SECURITY & DEPLOYMENT TRUST CENTER

Private by architecture, not by policy.

VDF AI is an on-prem AI agent platform for regulated enterprises that need air-gapped AI deployment, private RAG, sovereign AI infrastructure, and customer-managed everything. Nothing depends on an external inference API. This is where security, compliance, and procurement teams find how it works.

On-premises Air-gapped Private cloud / VPC Bring-your-own models
Get the RFP checklist
100% on-premises deployment runs inside your data center, VPC, or air-gapped network
Zero data leaves your perimeter prompts, documents, and embeddings stay under your control
Bring-your-own models and identity your models, your SSO, your keys, your audit trail
DIRECT ANSWERS

Short answers for security and AI search

These are the questions buyers, auditors, and AI answer engines ask first when comparing cloud AI, on-prem AI agents, sovereign AI infrastructure, and air-gapped deployments.

How do you deploy AI agents without sending data to external APIs?

Run orchestration, private RAG, embeddings, model inference, logging, and governance inside your own perimeter. VDF AI is designed so prompts, documents, embeddings, model outputs, and audit logs stay on-premises, in your private cloud, or in an air-gapped environment.

What does zero data exfiltration mean for enterprise AI agents?

It means the production data plane has no required path to third-party model APIs. Network egress can be disabled, models can run locally, and security teams keep control of identity, keys, retrieval indexes, logs, and update approval.

What is private RAG for regulated enterprises?

Private RAG grounds answers in your own documents and databases while keeping retrieval, vector indexes, embeddings, source permissions, and citations inside your controlled infrastructure.

DEPLOYMENT MODELS

Deploy it where your data has to stay

Every model runs inside a boundary you control. Choose the isolation level your regulators, security team, and infrastructure require — the platform is the same.

Maximum isolation

Air-gapped

The full platform — orchestration, routing, retrieval, and models — runs on networks with no outbound internet access. Updates arrive through a controlled, offline artifact process.

  • No outbound connectivity required
  • Offline model and update delivery
  • Suited to defense, government, and OT/critical infrastructure
Most common

On-premises

Deployed on your own hardware in your data center. Data, models, and logs remain inside your infrastructure and identity boundary, governed by your existing controls.

  • Your hardware, your network zones
  • Integrates with existing IAM, SIEM, and secrets management
  • Full residency and sovereignty control
Cloud-native

Private cloud / VPC

Deployed into your own cloud tenancy (AWS, Azure, GCP, or sovereign cloud). You keep the account, the network policy, the encryption keys, and the data plane.

  • Single-tenant in your own account
  • Customer-managed keys (BYOK / KMS)
  • Region-pinned for data residency
THE CONTROL PLANE

The controls your security team expects

VDF AI plugs into the identity, logging, secrets, and network controls you already run — it does not ask you to trust a new external service.

01

Identity & SSO

Integrates with your existing identity provider over SAML or OIDC (Entra ID, Okta, Keycloak, LDAP). No separate user store to manage, no shadow accounts.

02

Role-based access control

Granular RBAC governs who can use which agents, models, tools, and data sources. Access to sensitive workflows and connectors is scoped by role, team, and environment.

03

Audit logging

Every prompt, tool call, retrieval, model route, and response is recorded with actor, timestamp, and context. Logs stream to your SIEM for retention and investigation.

04

Model governance

You control which models are approved, where they run, and which workloads may use them. The router enforces model policy per domain, sensitivity level, and residency requirement.

05

Private retrieval (RAG)

Retrieval runs against your own document stores and vector indexes inside your perimeter. Embeddings are generated locally; no content is sent to third-party APIs.

06

Network isolation

Deploys into segmented network zones with no dependency on external inference endpoints. Egress can be fully disabled for air-gapped and OT environments.

ARCHITECTURE BEATS POLICY

Cloud AI vs on-prem AI: compliance and risk comparison

Policies and contracts are necessary, but regulated AI deployments also need enforceable technical boundaries. The architecture should make the safe path the default path.

Decision areaTypical cloud AI platformVDF AI private deployment
Inference path Prompts and context are commonly sent to an external model endpoint. Models can run inside the customer perimeter; external inference is optional and can be disabled.
Retrieval and embeddings Documents and embeddings may be processed or stored in provider-managed services. Private RAG, embeddings, indexes, and citations stay in customer-managed infrastructure.
Data residency Residency depends on provider regions, subprocessors, service settings, and contractual controls. Data plane is pinned to the customer data center, private cloud tenancy, sovereign cloud, or air-gapped network.
Audit evidence Audit detail is limited by the provider’s platform events and retention model. Prompt, retrieval, model route, tool call, response, and approval events stream to your SIEM.
Change control Platform, model, and policy changes may follow the vendor’s release cadence. Customer-approved artifacts, model versions, and updates support regulated change windows.
Cost model at scale Per-token, per-run, or consumption meters can make broad agent adoption hard to forecast. Platform pricing and customer-owned capacity support predictable scaling across teams.

