On-premise
Deployment within infrastructure physically or operationally managed by the client, subject to technical assessment.
Private Deployment
The appropriate deployment is determined by infrastructure, information sensitivity, operational requirements, governance obligations and acceptable risk—not by a universal template.
01 / Environment
Availability depends on the technical and operational assessment. KavakTech does not claim that every model, integration or environment is compatible by default.
Deployment within infrastructure physically or operationally managed by the client, subject to technical assessment.
A dedicated cloud environment governed within the organisation’s approved accounts, regions and controls.
Isolated compute and storage allocated to the agreed workload, integration model and security boundary.
Architectures designed for limited connectivity, isolated networks or tightly controlled information flows.
Comparison
| Environment | Typical fit | Connectivity | Assessment focus |
|---|---|---|---|
| On-premise | Existing client-managed infrastructure and strong local control requirements. | May support limited external connectivity, subject to the selected models and integrations. | Compute capacity, operations, patching, identity, storage and support access. |
| Private cloud | Cloud-based operation inside approved client accounts, regions and network controls. | Designed around the organisation’s cloud and network policies. | Tenant design, regions, keys, logging, model endpoints and service dependencies. |
| Dedicated servers | A separated environment without requiring the client to operate all underlying infrastructure. | Can be restricted to agreed interfaces and administration paths. | Hosting jurisdiction, isolation, backups, monitoring, support and exit arrangements. |
| Restricted environment | Sensitive workflows with limited, intermittent or no routine external connectivity. | Offline or tightly controlled exchange patterns may be considered. | Model packaging, update transfer, source ingestion, export, resilience and local operations. |
Control is part of the architecture
Information boundaries, model execution, access rules and traceability must be considered together. The design process therefore begins with the environment and risk profile before selecting the implementation.
“Private by Design” means that data boundaries, model operation, access and traceability are designed into the system from the outset.
Control layers
Exact controls are defined during assessment and mapped to the client’s systems, responsibilities and legal context.
Define what information may enter the system, where it is stored, how long it is retained and who can use it.
Select and configure models around the task, infrastructure and acceptable exposure—not a default public endpoint.
Align roles, permissions and review rights with actual professional responsibilities.
Connect only approved systems and data flows using interfaces appropriate to the client environment.
Record relevant events, sources, versions and review states according to the defined governance model.
Evaluate and document material changes to models, prompts, knowledge sources and workflows before release.
Shared delivery, explicit accountability
The final responsibility model is agreed contractually. This table shows the intended division during assessment and pilot work.
| Control area | Client responsibility | KavakTech responsibility |
|---|---|---|
| Information classification | Defines sensitivity, permitted use, retention and authorised users. | Translates the agreed boundary into the proposed system design. |
| Architecture and integration | Provides constraints, owners and access to approved technical information. | Designs and documents the assessed deployment and integration approach. |
| Identity and access | Approves roles, user lifecycle and segregation of duties. | Configures the product controls available within the agreed scope. |
| Model and workflow evaluation | Provides domain reviewers, acceptance criteria and representative approved material. | Configures tests, records limitations and supports remediation or refinement. |
| Professional decisions | Retains authority for legal, clinical, operational and institutional decisions. | Keeps review states and supporting evidence visible where the workflow requires it. |
02 / Technical assessment
KavakTech defines the proposed controls, dependencies and responsibilities for each project. Formal compliance, certification or assurance claims should be made only after the complete implementation has been assessed by the appropriate qualified parties.
A controlled first conversation
A technical discussion can establish the information boundaries, infrastructure options, integration requirements and validation work needed for a controlled pilot.