Private AI · On-premise deployment
AI that stays in your building.
A language model installed on hardware you buy and own, running on your own network — or on no network at all. It answers questions about your own documents without sending them to a cloud service.
We are in the building to install it, and there are two more moments like it. That access is a separate question from the architecture, and it belongs in a contract before you sign — section 04 names all three.
On-premise · You own it · Priced to scope · NDA on request
What actually gets installed.
Not a cloud subscription with a private label on it. A physical thing that arrives, gets racked, and stays.
A machine. A workstation or rack server with GPUs, sized to how much text it has to hold and how many people use it at once. It sits where your IT decides. We specify it during scoping rather than publish a spec sheet; the right one depends on your document volume and your room.
An open-weight model, stored on its drives. The weights are files on that machine — no API key, no metered call, no remote endpoint the software depends on to answer.
An index built from documents you choose. Your files are loaded and indexed on the machine. When someone asks a question, the system retrieves the relevant passages and the model answers from them, with citations back to the source. Any further tuning on your material is a scoping conversation, not a default.
A page your staff open in a browser. Someone types a question in plain language and gets an answer with the sources attached. Find the clause across four hundred agreements. Summarize the file before the meeting. Answer the question the newest person keeps walking down the hall to ask.
When it doesn't have the answer, there is nothing to fall back on — no outside service to query. Like every language model it can be wrong, or sound certain when it shouldn't, which is why every answer carries citations you can open and why a qualified person reviews output before it is used. The limits below are not decorative.
What an air gap doesn't do.
An air gap changes facts. It does not change obligations.
Read this part twice
An on-premise, air-gapped deployment does not make you compliant with anything. Not bar rules on confidentiality. Not HIPAA. Not FINRA or SEC obligations. Not CUI handling under NIST 800-171. Not GDPR. No arrangement of hardware satisfies a regulation, and no vendor — including us — can hand you compliance as a product feature. Anyone who tells you otherwise is selling you a sentence you will have to defend later without them.
What an on-premise deployment does is change the underlying facts your compliance officer, general counsel, or privacy officer evaluates. Those facts are genuinely different when the processing happens in your office:
- Where the data resides, and on whose equipment.
- What network paths exist off that machine — including, with a full air gap, none.
- Who holds the administrative credentials, and who rotates them.
- Who can be physically present at the machine, and under whose supervision.
- What logs exist, where they are written, and who can read them.
- What happens to the data if you stop paying anyone — us included.
Those are inputs. The analysis is your compliance officer's, and so is the decision. We aren't qualified to make either for your firm, and you should treat an offer to do so as a warning sign.
We will give them a written description to work from: the deployment as built, the network posture, the access paths we hold, the update process, and what is logged. If they ask us to attest to something we can't honestly attest to, we'll say so rather than write it down.
If they conclude it doesn't work for your obligations, that is a useful outcome — better found in week one than after a machine is in your server room.
Where your documents live.
You choose what goes in. Loading is a deliberate act — a directory, an export, a set of matter files you've decided belongs in scope. Nothing gets swept up by default; no background sync puts anything there.
Once loaded, the files and the index built from them are on that machine's drives. In normal operation they are not uploaded to us, not sent to a model provider, and not used to train anyone else's model.
The qualification
"Nothing leaves the machine" describes the running system, not AOS AI. The accurate claim is narrower: no cloud AI service receives your documents and no third party receives them through the product — but we ourselves have access at three specific, bounded moments, and you should evaluate and contract for that separately. Section 04 names them.
Deletion is yours. Drop the index and rebuild it. Remove documents from scope. It is your machine, so in the last resort you pull the drives — no ticket, no vendor, no waiting on someone's retention policy.
Where we have access.
Three moments. We would rather name them than have your general counsel find them.
Moment one
Installation
We are at the machine. During setup we hold administrative credentials and can see the file system. Unavoidable for anyone who installs a server — your own IT contractor included — but it is access, and calling it anything else would be dishonest.
Credentials can be rotated to you the moment we step away, and we recommend it.
Moment two
Document loading
If we perform the initial load, we handle the material. That is real exposure to your files, and for some firms it is the wrong answer.
So it is optional. Your own staff can do the loading instead; we'll train them, document the process, and stay out of the room. It costs a little time and removes us from the step.
Moment three
Support, if you buy it
A support plan is optional and separate, and by definition an access arrangement — there is no version of support where a vendor helps without access.
On a fully air-gapped system there is no remote path at all, so support means a scheduled visit by someone you let in. On an isolated segment, remote access is a decision you make, not a default we ship.
How it gets bounded
In the contract, not the brochure
Supervised sessions only. Your staff at the keyboard while we advise. Credentials held by you, rotated after each visit. A written log of what was done. NDA before we discuss specifics of your environment.
Which of these you require is your call, and it belongs in the agreement. We won't write "no third party has access" into a document your regulator might read, because it wouldn't be true.
The limits, stated plainly.
Every one of these is a real cost of the design.
It is less capable than a frontier cloud model.
An open-weight model you run yourself is generally weaker than the best hosted models on hard reasoning and broad world knowledge. On focused work over your own documents the gap narrows — but we won't tell you it disappears. The honest number comes from a trial on your material, judged by your own people.
It runs on hardware you buy and own.
That is the point, and also a capital purchase. It occupies space, draws power, needs cooling, and ages like every server. If it fails, it is yours to repair — or yours to have us repair under a support plan you bought. Ownership cuts both ways; price both directions.
Updates are deliberate, not automatic.
