Deployment

Deployed where you decide. Controlled by you.

The platform installs inside your environment on infrastructure you control. There is no vendor cloud, no external account, and no telemetry — the deployment model is a security control, not a convenience trade-off.

Deployment profiles

Six supported shapes

On-premises core

Hardened container package for a single-environment deployment, installed by your ops team on your servers.

Enterprise Kubernetes

Stateless replicas plus a durable worker, suitable for customer-operated clusters.

Private / hybrid cloud

Architecture compatible with Azure Local and hybrid environments for Microsoft-heavy estates.

Connected private

Runs in your network with governed, signed update paths — no other external dependency.

Air-gapped

No external connectivity required. Updates and licences transfer offline as signed, verifiable files.

Pilot deployment

Laptop-class or single-server install for a fixed-scope pilot, upgradeable to production profiles.

Shared responsibility

Who runs what

Shared responsibility boundaries
AreaCustomermAIb Tech
Infrastructure, network, physical securityOwns and operatesDocuments requirements
Identity provider and user lifecycleOwns (your Entra/OIDC tenant)Integrates and enforces roles in-product
Knowledge approval decisionsYour administrators approveProvides the governed workflow and enforcement
Product updatesApplies via signed packagesBuilds, signs and documents releases
Backups and restore drillsOperates on your storageProvides tooling and drill procedure
Support accessGrants explicitly, time-limitedOff by default; every session audited

Deploy private AI without surrendering control.

A briefing takes one call. No obligation, NDA available on request, and technical or executive sessions to suit your team.