PRIVATE AND ENTERPRISE DEPLOYMENT

The pilot ran on a laptop. Production runs in your building.

Assistants, agents, document workflows, voice and private models, inside your environment. Proven on your data before release and run by YPAI, with the data, the region and the deletion yours.

THE KNOWLEDGE ASSISTANT 3 documents · 3 questions

Your case files stay in the archive. The assistant reads them there.

Three documents, one question. The assistant finds the passage that answers it and quotes it back, so the reviewer can check the source. Paste your own documents and ask your own question.

The documents

  1. Change control procedure, section 4 Emergency changes to the inference service may be applied by the on-call engineer after approval from the duty manager, and must be recorded in the change log within 24 hours.
  2. Retention schedule, row 7 Prompts and responses on the managed model path are retained for zero days. Application logs are retained for 400 days in the customer's account and deleted by the customer.
  3. Access policy, section 2 Support access to the production environment is granted per incident by the customer's platform owner and expires after eight hours or at incident close, whichever comes first.

Or ask

The answer sample

the duty manager

Quoted from

Change control procedure, section 4. Emergency changes to the inference service may be applied by the on-call engineer after approval from the duty manager, and must be recorded in the change log within 24 hours.

Built by YPAI, running in this tab from weights this site serves. A sample until you run it. No customer data.

WHERE IT RUNS 4 patterns · 1 boundary

Four places it can run. One boundary you sign.

You choose the pattern. The boundary is drawn and counted around it, and your security owner signs it before release. The same systems run in all four.

Pattern 01

Your cloud

Your AWS, Azure or Google account, your region, your identity provider. Model calls leave only over private endpoints you approve, with zero retention on the far side.

  • your account and region
  • private endpoints, zero retention
  • customer-managed keys

Pattern 02

Dedicated EEA tenant

A dedicated tenant inside EEA jurisdiction, run by YPAI. Keys are generated and held by you. Region and deletion stay your decisions.

  • no shared infrastructure
  • keys revocable by you
  • EEA jurisdiction

Pattern 03

Hybrid

Records, retrieval, permissions and actions stay inside. A frontier model outside answers only from context the gate approved.

  • records stay inside
  • names, places, dates held
  • one private path, counted

Pattern 04

Your hardware

Weights, runtime, application and index on hardware you own. Disconnected is claimed after inference, telemetry, updates and support access are shown to stay inside.

  • weights mirrored, hashed
  • no outbound path
  • updates named and scheduled

The pattern is read from your brief and confirmed on reply. Every pattern ships with the same pack and the same envelope.

THE EGRESS MAP 2 approved · 0 unapproved

Two paths leave the building. Both are named.

This is one deployment's map. Two private paths leave it, one to the model and one to monitoring, and the count of unapproved paths reads zero. Switch a public path on and watch the count move.

Inside Outside application document store retrieval index identity provider audit log managed model monitoring public internet

THE DOCUMENT WORKFLOW 5 held inside

Every record has a person in it. The workflow holds the person and moves the record.

An admission note goes through the workflow. The names, places and dates are marked and held inside. The rest, the clinical facts and the task, may cross to a model outside.

As written, held inside

Patient Ola Nordmann, born 12 March 1961, was admitted to Ullevål on 4 May with chest pain. Dr Anne Berg ordered a troponin test and an ECG. Summarise the admission for the discharge letter.

As it crosses

Patient person 1, born date 1, was admitted to place 1 on date 2 with chest pain. Dr person 2 ordered a troponin test and an ECG. Summarise the admission for the discharge letter.

  • patient held
  • admitted Ullevål, 4 May
  • presenting chest pain
  • ordered troponin test, ECG
  • task discharge letter summary
sample result, run it here to verify

5 held inside: 2 people, 2 dates, 1 place. The rest may cross to a model outside.

The record stays where it is stored. The workflow reads it there. Document workflows →

THE RELEASE GATE 8 held-out items · 2 critical

The demo answered the demo questions. Release waits for your cases.