Policy is not the perimeter

Contractual promises matter, but regulated buyers also need a technical boundary that prevents data from leaving in the first place.

Evidence should be generated by runtime

Audit logs, model routes, retrieval citations, and approval records should be captured automatically as work happens.

Control should sit with the customer

Identity, keys, models, network policy, data stores, and retention should be governed by the enterprise operating the system.

COMPLIANCE MAPPING

Mapped to the regulations you answer to

On-prem deployment is the most direct way to satisfy data-residency, sovereignty, and third-party-risk obligations. Here is how the architecture supports each framework.

FrameworkCompliance support
EU AI Act Risk classification, human oversight, traceability, and technical documentation for governed AI workflows.
VDF AI supports EU AI Act compliance programs with AI inventory, use-case risk classification, human-oversight controls, change history, audit logs, and technical documentation generated from governed workflows.
GDPR Data residency, purpose limitation, minimization, and deletion workflows for personal data.
Data stays in-region and inside your perimeter; no production prompt or document processing is required by external model providers. Customer-managed retrieval and storage support minimization, purpose limitation, retention, and erasure workflows.
DORA Operational resilience evidence for ICT risk, incident review, testing, and third-party dependency reduction.
On-premises and air-gapped deployment reduce reliance on external inference providers as operational dependencies. Full audit trails, model governance, offline update controls, and SIEM integration support resilience testing and incident reporting programs.
HIPAA PHI containment, access control, audit logging, authentication, and encryption support.
For healthcare deployments, PHI can remain inside the covered entity’s environment. Customer-managed access controls, audit logs, authentication, network segmentation, and encryption support Security Rule-aligned AI-assisted clinical and administrative workflows.
NIS2 Cybersecurity risk-management support for essential and important entities.
Air-gapped, on-premises, and network-isolated deployment options help essential and important entities keep critical AI workflows under local control, with logging, access controls, incident investigation data, and supply-chain visibility.
EU AI Act How it works + evidence

VDF AI supports EU AI Act compliance programs with AI inventory, use-case risk classification, human-oversight controls, change history, audit logs, and technical documentation generated from governed workflows.

Evidence reviewers can request

  • AI system inventory with owner, purpose, model, tool, and data-source metadata
  • Approval gates and role-scoped permissions for high-impact workflows
  • Run logs that show prompt, retrieval, model route, tool call, response, and reviewer action
Read the related resource
GDPR How it works + evidence

Data stays in-region and inside your perimeter; no production prompt or document processing is required by external model providers. Customer-managed retrieval and storage support minimization, purpose limitation, retention, and erasure workflows.

Evidence reviewers can request

  • Region-pinned data plane and customer-controlled storage
  • Document-level access control inherited from enterprise identity
  • Configurable retention and deletion procedures for indexes, logs, and source connectors
Read the related resource
DORA How it works + evidence

On-premises and air-gapped deployment reduce reliance on external inference providers as operational dependencies. Full audit trails, model governance, offline update controls, and SIEM integration support resilience testing and incident reporting programs.

Evidence reviewers can request

  • Dependency register for models, runtimes, connectors, and infrastructure services
  • SIEM-exportable audit events for detection, investigation, and reporting
  • Controlled patch and update procedure for private and air-gapped networks
Read the related resource
HIPAA How it works + evidence

For healthcare deployments, PHI can remain inside the covered entity’s environment. Customer-managed access controls, audit logs, authentication, network segmentation, and encryption support Security Rule-aligned AI-assisted clinical and administrative workflows.

Evidence reviewers can request

  • SSO and RBAC controls for workforce access
  • Audit controls for prompts, retrieval, tool calls, and outputs
  • Customer-managed keys and deployment inside the covered entity’s boundary
Read the related resource
NIS2 How it works + evidence

Air-gapped, on-premises, and network-isolated deployment options help essential and important entities keep critical AI workflows under local control, with logging, access controls, incident investigation data, and supply-chain visibility.

Evidence reviewers can request

  • Network-isolated deployment patterns for critical and OT-adjacent environments
  • Role-based access, least-privilege tool controls, and human review gates
  • Audit evidence for incident handling and post-incident review
Read the related resource

This mapping describes how the platform’s architecture and controls support your compliance program. It is not legal advice; obligations depend on your deployment, jurisdiction, and use case.

SECURITY FAQ

Questions security teams ask first

Does any data ever leave our environment?

No. VDF AI is designed to run entirely inside your infrastructure — on-premises, in your private cloud tenancy, or fully air-gapped. Prompts, documents, embeddings, model weights, and logs remain inside your perimeter. There is no requirement to call an external inference API.

Can we use our own models?

Yes. VDF AI is model-agnostic and supports bring-your-own-models. You choose which open-weight or licensed models to run, where they run, and which workloads may use them. The router enforces your model policy per domain, sensitivity, and residency requirement.

How does VDF AI integrate with our identity and security stack?

