Company

Request a demoSee it on your own data.Book a 30-minute walkthrough with a knowledge expert and find the value hiding in your systems.Book a demo

By industry

Not listed?Built for any data domainDon't see your industry? It's still a fit. The Knowledge Fabric™ is model- and domain-agnostic, so it works on any data.Talk to our team
Secure enclave workstation

The reasonable objection to running AI in a closed environment is that the good models are not in it.

That objection is fair as far as it goes, and it is the reason so many secure programs have concluded that useful AI is something they will get to later. The premise underneath it deserves examining, though, because it assumes the only way to apply a model to data is to send the data to the model.

Why is the usual pattern unavailable here?

Because it requires export. Extract the data, load it into an external provider’s environment, and ask questions there.

That produces the objection every security review raises, and in a classified or air-gapped context it is not an objection to be negotiated. It is a hard stop. The same is true in commercial environments handling material under confidentiality undertakings, where counsel will not approve loading the material into a vendor environment regardless of the contractual assurances offered.

It also caps what can be asked, because the model only knows what was exported, which is rarely the whole estate and almost never its current state.

What does bringing the intelligence to the data mean in practice?

The models run inside your own environment, against live resolved records, rather than against a copy that left it.

Nothing is uploaded to a third party. Nothing is retained by a vendor. Nothing asked is used to train a model anyone else will benefit from. Sensitive domains are answered by models running locally on data that never crosses the boundary, and only work whose sensitivity classification permits it is routed to a frontier model.

The routing decision is recorded either way, which matters more than it first appears. A reviewer asking eighteen months later whether a particular query left the enclave gets an answer from a log rather than from an assurance.

Does a local model give up too much capability?

This is the honest trade-off and it deserves a direct answer rather than a reassuring one.

Locally hosted models are generally less capable than the largest frontier models, and for open-ended reasoning tasks that difference is real. What narrows the gap substantially is what the model is standing on. A capable model reasoning over an unresolved estate, where one customer exists five times under five identifiers, produces fluent output built on a miscount. A smaller model reasoning over resolved entities, typed relationships, and scored attributes is answering a much easier question, because most of the difficulty was removed before the model saw it.

The classification-based routing then handles the remainder. Work that genuinely needs frontier capability and carries a classification permitting it goes out. Work that does not stays in.

What has to be true of the data first?

The same three properties that make any of this defensible.

Entities resolved once across the systems that describe them, so a question can span them. A confidence rating on every individual attribute, so the model’s answer can carry a confidence that means something. Governance applied continuously at the attribute level, so access can be enforced per value rather than per system, which is how a partner receives a governed view without anyone building them a separate copy.

Attribute-level access enforcement is the mechanism that makes partner sharing workable at all. One definition serves consumers with different entitlements, and nobody maintains a parallel redacted export.

Does deployment work in a fully isolated environment?

Yes, and data residency becomes a function of where you install it rather than a contractual promise about where a vendor keeps it.

Model access is brokered locally rather than through an external API, so prompts, context, and responses stay inside the boundary. Deployment works in fully isolated environments, including forward at the edge where connectivity is intermittent or absent.

The ownership argument runs alongside the security one and is worth stating separately. A platform that learns across its customer base is, by construction, moving what you know toward the organizations you compete with. Learning that happens inside your environment, from your outcomes, stays yours, and it remains yours if you stop being a customer.

What can be asked that could not be asked before?

The class of question that exists only in the relationships between your own systems.

Which entities appear across four systems under three spellings. Which relationships changed last quarter and what moved with them. Which attributes a given recommendation actually rested on, and how well supported each one was on the day it was made.

None of that exists in a public corpus. No external model, however capable, can answer it, because the answer is not in the training data. It is in the estate, which is exactly the thing that could not be exported.

Inside the boundary, connected or not

The PolyPhaze white paper Decide Faster. Act Faster. covers the orchestration layer, model placement, secure routing, and how four consumer populations are served from one governed foundation. Download the full air-gapped AI deployment ebook for the complete detail.

Frequently asked questions

Can you run AI in an air-gapped environment?

Yes, when the models run inside the boundary rather than the data being exported to them. Model access is brokered locally, prompts and responses stay within the environment, and deployment works in fully isolated enclaves with residency determined by where the platform is installed.

Are locally hosted models good enough?

For reasoning over a resolved and scored estate, often yes, because most of the difficulty has been removed before the model is involved. Work that genuinely requires frontier capability and carries a permitting classification can be routed outward, with the routing decision recorded.

How is data access controlled for external partners?

At the attribute level rather than the system level. One definition can serve consumers with different entitlements, so a partner receives a governed view of exactly the values they are permitted to see, without anyone maintaining a separate redacted copy.

Request a demoRun it inside your own boundarySee a deployment that works air-gapped, on-premises or in GovCloud, with governance at the data layer.Request a demo