Private AI

Your model. Your boundary.

Where a prompt is allowed to go depends on what it touches — not on which model happens to be fastest or cheapest.

Customer-controlled inference and execution boundaries.

Routing by classification
Confidential / RestrictedInternal cluster only
InternalInternal cluster or an approved SaaS model
PublicAn approved external model
Boundary switches
  • External inference
  • Internet access
  • Telemetry export
  • Prompt retention
  • Local models (via the gateway)
  • Air-gapped operation

Bring your own model — OpenAI-compatible endpoints, Ollama, Anthropic, or Cloudflare AI Gateway / Workers AI — with keys envelope-encrypted at rest.

Who is signed in

Sign-in runs through your own identity provider, not ours.

Sign in with your own identity provider (OIDC with PKCE); no shipped default administrator password.

Your model. Your boundary.

Request a demo