PRIVACY-PRESERVING AGENTS · POWERED BY PETs

Agents that improve your models. Without ever seeing your data

Privacy-preserving agents run on a stack of PETs —
federated learning, secure aggregation, differential privacy.
Raw data never leaves the perimeter.

Request a pilot See how it works
Built for
Healthcare Banking & insurance Public sector Industry & inspection
IN TUNE
DRIFT DETECTED
FINE-TUNING
PERIMETER VENDOR CUSTOMER base model · config · seed gradients · metrics RAW DATA STAYS · ONLY GRADIENTS CROSS
Cycle. Every round
In Tune Drift Detected Fine-Tune In-Perimeter Back In Tune
24w → 6d
Drift response
−50%
Refresh cost
0 bytes
Raw data out
↗ From the Pilot
THE PROBLEM

A vendor can’t reach the
data its model breaks on

Across regulated markets the pattern repeats: data residency, GDPR, HIPAA and sector rules make “just send us the data” a non-starter. You ship the model. Your client holds the data. FedTuna bridges the two.

Model drift
→
Data locked
→
Vendor can’t access
→
Can’t improve
→
Dead end
DRIFT

Models age

New hardware, new cameras, new patterns appear on the client side — and a deployed model quietly degrades.

NO ALERTS

You're blind to it

Drift shows up as customer complaints, not alerts. By then the model has been wrong for weeks.

CLOSED DATA

Data stays closed

Hospitals, banks, insurers and public bodies can’t hand raw records to an outside vendor — policy and regulation forbid it.

DEAD END

A dead end

Without the data, the vendor can’t retune inside the client perimeter — and loses accuracy, trust and the contract.

Time to remediate

Two ways to close the
same incident

The module already sits inside the client’s contour — detection
and repair happen without waiting on a human chain.

The hidden cost

7 manual steps · weeks of delay

The classic model refresh:
a long manual chain

Every step adds delay between degradation and restored quality — and the
cost compounds.

Degradation detected Quality restored
  1. Quality crosses threshold

  2. Engineer / admin gathers logs

  3. Error examples & time windows

  4. Security / legal / anonymization

  5. Root-cause + hypotheses

  6. New model or calibration

  7. Back into the closed contour

Quality crosses threshold

Diagnostic delay
Understanding what broke.
Data-access delay
Getting data that can’t be moved.
ML-team delay
Manual analysis & fix prep.
Deployment delay
Returning the model to the contour.

Result: the model keeps degrading while teams chase evidence.

After FedTuna

4 agent steps · days, not weeks

The same incident, closed in days

The module already sits inside the client’s contour — detection and repair happen without
waiting on a human chain.

Drift detected SLA restored
  1. FRR/FAR or drift stats cross threshold

  2. Local module computes stats in-contour

  3. Agent picks calibrate / fine-tune / escalate

  4. Quality-gated, rollback-safe release

FRR/FAR or drift stats cross threshold

Diagnosis
Agent classifies the drift automatically.
Data access
Stays in the contour — nothing to export.
ML team
Steps in only for real exceptions.
Deployment
Quality-gated, rollback-safe release.

Result: SLA restored — raw data never leaves the contour.

THE TRADE-OFF

Every approach trades
security for usability. We don’t

CHOICE 1

SaaS

Move your data to a vendor cloud.

CHOICE 2

On-premise

Run it all in your own contour.

The product

One agent layer.
A toolbox of PETs underneath

PRIVACY-PRESERVING AGENTS
Interact with & improve models — never touch raw data
PREPROCESS ORCHESTRATE MONITOR
↓ Powered by a toolbox of PETs ↓
PET · CORE

Federated learning

Train across sites; only model updates move.

PET

Secure aggregation

Combine updates without seeing any single one.

PET · CORE

Differential privacy

Provable, bounded limits on what can leak.

PET

Homomorphic encryption

Compute on encrypted data — never decrypt it.

Client perimeter · raw data never moves
Federated learning · a PET in action

Three movements. Nothing else moves

VENDOR CONTOUR
Base model + validation
WEIGHTS · SEED
GRADIENTS · METRICS
PERIMETER
CLIENT CONTOUR
Local data · on-prem
ROUND 0 / 5
01 Connect
02 Train locally
03 Sync gradients
04 Improve
CLIENT FAR FAR — false accepts
0.00 %
CLIENT FRR FRR — false rejects
0.00 %
Shown as example — the loop tracks your own metric (AUC, F1, EER).
Trust & Security

Raw data can’t cross the line

Client perimeter · stays inside
Raw images & records
Identifiers
Client-trained weights
Feature stores
Perimeter Boundary
Perimeter Boundary
Crosses · gRPC + TLS
Gradients Aggregated + DP · unreadable alone
Aggregated metrics
Model version
Attempting to send raw data...
✕  Rejected - raw data cannot cross
Only gradients, metrics & model version ever cross.
Agent architecture

The cloud sends plans only. Gradients and metrics flow perimeter-to-perimeter over gRPC/TLS

Each agent runs as a frontier model or a local SLM deployed in-perimeter — next to the product, in both vendor & customer contours.

