Deployment models

Five places it can run. One way to build for them.

The same deployment contract and the same developer experience across public cloud, private VPC, on-prem, sovereign, and fully air-gapped — so where your AI lives is a deployment choice, not a rebuild.

Public cloud
Open connectivity
Private VPC
Scoped
On-prem
Internal
Sovereign
In-region
Air-gapped
No outbound
← more elasticmore isolated →
Portability

One contract, promoted unchanged.

Prove a workload in the cloud, then promote the same specification into your most controlled environment — without rewriting it for each one.

01
Cloud pilot
02
Private VPC
03
On-prem
04
Sovereign
05
Air-gapped

Same spec · same developer experience · zero code changes between environments.

The five models

What each environment is for.

Every model carries the same contract and developer experience. What changes is connectivity, control, and the constraints each one is built to satisfy.

01

Public cloud

Connectivity: open
What it is

The CloudsAI contract and developer experience running on hyperscaler accelerators inside your own cloud account.

Why choose it
  • Fastest path to capacity, no procurement
  • Elastic scale for pilots and burst
  • Try accelerators before you buy them
Controls & architecture
  • Runs in your cloud tenancy and VPC
  • Your IAM, your accounts
  • Portable spec — no single-cloud lock-in
02

Private cloud / VPC

Connectivity: scoped
What it is

Self-managed inside your own virtual private cloud, with the cloud operating model but tighter isolation.

Why choose it
  • Network isolation and dedicated capacity
  • Cloud economics, more data control
  • No shared control plane
Controls & architecture
  • Private networking and your VPC boundaries
  • Customer-held keys and policy
  • Peered to existing private services
03

On-prem

Connectivity: internal
What it is

Deployed in your own datacenter, on your own accelerators, fabric, and storage.

Why choose it
  • Data that can't or shouldn't move
  • Long-run cost control on owned hardware
  • Lowest latency to on-prem data sources
Controls & architecture
  • Full physical and network control
  • Integrates with existing fabric & storage
  • Tuned to your topology and accelerators
04

Sovereign

Connectivity: in-region
What it is

In-region, jurisdiction-bound deployment with a local control plane and local key custody.

Why choose it
  • Data-residency and regulatory mandates
  • National and industry compliance regimes
  • Public-sector and regulated buyers
Controls & architecture
  • In-region data and keys, no egress out of jurisdiction
  • Jurisdiction-bound operations
  • Compliance attestation and audit trails
05

Air-gapped

Connectivity: none
What it is

Fully disconnected — the entire factory operates with no outbound connectivity at all.

Why choose it
  • Classified, defense, and intelligence
  • Critical infrastructure and OT networks
  • Highest-assurance enterprise enclaves
Controls & architecture
  • Offline updates via signed artifacts
  • Local model and data custody
  • Verifiable builds and attestation
Sovereign & air-gapped

Where most platforms stop, we keep going.

The highest-assurance environments are first-class, not an afterthought. These are the controls that make a deploy-anywhere claim real in regulated and disconnected settings.

Sovereign

Built to satisfy the jurisdiction.

  • Data residency: data and keys stay in-region by design
  • Jurisdiction-bound control plane and operations
  • Local key management and customer-held custody
  • Compliance attestation and audit trails
Air-gapped

Operates with zero outbound.

  • No outbound connectivity required to run or update
  • Offline updates via signed, verifiable artifact supply chain
  • Local model and data custody — nothing leaves the enclave
  • Build attestation for what runs inside the boundary
What never changes

The environment moves. The experience doesn't.

Whichever model you choose, your teams build against the same contract — and your workloads stay portable across all five.

One deployment spec
Same CLI, notebooks & APIs
Every major accelerator
Tuned networking & storage paths
Secure agent-harness runtime
Zero code changes between models

See how the platform tunes each environment — platform & accelerators ↗

Let's talk

Tell us where your AI must run.

Whether that's a public-cloud pilot or a fully air-gapped enclave, we'll map the deployment model, controls, and architecture to your constraints.