EVALUATION TOOLKIT

Enterprise AI Agent Platform RFP Checklist

A vendor-neutral checklist to evaluate on-prem AI agent platforms, air-gapped AI deployment, private RAG, sovereign AI infrastructure, BYOM enterprise AI, governance, security, compliance evidence, and predictable pricing. Tick items as you go — your progress is saved in your browser.

On-prem AI Air-gapped AI Private RAG BYOM DORA / EU AI Act
Your evaluation
0 of 66

Checked items are saved locally. Nothing is uploaded.

BUYER ANSWERS

What your RFP should force vendors to answer

These answer-first prompts are written for security, architecture, procurement, and compliance teams comparing cloud-only, hybrid, on-premises, and air-gapped AI agent platforms.

What should an enterprise AI agent RFP require first?

Start with deployment architecture, data residency, model governance, private RAG, auditability, and cost predictability. If a vendor cannot explain where prompts, documents, embeddings, model outputs, and logs go, pause the evaluation.

What is the strongest answer to data sovereignty requirements?

The strongest answer is an architecture where the AI data plane runs on-premises, in your private cloud tenancy, or air-gapped, with no required external inference API and customer-managed identity, keys, models, logs, and storage.

How should regulated teams compare AI vendors?

Score vendors by evidence, not promises: diagrams, control mappings, sample audit logs, subprocessor clarity, offline update process, private RAG design, model inventory, and support for EU AI Act, GDPR, DORA, HIPAA, and NIS2 programs.

EVALUATION METHOD

Use the checklist as a scoring framework

  1. 01

    Start with the boundary

    Document whether the platform must run on-premises, in a VPC, in sovereign cloud, or fully air-gapped. This decides which vendors are viable before feature demos begin.

  2. 02

    Score evidence, not claims

    Ask for reference architectures, data-flow diagrams, audit samples, model-governance examples, subprocessor notes, and patch/update procedures.

  3. 03

    Test one sensitive workflow

    Use a workflow with real access-control, retrieval, approval, and logging needs. A generic chatbot demo will not reveal production risk.

  4. 04

    Model the operating cost

    Estimate inference, storage, vector indexing, seats, connectors, environments, professional services, and support at production volume.

Vendor red flags

  • The vendor says data residency is solved only by choosing a cloud region.
  • Prompts, documents, embeddings, or logs must pass through a shared vendor data plane.
  • There is no clear offline update path for air-gapped or restricted networks.
  • Model governance is described as documentation, not runtime enforcement.
  • Audit logs do not show model routes, retrieval evidence, tool calls, and approvals.
  • Pricing depends on usage meters that procurement cannot forecast at enterprise scale.

What strong vendor answers sound like

Air-gapped deployment

Full platform runs without outbound internet; updates arrive as inspected offline artifacts.

Private RAG enterprise

Embeddings, indexes, citations, and permission checks stay inside customer infrastructure.

BYOM enterprise AI

Customer can approve, run, route, evaluate, and retire models under one governance layer.

Zero data exfiltration

External inference APIs are optional, policy-controlled, and can be fully disabled.

DORA and EU AI Act evidence

Runtime produces inventory, logs, approval records, dependency registers, and technical documentation support.

THE CHECKLIST

Security, governance, deployment, and cost questions

Use each item as a yes/no question during RFPs, security reviews, architecture reviews, and vendor demos. Require written evidence for any answer that affects regulated data or production access.

01

Deployment, isolation & data residency

Where the platform runs, and where your data goes when it does.

02

Governance & compliance

How the platform supports your regulatory obligations and audits.

03

Security & identity

How the platform fits your existing security architecture.

04

Private RAG & knowledge controls

How retrieval works without leaking internal knowledge.

05

Orchestration, BYOM & model control

How agents are built, routed, and governed across models.

06

Operations, monitoring & support

How the platform behaves after the pilot becomes production.

07

Pricing & implementation

What it actually costs, and how you get to production.

Want these answered for your environment?

We will complete this checklist against your specific deployment, security, and compliance requirements — and back it with a reference architecture and security questionnaire response. Start at the Trust Center.

RFP FAQ

Questions procurement teams ask

What questions should be in an enterprise AI agent RFP?

An enterprise AI agent RFP should cover deployment model, data residency, air-gapped support, private RAG, identity and RBAC, audit logging, model governance, BYOM support, compliance evidence, subprocessors, operating model, and pricing predictability.

How do we evaluate an on-prem AI agent platform?

Evaluate whether orchestration, retrieval, embeddings, model inference, logs, and governance can run inside your environment. Then ask for diagrams, evidence samples, SIEM integration details, offline update process, model lifecycle controls, and production support commitments.

What is a red flag in AI agent vendor evaluation?

A major red flag is any architecture where sensitive prompts, source documents, embeddings, or audit logs must leave your perimeter without a clear technical reason, customer approval path, and compensating control.

Should an RFP require air-gapped AI deployment?

Require air-gapped deployment if your environment has no outbound internet, supports defense or government workloads, touches OT or critical infrastructure, or has policy restrictions that prohibit external model APIs.

How should procurement compare token pricing with platform pricing?

Model the cost at production volume: prompts, tool calls, private RAG retrieval, batch jobs, retries, agent loops, users, environments, connectors, support, and infrastructure. Token-only pricing often looks simple in pilots but can be hard to forecast at enterprise scale.

What evidence supports EU AI Act and DORA readiness?

Useful evidence includes AI inventory, risk classification, human-oversight controls, model and dependency registers, audit logs, incident-review data, operational resilience test support, technical documentation, and controlled change history.