The data decides. Long before anyone compares models or draws an architecture, the marking on the document, the clause in the client agreement and the regulator behind both have ruled on where that material may be processed and who may reach it. Executives open the conversation asking which AI product to buy. Their compliance officer is asking something prior: is this material allowed to leave the boundary that already governs it?
How Do You Run AI on Confidential Data
That Cannot Go to the Cloud?
Permission comes from the classification, the contract and the regulator that already govern the material. What an approver has to see, and where each question that follows gets settled.
Permission comes from the data rather than from a product choice. The classification, the contract and the regulator that already apply have settled where your material may be processed. Read that verdict first, then put the inference inside the boundary it names. Iternal builds AirgapAI for exactly that placement: it runs 100% local on the device, and the material never leaves it.
The limit: settling permission is not the same as winning approval, and neither is the same as being safe. Buyers repeatedly described their own IT and approval framework stopping any new system at the door, so a sound boundary argument still has to survive your own security review. Putting the model inside the control set that governs your material retires the third-party-disclosure argument. It retires neither the records and discovery exposure of what people type, nor the reviewer who wants an auditor’s attestation: Iternal publishes AirgapAI as compliant by design and follows SOC 2 practices rather than holding an attestation report.
What an approver has to see, on paper, before anyone signs. Name the control set that governs the material and the boundary the deployment will sit inside. Produce a data-flow description that traces every hop. State what leaves the machine. Hand the reviewer a dated certification status covering every line. The targeted questions below put each of those in writing.
Permission and placement are separate decisions, taken in that order. Permission asks whether the material may leave the boundary that governs it, the question settled here. Placement asks which machine the software installs on, a separate decision taken afterwards against different requirements. For more information visit the placement page.
The Rule That Arrives Before the Shortlist
One constraint reaches us more often than any other, and it arrives as a flat statement rather than a question: our most sensitive material can never go into a hosted AI service. Buyers said it again and again. A consultant to banks cannot legally send client information to third-party AI services. A global consulting firm holds client material so sensitive it cannot leave controlled devices. A semiconductor foundry supplier forbids its data from touching the internet at all.
The pattern underneath the phrasings. None of those buyers cited a jurisdiction or named a regime. They stated a boundary and expected the architecture to respect it, because the classification, the contract and the regulator had already settled it. An organization that treats the boundary as fixed evaluates AI quickly. One that treats it as negotiable spends months discovering it was fixed all along.
Settle Permission First, Then Route the Question
Permission is one question with one verdict, and everything after it belongs to a different specialist. Work the material through three steps — classify it, name the control set, state what your approver must see — and the fourth routes itself. Each path below ends in a verdict and a page.
| What you find when you classify the material | What it settles | Where it is answered |
|---|---|---|
| A named regulation on the document — a controlled marking, an export notice, a criminal-justice or education record. | Which deployments the marking permits. | the regulated data classes page |
| A country rule — the material may not cross a border, or must stay under one nation’s law. | Where compute and corpus may physically sit. | the residency and sovereignty page |
| A reviewer with a questionnaire — certificates demanded, sign-off withheld until they arrive. | What evidence closes a review, and what the list is missing. | the security review page |
| A worry about what the software keeps or sends — retention, training use and telemetry, asked as one bundle. | Three separate answers, one per leg the material touches. | the data-retention page |
| A disclosure obligation — a public-records request, a subpoena, a legal hold, a privilege worry. | Whether what people typed becomes a file somebody can demand. | the records and privilege page |
| An entitlement question — which team may load which material, and what an administrator can prove afterwards. | Sign-in, entitlement and the audit trail. | the access and administration page |
| A site with no route out — a sealed facility, a plant, a flight, people who work disconnected. | What keeps working with no network, and what quietly stops. | the offline and air-gapped page |
| A demand that it run on hardware you already control — the endpoint, the enclave, your own tenant. | Which machine the software installs on. | the placement page |
Two paths end somewhere other than a page. A clause barring the material from any AI system ends in a renegotiation rather than an architecture. A marking applied more broadly than the rule requires ends in a labeling review, because inflated labels buy controls nobody needed.
What “Nothing Leaves the Device” Settles
A permission argument rests on one fact stated plainly: what leaves. Iternal builds AirgapAI to run 100% local on the device, and states that the material never leaves it. Inference happens on the machine’s own silicon, against data sets on its own disk, which is why the deployment inherits the IT security policies you already enforce rather than a new control set somebody has to write and defend.
