Deployment isolation
Where does the workload run?
On dedicated infrastructure in the customer-controlled environment, sized and segmented for the deployment.
Sotaire runs in a dedicated customer environment. Network paths, identity, retention, evidence, backup, and review controls are configured to that environment and verified during handoff.
Security is more than a row of framework badges. These are the operating areas Sotaire documents with the customer.
Where does the workload run?
On dedicated infrastructure in the customer-controlled environment, sized and segmented for the deployment.
Where do source data and model traffic go?
Sources, storage, retrieval, and inference paths are documented in the deployment data-flow record.
Who can access which data and tools?
Users and agents receive scoped roles aligned to the customer’s identity and workspace model.
What can cross the network boundary?
Approved destinations and brokered calls are explicitly configured, logged, and tested during handoff.
Can an operator reconstruct an event?
Prompts, retrieval context, tool calls, approvals, and configuration activity are retained as reviewable records.
How is service restored safely?
Backup scope, encryption, retention, restore tests, and recovery ownership are defined per environment.
How does software change after handoff?
Versions, maintenance windows, rollback steps, monitoring, and operator runbooks are agreed with the customer.
What keeps automation within scope?
Tool allowlists, step limits, citations, checkpoints, and human review are configured to the workflow’s impact.
The exact services vary by deployment, but identity, retrieval, inference, and evidence stay explicit.
Identity and role establish the workspace and sources the request may reach.
Approved local collections return passages and provenance for the request.
The configured model generates within the customer deployment boundary.
Citations, approvals, tool activity, and final output remain available for review.
The handoff names who makes policy decisions, who operates the platform, and what must be validated together.
Platform configuration, deployment baseline, workflow controls, documentation, and implementation support.
Identity lifecycle, source-data quality, policy decisions, reviewer assignment, facility security, and user governance.
Architecture approval, integration allowlists, acceptance testing, incident exercises, backup validation, and change review.
Sotaire can be configured to support a customer’s control environment. Scope, evidence, and responsibility are documented; certification remains with the relevant organization and auditor.
A few common questions teams ask before private AI enters a controlled environment.
We’ll walk through the data flow, identity model, approved network paths, evidence, recovery, and responsibilities for your environment.
Bring the workflow, the sensitive sources, and the review rules. We'll map the deployment boundary and next step.