialised versions, trained for one task rather than for all of them. A model like that runs on less hardware, answers faster and fits where the big one does not, your own datacenter included. If you have a process with volume and stable criteria, that is the conversation we want to have with you.

// faq

Questions, answered.

What the sector's technical, compliance and business teams ask.

What does NIS2 require from a telco using AI?

NIS2 (Directive (EU) 2022/2555) treats telcos as essential entities, with cybersecurity risk management, incident reporting and supply-chain risk obligations, and its Spanish transposition is still under way. An auditable EU provider with an on-premise option reduces third-party exposure in your supply chain; the concrete national obligations will firm up as the transposing law is enacted.

How do you protect the secrecy of communications?

Customer communications never pass through an opaque foreign API: inference runs on EU infrastructure with zero logs, and on-premise keeps traffic and content entirely inside your network.

Does the cost hold at operator volume?

Yes. Pricing is a flat rate per API key, not per token, so cost per interaction stops scaling with volume, exactly the profile a contact operation with millions of calls needs.

Can we run the voice pipeline entirely open?

Yes: Whisper for speech-to-text, an open LLM for the logic and Kokoro for text-to-speech, all on EU infrastructure or on-premise, with no closed API in the loop.

How does it integrate with our current stack?

The API is OpenAI-compatible: change the base URL and key and your SDKs and pipelines keep working unchanged.

// get started

START BURNING TOKENS

Skip the AI infra work. Deploy your first private inference endpoint today.

Flat rate. EU data. OpenAI API compatible.