Skip to content
Sectors
Sectors · Vendors

Embed AI in your product without vendor lock-in.

AI product consulting and security for software vendors and SaaS. LLM integration into your roadmap with multi-provider architecture (Anthropic, Mistral, OpenAI, local), token pricing and margin, B2B GDPR data processing agreements, defence against user prompt injection, AI Act transparency.

In 3 sentences

Colombani.ai helps software vendors embed AI in their product without depending on a single model provider. The architecture lets them switch models without interruption, between Anthropic, Mistral, OpenAI or a local model. The cost of calls is controlled and reflected in pricing, each customer's data stays separate, and the agent withstands manipulation. GDPR data processing agreements and AI Act documentation are delivered with the product.

Use cases

Multi-provider LLM abstraction architecture

Abstraction layer that lets you switch between Anthropic, Mistral, OpenAI or a local model without changing your product code. Automatic fallback on provider incidents.

AI feature on customer data (secure RAG)

Semantic search or assistant integration on your customers data, with strict multi-tenant isolation. A tenant can never access another tenant prompts or data.

Token pricing and SaaS margin

Pricing models that absorb LLM cost variability while preserving your margin: plan-based quotas, marked-up pass-through, optional tokens, prepaid.

Contractual documentation and AI Act

Drafting of ToS, DPA, GDPR data processing agreements, AI Act mentions (transparency for generative uses, synthetic content marking). Usable as a basis for your enterprise negotiations.

Ethics and regulatory framework

B2B GDPR, processors and sub-processors

As a vendor, you are a processor for your customers (GDPR Article 28). If you use a cloud LLM, it acts as your sub-processor. Contractual chain to document: client DPA, LLM vendor DPA (Anthropic, Mistral, OpenAI), international transfer if applicable.

AI Act, generative uses and transparency

Since August 2026, obligation to inform the user they are interacting with an AI and to mark synthetic content (art. 50). Colombani.ai helps formalize this compliance in your product flows.

Compliance inherited from customer sector

If your customers are subject to HDS, DORA or PCI DSS, your product must adapt. Colombani.ai identifies applicable requirements and adapts your architecture to be sellable to these regulated customers.

What we don't do

  • End-to-end product development: your team keeps the codebase.
  • UX design: the deliverables scope the AI, not the product overall interface.
  • Product marketing: Colombani.ai does not write your commercial positioning.
  • External DPO role: Colombani.ai helps your DPO or finds one, never in their place.

Frequently asked questions

How do you handle LLM tokens in SaaS pricing? +

Four models exist. A quota included in each plan, billed beyond it. The real cost passed through with a fixed margin. A free product whose AI features are paid by usage. A flat price with a technical cap. The right choice depends on how much consumption varies across your customers and on your commercial strategy: Colombani.ai settles it at the start of the engagement.

How do you isolate prompts between customers? +

Three layers. First, a session ID injected in every LLM call with isolated context (no history re-sharing). Second, tenant-scoped MCP: tools can only query the current tenant data. Third, post-tool validation hooks verify the response contains no data from another tenant. Tested in CI with adversarial scenarios.

Do we need a DPA with Anthropic, Mistral or OpenAI? +

Yes, systematically. Each LLM vendor offers a Data Processing Agreement (GDPR art. 28). Anthropic and OpenAI offer DPAs with zero-training-on-customer-data commitment. Mistral offers dedicated EU instances with adapted DPA. Colombani.ai helps you structure the contractual chain.

Got a project in mind?

Describe your situation. The first 30-minute call is free. Get a frank response within 48 hours.