Air-gapped AI deployment inside your perimeter

First the perimeter, then the models

We design where models, prompts and the knowledge base live, who can access them and what gets logged. Without this design a private AI does not pass your security team; with it, it does - before hardware is bought.

What we build

Your security team forbids sending documents to public AI models - and they are right: contracts, customer bases and policies must not go to an outside provider. Meanwhile staff already paste them into chatbots from their phones. A closed perimeter solves both: the model runs inside your network, access is role-based, every query stays in the log. We design the perimeter around your policies and the laws that apply to you, and agree it with security before GPUs are bought.

  • Personal data

    Personal data is processed and stored inside your perimeter, in your jurisdiction, with no transfer to a foreign cloud.

  • Critical infrastructure

    For government bodies and strategic enterprises: a perimeter without foreign cloud services on critical sites.

  • Trade secrets

    Prompts, documents and the knowledge base stay with you; access is role-based with a log of who asked the model what.

  • Hybrid with the cloud

    Sometimes non-sensitive tasks are cheaper in the cloud. We fix the boundary between cloud and perimeter in the architecture, not just in words.

What the work includes

Priced per task, estimate within 1–2 days after the brief. Hardware and data centre costs are listed separately.

  • Requirements review: personal data, critical infrastructure, security policies, integrations
  • Perimeter design: network segments, storage, gateways, redundancy
  • Roles and access via your SSO, logging of model queries
  • Rules for prompts and the knowledge base: what can be uploaded and who sees it
  • Pilot scenario and acceptance criteria
  • Hardware and site requirements for the next stage

How we work

  1. 01

    Requirements

    We clarify which data must not leave: personal data, trade secrets, critical infrastructure. We record your security team’s requirements and the use case behind the project.

  2. 02

    Perimeter architecture

    Where models, the knowledge base and logs live, who can access what, and how the perimeter connects to your systems. The design is agreed with security before any hardware is bought.

  3. 03

    Pilot inside the perimeter

    4–8 weeks on a real task: model, documents, roles. Acceptance criteria - share of correct answers with a source, speed, hand-offs to people - are agreed upfront.

  4. 04

    Fine-tuning and scaling

    If a base model with document search is not enough, we fine-tune it on your data. Users, use cases and capacity grow with the load.

  5. 05

    Support

    Monitoring, model and knowledge base updates, incident handling. The perimeter and the code stay yours.

Questions

What is a closed AI perimeter?

Models, the knowledge base and logs inside your perimeter: staff work with AI while data never reaches an outside provider. It is for companies with personal data, trade secrets and strict security rules.

Does it replace our security policy?

No. We build the technical perimeter around your policies and agree it with your security team.

Where do we start if we have no GPUs yet?

With the perimeter design and a pilot on available hardware. GPU purchase is planned once the load is clear: how many users, which documents, which model.

Can it be combined with the cloud?

Yes, for tasks without sensitive data. Critical data stays inside the perimeter, and the boundary is written into the architecture.

The perimeter is live - next comes support

After launch we support the perimeter: model and knowledge base updates, monitoring, incidents and improvements under a contract or an SLA.

SLA support →

A quote in 1–2 days

Name the process that eats time. You get a pilot range, not a 40-slide deck.

Or message us