Before release the system is evaluated inside your boundary on sets built from your production data, with hard variants of your own questions. Here the gate runs on eight held-out items. Two are critical. The square at the row end fills when the item passes.

  1. 01 critical Who approves an emergency change? the duty manager
  2. 02 Within what time must the change be recorded? 24 hours
  3. 03 Who applies the change? the on-call engineer
  4. 04 critical How long are prompts retained on the managed model path? zero days
  5. 05 Who deletes the application logs? the customer
  6. 06 hard For how long, if at all, does the managed path keep what was asked? zero days
  7. 07 hard When does support access expire if the incident runs for a day? after eight hours
  8. 08 hard Which role can grant production support access? the customer's platform owner

THE VOICE SYSTEM three seconds · this room

Your users speak in corridors and cabins. The transcript stays with you.

Record three seconds in the room you are in. The take is transcribed in this tab. In your deployment the transcript goes straight to your workflow.

The take

Transcript, sample take

start route guidance to the harbour terminal

Speech data →

Runs in this tab. A sample until you run it. No customer data.

THE VISION SYSTEM one frame · snowfall · dusk

The camera sees the crossing at dusk. The reading is made on your hardware.

One frame from a street camera in snowfall. The detector marks what it finds, with its confidence. In your deployment the frame stays on your hardware and the operator confirms or corrects the reading.

Reading person 0.68. The operator confirms or corrects it before the reading is written.

same frame, run the detector here to verify

Runs in this tab Industry solutions →

THE EU LINE EU inference profile, Frankfurt

Your users write in Norwegian. The model answers in it, from Frankfurt.

Open-weight and fine-tuned models in the Llama and Mistral families, evaluated for the languages your users speak, served on the EU inference profile. The agent acts inside a grant and shows every step.

A private model in Norwegian

Prompt

Oppsummer denne saken for saksbehandleren i to setninger.

Answer

Søknaden gjelder tilknytning til kommunalt vann og avløp for eiendommen i Fjellveien 12, og mangler situasjonskart og samtykke fra nabo. Saken settes på vent til begge dokumenter er mottatt.

Model
Mistral family, EU inference profile
Processed in
eu-central-1, Frankfurt

A worked example, not a live run. The EU inference profile runs it live when that route lands. The AI Implementation service line →

An agent inside its grant

Task

Check the incident against the runbook and file the change request.

Granted for this task

  • read_runbook
  • read_incident
  • draft_change
  • request_approval
  • file_change

Trace

  1. read_runbook runbook 4.2, emergency change
  2. read_incident INC-2231, inference service degraded
  3. draft_change change request drafted, rollback path named
  4. request_approval sent to the duty manager, waiting
  5. file_change blocked, approval outside the grant

Filing the change sits outside the grant, so the run stops there and the trace shows where.

A worked example, not a live run. The agent route shows a live trace when it lands. Enterprise automation →

THE REVIEW 3 questions · 3 documents

The review asks three questions. The deployment answers them.

Most private deployments stop at the same three questions. Each has a document behind it, produced as part of delivery.

The document Egress map Boundary signable

Every path named, approved or closed. Zero unapproved paths at release, counted, with the retention rule per component.

Inside Outside application document store retrieval index identity provider audit log managed model monitoring public internet
unapproved paths
0
approved paths
2
retention on the model path
0 days

Signed before release Switch a path on the map above ↑

The review that stopped the pilot is the one the pack is written for.

THE ENVELOPE 12 numbers

Twelve numbers. The SOW binds each one.

Service specifications for a named deployment profile. The SOW names the target, the architecture, the prerequisites and the measurement method. Production starts after the acceptance evidence passes.

  1. Network boundary 0 unapproved egress paths data boundary
  2. Inference retention 0 days of prompt and response retention data boundary
  3. Availability 99.99% monthly service availability release and operations
  4. Recovery RPO 0 critical writes, RTO under 60 s on the serving path release and operations
  5. Private 70B inference 1 s p95 to first token, 50 ms per token models
  6. Fast 8B inference 250 ms p95 to first token, 10 ms per token models
  7. Release quality 100% required gates, 0 critical findings release and operations
  8. Rollback 5 min to the last known good version release and operations
  9. Audit and keys 100% agreed event coverage, customer-managed keys data boundary
  10. Environments 3 isolated environments release and operations
  11. Actions fail closed outside approved authority data boundary
  12. Model control policy-equivalent targets only models

The SOW binds the selected profile. Production begins after its prerequisites and acceptance tests pass.

