Private AI
Your model. Your boundary.
Where a prompt is allowed to go depends on what it touches — not on which model happens to be fastest or cheapest.
Customer-controlled inference and execution boundaries.
Routing by classification
| Confidential / Restricted | Internal cluster only |
| Internal | Internal cluster or an approved SaaS model |
| Public | An approved external model |
Boundary switches
- External inference
- Internet access
- Telemetry export
- Prompt retention
- Local models (via the gateway)
- Air-gapped operation
Bring your own model — OpenAI-compatible endpoints, Ollama, Anthropic, or Cloudflare AI Gateway / Workers AI — with keys envelope-encrypted at rest.
Who is signed in
Sign-in runs through your own identity provider, not ours.
Sign in with your own identity provider (OIDC with PKCE); no shipped default administrator password.
Your model. Your boundary.
Request a demo