Authentication uses your existing SSO over SAML or OIDC. Authorization is governed by role-based access control. Audit events stream to your SIEM. Secrets integrate with your existing vault, and encryption keys can be customer-managed.

What can you provide for our security and procurement review?

We provide a reference architecture, an RFP/evaluation checklist, deployment and network diagrams, a compliance mapping, and a security questionnaire response. We can also join a security architecture review with your team.

Do you support fully offline, air-gapped deployment?

Yes. The complete platform — orchestration, routing, retrieval, and models — can run with no outbound internet access. Updates and models are delivered through a controlled offline artifact process suited to defense, government, and OT networks.

How do we deploy AI agents without sending data to external APIs?

Deploy the full data plane inside your own environment: identity, orchestration, private RAG, vector indexes, embeddings, model runtime, audit logs, and admin controls. In this pattern, external inference APIs are not required, and egress can be disabled for sensitive networks.

How does the offline update process work for air-gapped AI deployments?

Updates are packaged as signed artifacts that your team can inspect, approve, transfer through your existing offline media process, and install from an internal registry or artifact repository. The air-gapped runtime does not need outbound internet access.

How does VDF AI support model governance?

Model governance is enforced through an approved model catalog, version history, policy-based routing, workload permissions, evaluation records, and audit logs showing which model handled each request. You decide which models are allowed for each domain and sensitivity level.

Can VDF AI integrate with our SIEM, SOAR, or GRC tooling?

Yes. Audit events can be exported to your SIEM, routed into incident-response workflows, and used as evidence for GRC processes. Typical events include actor, agent, data source, model route, tool call, response, approval, and timestamp.

How does private RAG work in an on-prem AI platform?

Documents remain in your approved stores or are indexed into your private vector database. Embeddings are generated locally, retrieval respects document permissions, and responses cite source material without sending content to third-party model providers.

Can we bring our own embedding models, LLMs, and serving runtime?

Yes. VDF AI is designed for BYOM enterprise AI: bring your own models, embedding models, serving runtime, GPU infrastructure, identity provider, keys, and monitoring stack. The platform governs the workflow above those components.

What evidence do auditors and security reviewers usually ask for?

They usually ask for architecture diagrams, data-flow diagrams, access-control design, model inventory, risk classification, retention policy, subprocessors, patch process, incident logging, vulnerability-management process, and sample audit records.

How does VDF AI support DORA compliance programs for financial services?

VDF AI supports DORA-aligned programs by reducing external inference dependencies, keeping detailed ICT audit logs, supporting resilience testing, documenting model and connector dependencies, and enabling customer-controlled change windows. It does not replace your legal or supervisory compliance obligations.

How does VDF AI support EU AI Act compliance programs?

VDF AI helps teams maintain AI inventories, classify AI use cases, enforce human oversight, document model and data-source choices, and produce technical evidence from governed runs. Final obligations depend on your role, use case, jurisdiction, and risk classification.

Do you require model API subprocessors for production workloads?

No. On-premises, VPC, and air-gapped deployments do not require third-party model APIs for production inference. If a customer chooses to connect an external model provider, that provider is customer-selected and governed by the customer’s own policy.

How predictable are costs at enterprise scale?

VDF AI is built for platform and capacity planning rather than unlimited per-token surprises. Customers run models on infrastructure they control and can combine local models, routing policy, and workload limits to make usage predictable across teams.

TRANSPARENCY

Subprocessors, updates, and security advisories

Trust centers should answer what runs where, which third parties touch production data, and how security-impacting changes reach regulated customers.

Subprocessors and production data plane

Production inference and retrieval No required third-party model API subprocessor

For on-premises, private cloud, and air-gapped deployments, inference, embeddings, private RAG, logs, and orchestration run in the customer-controlled environment.

Customer infrastructure Customer selected

Cloud tenancy, data center, identity provider, SIEM, secrets manager, vector database, model runtime, and storage remain under the customer’s operational and contractual control.

Optional external services Policy controlled

If a customer permits an external model, connector, or support workflow, it is explicitly configured and governed by customer policy, procurement, and risk review.

Updates and advisories

2026 Q2 Trust Center expanded for regulated AI procurement

Added deeper RFP, compliance, private RAG, air-gapped deployment, and evidence-pack guidance for security reviewers.

2026 Q1 Reference architecture refresh

Updated deployment diagrams and buyer questions for on-premises, VPC, sovereign cloud, and air-gapped AI agent rollouts.

Ongoing Security advisory process

Security-impacting advisories are reviewed with affected customers through the agreed support and disclosure path for their deployment model.

Ask our Trust Center

Send your architecture questionnaire, DORA checklist, EU AI Act evidence request, HIPAA security review, or air-gapped deployment constraints. We will answer against your environment, not a generic cloud pattern.

Bring your security team to the table.

We will walk your architects, security, and compliance leads through the deployment model, data flow, controls, and compliance mapping for your environment — and answer your security questionnaire against a concrete reference architecture.