Private AI for MSPs and IT consultants: deploy it inside each client’s own environment
Clients now ask their IT provider for AI they can use on confidential data. VDF AI gives MSPs and IT consultants a governed platform to deploy in each client’s data center, cloud account or air-gapped network, and one way to run it across every account: a separate environment per client, role-based access, an audit trail for every run and, on the MASP partner track, Level-3 engineering from VDF AI behind your L1 and L2 desk.
What clients will ask for
What an MSP needs to offer private AI to clients
A client that holds regulated or confidential data will not accept a shared public AI service, so the offer has to answer four questions before the first workshop: how clients stay apart, where the software runs, what the auditors will see, and how the service earns its keep.
Keep every client in its own environment
Multi-client isolation starts with how you deploy: each client gets a separate VDF AI environment, so one client’s documents, indexes and logs never share storage with another’s. Inside an environment, workspaces keep business units apart as well.
- One environment per client, not a shared index
- Workspace separation for connections, indexes and datasets
- An air-gapped option for clients that block outbound traffic
Install where the client’s data already lives
Deploy on client hardware, single-tenant in a cloud account the client owns (AWS, Azure, GCP or a sovereign cloud), or fully air-gapped. On self-hosted installs, Microsoft Entra ID single sign-on is native; Okta, Keycloak and other SAML or OIDC providers connect through an SSO-aware reverse proxy in front of VDF AI.
- On-premises, private cloud or air-gapped
- Native Entra ID sign-in; other providers through a reverse proxy
- Role-based access with per-role tool grants
Give each client’s auditors a record they can check
Clients in regulated sectors will ask how their AI is governed. Every run is logged with the prompt, retrieved sources, model choice, tool calls and approvals, so an audit request is answered from the client’s own environment instead of being rebuilt from screenshots.
- Per-run execution trail
- Human approval gates on sensitive steps
- Logs that stay in the client’s environment
Build a repeatable service, not a custom project
Managed AI pays when the work repeats: one deployment runbook, one monitoring routine, and workflow designs and Agent Skills you refine with every client, while model routing keeps routine tasks on smaller models. VDF AI owns product engineering, updates and security patches, so your hours go into onboarding and outcomes.
- Reusable workflow designs and Agent Skills
- Routing to the smallest capable model
- Product updates and Level-3 escalation from VDF AI
Operating split
Who does what on the MASP track
The Managed AI Solutions Partner track is the route for MSPs that run client environments end to end. You own the client relationship and the first two support lines, while VDF AI stays responsible for the product itself.
| Area | MSP partner | VDF AI |
|---|---|---|
| Client relationship and sales | Leads | Supports |
| Onboarding, solution design and deployment | Leads | Supports |
| Professional services | Leads | Optional |
| Day-to-day operation of each client environment | Leads | — |
| Customer success and technical account management | Leads | Supports |
| L1 and L2 support | Leads | — |
| Usage reporting | — | Leads |
| Product, roadmap, updates and security patches | — | Leads |
| Level-3 engineering escalation | — | Leads |
A summary only: onboarding and the partner agreement set the detail, and the commercial terms sit in the MASP Program Guide that approved partners receive. Read the MASP track overview for support levels and how air-gapped client sites are handled.
Rollout path
From the first client to a repeatable service
Treat the first client as the template for every later one: qualify the boundary, deploy a single workflow, hand over evidence, then repeat with what you learned.
-
Qualify the client and its boundary
Confirm where the client’s data must stay, which identity provider it uses and whether outbound traffic is allowed. That settles on-premises, private cloud or air-gapped before any hardware is ordered.
-
Deploy one workflow in the client environment
Install the platform, connect one document collection through a read-only account, and pilot a single workflow, such as policy Q&A or ticket triage, with one team.
-
Hand over evidence and take on support
Walk the client’s security and compliance owners through the audit trail, agree the approval points, and run L1 and L2 support, with VDF AI handling Level-3 escalation on the MASP track.
-
Repeat the playbook for the next client
Reuse the runbook, workflow designs and Agent Skills that worked in a fresh environment for the next client, then grow each account with new workflows as trust builds.
What changes
What your clients and your practice get
Private deployment turns an AI request you would otherwise have to turn down into a service you can run, document and grow.
Isolation a client can verify
Each client has its own environment, its own users and its own logs, which answers the first question a regulated client’s security team asks.
Audit evidence on request
Execution records show what actually ran, who approved it and which sources were used, instead of a policy document written after the fact.
A managed service rather than a one-off install
Operating the platform, supporting users and adding workflows give you a lasting role in each account beyond the first implementation.
Next steps
Pages to read before the first client
The partner track, the security material a client will request, and an install path for the first pilot.
FAQ
Private AI for MSPs: common questions
What is private AI for MSPs?
It is an AI platform that an MSP or IT consultant deploys and operates inside each client’s own environment, so the client’s documents, prompts and answers never pass through a public AI service. The MSP handles onboarding, deployment and first- and second-line support; the platform provides chat, document Q&A with citations, agents, role-based access and an audit trail for every run.
Can an IT consultant deploy private AI for clients?
Yes. VDF AI installs on a client’s own servers, in a cloud account the client owns, or on an air-gapped network, and a consultant can deliver that as a project or as an ongoing managed service. Partners on the MASP track take on deployment, customer success and L1 and L2 support, while VDF AI keeps product engineering, updates, security patches and Level-3 escalation.
How do you keep one client’s data away from another client?
Give every client a separate environment rather than a shared index. Each deployment has its own storage, users and logs, and within an environment a connection or index in one workspace cannot be reached from another. Clients with the strictest rules can run air-gapped, with usage reported through exported statements instead of a live connection.
Which identity providers do client deployments support?
On a self-hosted or on-premises install, Microsoft Entra ID single sign-on is native: Entra security groups map to VDF AI roles, and directory users and groups sync. Okta, Keycloak and other SAML or OIDC providers work through an SSO-aware reverse proxy placed in front of VDF AI. Role-based access control, with roles, permission groups and per-role tool grants, applies on every plan.
What evidence can an MSP give a client’s auditors?
Per-run records from the client’s own environment: the prompt, the sources retrieved, the model that answered, any tool calls and who approved them. Because those logs never leave the client environment, its auditors review them under the client’s own controls, and the client’s existing assessments cover the deployment.
Do MSP clients actually want AI services?
The 2026 MSP 501 report from Informa found that 91% of MSPs offer or use AI solutions, up from 79%. GTIA’s August 2026 study found that half of SMB respondents already work with a strategic partner or IT service provider on AI initiatives. Private deployment is what lets that work reach clients who hold regulated or confidential data.
How does an MSP earn from private AI?
From services: deployment and onboarding projects, the ongoing operation and support of each client environment, and new workflows added over time. Delivery cost falls as the same runbook, workflow designs and Agent Skills are reused across clients and as routing keeps routine work on smaller models. Partner commercial terms are set out in the MASP track and shared with approved partners.
Add private AI to your managed services
Start with one client whose data cannot go to a public AI service, and walk through deployment, support and audit evidence with our partner team.