CLOUD · FRONTIER AGENTS
Claude / Codex
plan & reason · never see raw data
Deployment details

Runs in FedTuna’s tenant or your own API key. Sees plans and aggregated stats — never raw data, never gradients.

Fully on-prem mode: swap the frontier agent for a local SLM — zero external calls.

TASKS ↓ TASKS ↓
VENDOR PERIMETER
Agents in-perimeter
frontier model or local SLM · touches vendor data
direct · privacy-preserving
statistics & gradients
CLIENT PERIMETER
Agents in-perimeter
frontier model or local SLM · touches client data
TASKS ↓
TASKS ↓
VENDOR PERIMETER
Agents in-perimeter
frontier model or local SLM · touches vendor data
CLIENT PERIMETER
Agents in-perimeter
frontier model or local SLM · touches client data
direct · privacy-preserving
statistics & gradients
Agent ↔ data

How an agent 
touches data

The agent reads & transforms data in-perimeter and emits only privacy-preserving artifacts — raw data never crosses.

Client perimeter · raw data stays
Raw data
↓ read
Local SLM agent reads & transforms
↓ emit
statistics
gradients
metrics
artifacts
TASK
Cloud agent
Claude / Codex
Reasons on artifacts · sends the next task.
Client perimeter · raw data stays
Raw data
↓ read
Local SLM agent reads & transforms
↓ emit
statistics
gradients
metrics
TASK
artifacts
Cloud agent
Claude / Codex
Reasons on artifacts · sends the next task.
The agents

Three agents.
One privacy boundary

01 · MONITOR

Drift-monitoring agent

watches the boundary — on privacy-preserving stats only
See it in the case
Score-distribution & embedding drift, by class
Data / label / concept drift (X→y)
Threshold exceeded → triggers retraining
Runs unattended: detect → retrain → validate. Optional human approval gate.
Verdict mild drift, not OOD
Inside 95% region 98.7%
Action calibrate, not retrain
agent · drift-monitoring cloud

> vendor vs customer · same PCA space

> off-centre on PC1 ······· 0.46σ

> inside vendor 95% region ··· 98.7%

note: concentrated sub-distribution · not OOD

→ recommend: calibrate threshold · no retrain yet

VENDOR vs CUSTOMER · SAME PCA SPACE

Illustrative of a real agent-guided run: Confederate federated fine-tuning & drift analysis (CelebA-Spoof liveness model).

How it works

The agent picks the cheapest sufficient fix

Not every drift needs a full retrain — the agent takes the
shortest path back to SLA.

01 Threshold shift Classes still separate, threshold isn’t optimal Action Adjust threshold
02 Calibration drift Score distribution shifted, model still useful Action Recalibrate
03 Data / covariate drift New market, cameras, devices, population Action Federated fine-tuning
04 Concept drift The X→y relationship changed Action Fine-tune / escalate
05 OOD / unknown case Too far from the known distribution Action Human review
Why this fix
Agent rationale

Sufficient — no retraining needed

01 / 05
Deployment

Drops into the perimeter

Frontier agents reason in the cloud; everything that touches data runs inside the contour. Mix per site.

01
Docker
Containerized — runs inside the perimeter
In-perimeter
02
SDK
Wire agents into the existing stack
In-perimeter
03
Frontier Agent
Claude / Codex — plan & reason, never see raw data
04
Local SLM
Runs next to the product, touches local data
In-perimeter
Boundary cloud reasons on artifacts · in-perimeter touches data
raw data never moves
Works with your stack

Integrations, not abstractions.

The platform ships compatible with tools your team already runs. Whitelist by design — only vetted packages execute inside the customer perimeter.

Visualize training

Stream training and validation curves the way your team already reads them. Baseline MLOps, no extra wiring.

Models, no custom objects

Use any architecture from timm directly.

Supports image, video, tabular & time-series models (deep nets, GBDT, foundation models). No serialization quirks, no custom layers to register.

Whitelisted models

Pull models from a curated whitelist. Vetted for the federated loop, safe for closed-perimeter deployment.

Track experiments

Log runs, compare federated rounds, share dashboards. Optional, off by default — your data, your choice.

FedTuna agents work with your preferred AI models

Anthropic
2 models
Claude Opus 4.8 Claude Sonnet 5
OpenAI
1 model
GPT-5.5
DeepSeek
4 models
R1 V3 Chat V4 Flash V4 Pro
Alibaba Cloud / Qwen
2 models
Qwen 2.5 Coder 32B Qwen 2.5 7B
Events

Where to meet FedTuna

Meet the FedTuna team at AI and technology events
around the world.

Where we're heading

One sovereign platform. Every
regulated domain

Data stays with its owner — only results come out. No tradeoff between security and capability. Already proven in production.  →  Read the case

Healthcare

Imaging, triage, coding — no data export.

External evidence GARTNER · 2026

Gartner places privacy-enhancing computation on the rising edge of its Hype Cycle

Source: Gartner Hype Cycle for Data Science & Machine Learning, 2026 (G00846574).

Try it yourself

Run a pilot on your own data

We don’t need to see it.