Industrial HVAC · cross-cloud

Ask the plant in English. The query stays put.

Facilities and energy teams ask questions across HVAC estates that already span Azure, AWS and on-prem historians. Our engineers shipped a governed question layer so the answer is produced next to the data, not in a public model.

Private Text2SQL across HVAC telemetry on Azure, AWS and on-prem

The problem we were given

Energy and facilities teams could not ask a simple question of the plant. Telemetry sat in three places at once: Azure, AWS, and on-prem SQL and historians. Each vendor controller spoke a different schema. A specialist wrote a new query for every site. A cloud copilot could see one tenant and invent SQL against the rest.

If the question is English, does the SQL still run with the caller database role, in the cloud the data already lives in?

What our engineers built

A governed question layer on Private AI Foundation, inside the delivery environment, not in a public model.

A catalog of approved schemas per environment: Azure stores, AWS stores, on-prem SQL and time-series. A planner that turns English into a bound plan, not free-form SQL. Execution with the caller database role. The model never gets a raw admin connection. The answer comes back with the rows, the SQL that ran, and which environment it hit.

DLP on occupancy and identity joins. No path out of the tenant.

What it is not

It does not write setpoints into the BMS. It does not train on plant data in a vendor cloud. A human still changes the plant.

Why the cloud answer fails here

Plant telemetry, occupancy and energy data often cannot leave the tenant. A query that works in one cloud copilot still cannot see the other historian or the on-prem SQL box. Invented SQL against a live plant is a safety issue, not a convenience.

Controls in this workflow

These controls run on Private AI Foundation. Every ask goes through the same path.

  • Work stays inside the customer perimeter. Inference does not require a network path out.
  • You hold the encryption keys in every tier that touches your data.
  • Every ask goes through the Model Gateway. There is no side door to a public model.
  • Policy and DLP evaluate the request before weights run.
  • RBAC names who may invoke which model class on which data class.
  • Each step writes confidence and a citation back to the source. Originals are preserved.
  • Consequential actions wait for a named approver. Nothing silent-posts to your core systems.
  • Immutable audit is written on the same install: who, what, which model, which policy, outcome.
  • Apache 2.0 and MIT weights only. Licence text and an SBOM ship on disk per release.

The paid proof of value

Thirty to forty-five days. Fixed fee. In the customer environment. One site, one question class, two stores. Success criteria and conversion price agreed in writing before starting. If it misses the threshold, the customer keeps the report and owes nothing further.

A typical first question: which AHUs drifted setpoint against outdoor temperature over a fixed window, answered without copying the data together. Expert-agreed answers, zero unsanctioned SQL, no egress.

Start with one site and one question class.

A paid proof of value, 30 to 45 days, in your own environment. Success criteria agreed in writing before we begin.

Start a paid proof of value

The full stack on one machine, disconnected from the network.

In your office, on your documents, with the cable pulled out. No competitor's sales engineer can do this.

Start a conversation

Requirements

Share your requirement

Tell us what you need. We will reply by email. Book an offline demo when you are ready.

By sending, you agree to our privacy policy.