Nothing self-installs on an isolated machine. Better open models will be released, and you won't have them until someone carries them in on a scheduled date. Isolation and slowness are the same property. You are choosing it on purpose.
We have no private-AI deployment to point you at.
AOS AI has three clients, and all three are phone-agent work. We have not deployed a private AI system for an outside client, and we are not going to imply we have. If your process requires a vendor with prior deployments in your sector, we are not that vendor today — better you learn that here than in the third meeting.
It does not remove the professional.
Output gets reviewed by someone qualified before it is filed, sent, diagnosed from, or advised on. The system drafts and finds; it does not sign. Any workflow that treats it as the last step is one we will tell you not to build.
Isolation is a spectrum, and you pick a point on it.
A true air gap means no network path off the machine at all — maximum isolation, maximum friction, sneakernet for everything. An isolated network segment is easier to live with, and a different set of facts to weigh. We build to whichever point your IT and compliance officer choose — or tell you plainly, before you buy, if that is outside what we can build.
What you own, and what it costs.
One-time purchase. The model weights and software run under their own open-weight and open-source licenses, listed for you in writing before you buy. No per-seat meter on your own files, and no renewal date that decides whether you can still read your own index.
The hardware is yours, in your name. We specify it; you buy it from whoever you like. It is on your asset register, not ours.
Support is optional and separate. Priced on its own, with the access questions from section 04 settled in writing. Declining it switches nothing off.
There is no public price, and we won't invent one. Our two off-the-shelf products do have published prices — the text agent is $89/month with a $1,499 setup, or $749 setup if you pay quarterly; the voice agent is $240/month with a $2,999 setup, or $1,499 quarterly. Private AI is priced to scope: document volume, hardware, network posture, and how much of the loading and administration you keep in-house.
- Deployment
- On-premise. Your hardware, your building.
- Network
- Full air gap or isolated segment — your IT and compliance officer decide, not us.
- Model
- Open-weight, stored and run on local drives. No API key, no metered calls, no remote endpoint.
- Documents
- Loaded deliberately, indexed on the machine, answered with citations to the source.
- Updates
- Manual and scheduled. Newer models arrive when someone carries them in.
- AOS AI access
- Installation; document loading if you ask; any support visit you authorize. Bounded in your contract, not by our marketing.
- Support
- Optional plan, separately priced. On-site or supervised, terms agreed before you sign.
- Price
- One-time purchase, quoted to scope. No public number.
- Track record
- Three verifiable clients, all phone-agent work. No private-AI deployment yet.
- Who decides
- Your compliance officer, general counsel, or privacy officer decides whether this fits your obligations. Not us, not this page.
Nine questions worth asking us.
No. We can't make you compliant with bar confidentiality rules, HIPAA, FINRA or SEC obligations, CUI handling under NIST 800-171, or GDPR, and neither can any other vendor — compliance is not a feature that ships in a box. What an on-premise deployment changes is the facts your compliance officer, general counsel, or privacy officer evaluates — section 02 lists them, and we put what we know in writing for them. The analysis and the decision are theirs.
In normal operation the product sends nothing out: no cloud AI service receives your documents and no third party receives them through the software. But we have access at the three moments section 04 names, and your contract should bound them — supervised sessions, your credentials, a log of what was done. We will not sign a statement saying no third party has access, because it wouldn't be true.
Generally, no. An open-weight model on your own hardware is usually less capable than a frontier cloud model at hard reasoning and broad general knowledge. The gap narrows on focused work over your own documents — retrieval, summarizing, finding the clause — but we won't claim it vanishes, and we won't quote a benchmark we haven't measured on your material.
No, and we are not going to dress it up. AOS AI has three clients, all three phone-agent work — not private AI. We will put you in touch with them. There is no case study to send you and no client list in your sector to check. Whoever goes first is an early client and should be priced and contracted like one.
Yes. An open-weight model runs inference on local hardware — the weights sit on a drive in the building, and nothing needs a network to answer a question. On a full air gap the machine has no route out at all. Whether that satisfies your bar's confidentiality rules is a separate question, and section 02 is where it starts. We have not deployed this for a law firm yet.
No. HIPAA compliance is a program — risk analysis, policies, training, business associate agreements, access control and audit — not a property of one machine. What an air gap changes is some of the facts that analysis works from: where the records sit, what leaves the network, who can reach the box. Your privacy officer does the analysis. We put what we know in writing for them and stop there.
You can, and if your IT team is comfortable doing it, do it. An open-weight model on a workstation will answer offline without paying anyone. What we add is the part that takes the time: hardware specified for your document volume, your own files indexed and answered with citations to the source, the access questions in section 04 settled in writing, and someone accountable when it stops working. If none of that is worth paying for in your firm, the do-it-yourself route is the honest answer.
We specify it; you buy it from whoever you like, and it goes on your asset register in your name. The specification follows document volume and how many people query it at once, which is one of the things the call is for. There is no leased appliance and no hardware we hold title to. Section 06 covers the rest of what you own.
Someone carries it in. Updates are manual and scheduled: newer weights or a software version arrive on media, get checked, and get installed during a session you authorize — the third of the three access moments in section 04. Nothing updates itself and nothing phones home to check. Declining an update switches nothing off; the system keeps running on the model you already have.
Something not answered here? Call 646-846-9369 · help@aosai.co
Talk to a person first.
There is no booking form here on purpose. A private deployment starts with a conversation about your environment, your obligations, and who in your firm has to sign off — not with a calendar widget.
Call or email. Bring your IT lead and, if you can, whoever owns compliance. Ask us the hard version of every question above.
NDA on request before we discuss specifics