Read that as a permission fact rather than as a recommendation. It answers the question an approver asks — does our material leave our control — and says nothing about which machine to buy or how to size a rollout. Local execution also does the work a certificate is asked to do: Iternal publishes AirgapAI as compliant by design, because the material never leaves hardware you control.
Four written answers turn an architecture claim into evidence, and Iternal gives each:
-
Which boundary will the deployment sit inside, and does adding it widen the scope our assessor reviews?Whether an accreditation you already hold covers the deployment.
-
What leaves the machine at any point in the product lifecycle, and can we have that list in writing?The permission argument, turned from a claim into a line on your security questionnaire.
-
Which certifications does Iternal hold today, which are open, and what is the date on that status?The distance between architectural alignment and a certificate, before a reviewer finds it.
-
Who signs the data-flow description, and will that person answer our security team directly?That the architecture has a named owner your reviewer can question.
For more information visit the security review page and the data-retention page.
Two Blockers That Travel With the Locality Rule
Permission is rarely the only thing between an organization and its first deployment. Two further constraints arrive beside it, both from the same office.
Security was already the biggest problem before AI arrived. Buyers described cybersecurity as the one thing keeping the IT leader awake, with AI landing as another front to defend. In their words: AI is a threat vector; a compromised dependency in the AI stack can steal every API key in the environment. Security carries a further handicap — leaders called it a tax rather than revenue, so it competes for budget from behind.
Compliance wants every box provably ticked. Others told us adoption stays frozen until they are certain every compliance box is checked, and that they cannot tell which AI solutions count as secure. One buyer supplied the complication himself: for most of these frameworks there is no certification to obtain, only frameworks to adhere to. Evidence, then, is what a reviewer can trace — a named boundary, a data flow, a dated status list.
What a Permission Verdict Covers, and What It Leaves Open
A permission verdict is a narrow instrument, and the narrowness is the point. It settles whether your material may leave the boundary that governs it, and nothing else. Which machine the software installs on, and which topology serves it, is a deployment decision taken afterwards against different requirements.
A permission verdict also wins no approval: your own review queue sets the calendar, and buyers described that queue stopping systems whose architecture was in perfect order.
- Which machine or hosting model the software installs on — see the placement page.
- What your people may type into an AI tool as a matter of written policy — see the acceptable use page.
- Which products a law practice should shortlist — see the legal shortlist.
- Which products a small public-safety agency can afford and operate — see the public safety shortlist.
- Where clinical and life-sciences teams apply this pattern — see the healthcare and life sciences page.
FAQ: AI on Material That Cannot Leave Your Control
Yes, when the inference happens inside the boundary that already governs the material. The classification, the contract and the regulator settle where it may be processed, so place the model inside the control set you have accredited rather than certifying a new external destination. Iternal builds AirgapAI to run 100% local on the device, with the material never leaving it. Settling permission still leaves your own approval queue to clear.
Run the inference where the material already lives. A deployment executing on your own device or inside your own enclave has no data plane reaching a hosted model, so nothing is left to keep out. Where a hosted component stays in the design, the protection turns contractual, and retention, training use and telemetry each need a written answer. For more information visit the data-retention page.
Compliance attaches to a deployment rather than to a product name, so the question rarely has a shortlist for an answer. Judge a candidate on the boundary it sits inside, the data flow it describes and the dated status it will put in writing. Iternal publishes AirgapAI as compliant by design — nothing leaves hardware you control — and follows SOC 2 practices rather than holding an auditor’s attestation report.
A private deployment removes the argument that you handed material to an outside party, the exposure most buyers name first. Three others stay standing: what people type can still become a discoverable record, an entitlement mistake can still put the wrong corpus in front of the wrong team, and a signed clause can still bar the use outright. Treat local execution as a strong risk control that carries obligations.
Because the security team was already at capacity before AI arrived. Buyers described cybersecurity as the one thing keeping the IT leader awake, AI as another threat vector, and a compromised dependency in the AI stack as a route to every API key. Their own approval framework then stops any new system at the door. Budget the review time, and bring the boundary argument in writing on day one.
Start With the Boundary
Name the control set that governs your material, put the inference inside it, and the shortlist writes itself. Every question that survives — the marking, the border, the questionnaire, the record, the entitlement, the machine — is settled on one of the pages linked here.