THE PACK 10 documents

One pack per workload. Handed over at release.

Written for the people who sign. Ten documents, in the order your review asks its questions, and five of them carry a number the envelope binds.

Contents Deployment pack one workload, the profile named on every sheet Handed over at release
What leaves our environment?
  1. §1
    Data-flow map Every path in and out, named, approved or closed, with the network zones.
    0 unapproved egress paths Drawn above: 0 unapproved paths
  2. §2
    Capability matrix Model, endpoint, tool, cache and logging, for every zero-retention path.
    0 days of prompt and response retention
  3. §3
    Key and region matrix Which keys are customer-managed, and where each component processes.
  4. §4
    Identity and agent scoping Who and what may act, with the approval limit for every agent.
    fail closed outside approved authority
Does it work on our data?
  1. §5
    Evaluation suite and acceptance report Critical criteria and protected slices, run on your cases and reported before release.
    100% required gates, 0 critical findings Not yet run on this page
  2. §6
    Provenance, SBOM and release evidence Signed provenance, the bill of materials and the release evidence for every production artefact.
Who runs it after go-live?
  1. §7
    Release and rollback procedure How a release goes out, and how it comes back.
    5 min to the last known good version
  2. §8
    Runbook, ownership and handover Who runs what after go-live, and how it is handed over.
    Opened in the review above
What do we show the regulator?
  1. §9
    AI Act deployer evidence Assigned oversight, monitoring and log retention, as the Act asks of a deployer.
  2. §10
    DPA and subprocessor list The data processing agreement and every subprocessor named.

Signed by your security owner before release. 10 documents · 5 numbers the SOW binds

The pack is the deployment on paper. The review reads it before production.

THE BRIEF

Three lines are enough. What it does, where it must run, what must not leave.

The boundary you sign starts as these three lines.

The system, or the pilot and where it stopped. Your cloud, an EEA tenant, a hybrid split, or your hardware. The records, the index, the keys.

A named project lead reads it and replies within 24 hours with the pattern, the prerequisites and a first read on the boundary.

BEFORE YOU SCOPE

What security, compliance and platform ask first.

Can the complete system run inside our environment?

Where the selected models, licences, infrastructure and dependencies support it. Inference, retrieval, application state, logging, updates and operational access are checked against the same envelope: 0 unapproved egress paths and an explicit retention rule per component. A system is described as fully private only when every material process runs inside.

Can sensitive data remain inside while an external model is used?

In a hybrid design, source documents, retrieval, permissions and actions stay inside and only approved context reaches the external model. That hop uses 0-day prompt and response retention while stateful components keep their own approved storage and deletion rules.

Do you support on-premises or air-gapped environments?

Where the model, licence, hardware and update process permit it. Disconnected is claimed after inference, telemetry, package retrieval and support access are shown to stay inside the boundary, with unapproved egress at 0.

Our pilot stalled at security review. Where do we start?

With the boundary. We draw it for your pattern, count what crosses, and hand security the egress map and the retention and key matrix. The pilot is then evaluated inside it on your own cases before anyone decides on production.

Who operates the system after launch?

YPAI can transfer the deployment to an internal owner or continue under an agreed monitoring and update scope. Ownership, access, the availability profile and its prerequisites, RTO, RPO and escalation paths are defined before production.

Does private deployment make the system GDPR compliant?

Location, 0 unapproved egress paths and a retention matrix support the applicable obligations. Roles, purposes, transfers and subprocessors belong in the DPA and the organisational framework, which the pack carries.

You name what you bring and where it must run. We build it there, prove it there, and run it with you.

The AI Implementation service line covers discovery, architecture and the deployment itself.