Runs where your data already is
Deployed on your hardware, in your VPC, or fully air-gapped. The model comes to the data rather than the data going to the model, so no personal data crosses a boundary to be processed.
Overview
A small language model built in-house and deployed inside your estate, so the personal data it reasons over never leaves the perimeter — and no third-party model provider ever enters your processing chain.
Why build our own
Every other control on this platform exists to keep personal data accounted for. Routing that same data through someone else's endpoint to summarise it would undo the lot.
What it does
The guarantees come from where the model runs, so they hold without depending on a provider honouring a term you cannot verify.
Deployed on your hardware, in your VPC, or fully air-gapped. The model comes to the data rather than the data going to the model, so no personal data crosses a boundary to be processed.
Nothing leaves the perimeter — not prompts, not documents, not embeddings. There is no model vendor in your processing chain, so there is no vendor to add to your records or your DPA schedule.
Adapted to your policies, product names and document formats, so it answers in your terms. The tuning data stays yours and is never pooled to improve anyone else's model.
Prompt, model version, retrieved context and output land in the same append-only trail the rest of the platform writes to, so an automated output can be reconstructed months later.
It appears in the model register with its owner, purpose and training-data provenance, and is assessed against the EU AI Act and DPDP Sec. 10 in the same engine as every other system you run.
Sized to run on commodity GPU hardware rather than a datacentre, which is what makes on-premises deployment a real option instead of a procurement exercise.
Deployment
Pick the one your obligations require. The model is the same in all three; only the boundary moves.
Your servers, your network, your access control. The usual choice for banks and government bodies with data-localisation obligations.
A dedicated tenancy in your own cloud account and region. Nothing is shared with another customer and nothing routes through us.
No outbound network at all. Model and weights are delivered and updated out of band, for classified and critical-infrastructure environments.
The SLM is one of seven Data Security categories, and it is governed by the same programme that governs the detection models — registered, assessed, and evidenced alongside everything else that touches personal data.
All of Data SecurityA walkthrough deploys the model in a sandbox that mirrors your constraints — on-prem, VPC or air-gapped — and puts your material through it.