There is no clever trick here, and that's the point. Each layer of the stack runs on your hardware, inside your network, under your accounts. Privacy isn't a policy we promise — it's a consequence of where the machines sit.
Chosen in the assessment, on the basis of what binds your data — not on what's easiest for us to run.
Installed in your own rack. Normal outbound access for updates, which we schedule and document. The common case.
Your tenancy, your keys, your region. Suitable where the constraint is jurisdiction and control rather than physical isolation.
Zero outbound connections. Updates arrive by hand on removable media, verified and logged. For the material that genuinely cannot risk a route out.
A member of staff asks a question. The orchestration layer pulls the relevant passages from your own index, hands them to the local model with the question, and returns an answer with citations back to the source documents. Every step of that round trip happens on machines you can walk up to.
The log of what was asked, what was retrieved, and what was answered stays with you too — which is usually the first thing an auditor asks for.
Bring your constraints and we'll sketch the deployment that fits them. No charge for the conversation or the sketch.