Public sector
Procurement conversations in government follow a recognisable order, and it is not the order vendors expect. Capability comes fourth. Here are the three questions that come first, and the honest answers to them.
Yaju Team · 5 August 2026
A demo that impresses a commercial buyer often lands flat in a public sector meeting. This is not conservatism. It is that the room is evaluating a different risk, and the questions that matter to them are usually left until the end of a standard pitch.
These are the three that come first.
Not "is it encrypted", which everyone answers yes to. The question is where processing physically happens, who could compel access to it, and what the arrangement is when the answer stops being acceptable.
Our default is processing inside the European Union, with Barcelona as the primary region, and a deployment can be pinned to a specific location where a contract requires it. Where data cannot leave an organisation's own infrastructure at all, the same Agent Orchestration System runs self-hosted, in your own cloud or fully air-gapped, with identical governance applied to every agent.
On compelled access: unless legally prohibited, we notify you promptly so you can respond to the requesting authority directly. We do not hand over customer data without a valid legal basis.
Public bodies are accountable in a way that is easy to underestimate. A decision may be examined years later by someone who was not present, and "the system did it" is not an answer that survives that examination.
This is why every agent action is recorded in an audit trail that exports on demand, and why policy is enforced at the moment of action rather than described in documentation. The distinction matters: a policy in a document is a statement of intent, while a policy enforced at the point of action is a fact about what could and could not have occurred.
Credentials resolve at runtime from an organisation-level vault, so an agent never holds a secret in clear text and a review can establish exactly which identity did what.
The question behind this one is dependency. A public body that cannot reverse a decision has not made a decision, it has made a commitment.
Practically this means data you can export in full, agents defined in a form you retain, and no architecture that only functions while a supplier relationship continues. It also means budgets that stop rather than warn, so that a pilot cannot quietly become a spending commitment nobody approved.
Not because it does not matter, but because it is the easiest of the four to evaluate and the least likely to be the reason a deployment fails. A capable agent inside a system nobody can audit is a liability. A moderately capable agent inside a system with attribution, policy and an audit trail is something a public body can actually defend.
We would rather have the first three conversations properly than have the fourth one enthusiastically.
The pattern we see work is narrow and boring on purpose. One well-defined category of internal work, not citizen-facing. A named owner. A budget that blocks. An evaluation set written before launch. A review step that a person actually performs rather than nominally owns.
That is slower than a pilot designed to impress. It also tends to be the one still running a year later.
The public sector and deployment pages cover residency and self-hosted options in detail. Our Trust Center covers compliance, subprocessors and how to raise a security issue, and procurement questionnaires can be sent to contact@capconsultor.eu.