The constraint Architecture Sizing FAQ Customer portal Get a quote Home

Whether you have a regulated environment or an air-gapped network, tell us the work you'd hand off and a real person replies within one business day.

Which sector?
Select all that apply
Please select a sector above.
✳︎ The constraint

When the data can't go to the cloud.

In regulated and classified environments, sending data to an external AI provider is a non-starter. Sovereignty, compliance and security rules mean the work has to stay inside your perimeter, so a normal cloud AI employee is off the table.

✳︎ The architecture

The brain runs inside your network.

Instead of calling an external model, we deploy a local one on your infrastructure. The employee does the same job end to end, but every byte stays in your environment. No external API calls. Nothing phones home.

01
A local brain
The AI model runs on your own servers and GPUs, not someone else's cloud. The intelligence lives where your data lives.
02
Air-gapped
It can run with zero internet access, fully isolated from the outside world. No connection in, no connection out.
03
Your hardware, your control
On-premise or in your private cloud, behind your firewall. You hold the keys, the data and the off switch.
04
Fully auditable
Every action is logged inside your perimeter, ready for review, audit and your compliance teams.
✳︎ Sizing it

The harder the work, the bigger the brain.

A simple, single-task role runs on a small local model and modest hardware. As the tasks and complexity grow, so does the model and the infrastructure behind it: more compute, more memory, a larger model, scaled to the job. We right-size the deployment to your workload, then grow it as you do, all inside your walls.

Small model · one server
A focused role
A single, repeatable task. A compact local model on modest on-prem hardware.
Mid-size model · GPU
A full role
A complete job across several systems. A larger model, accelerated by a GPU in your rack.
Large model · GPU cluster
A coordinated team
Complex, multi-step work or many employees. A large model and scaled infrastructure on your own cluster.
✳︎ The guarantee

Sealed from the outside world.

Every secure deployment is built to your security, compliance and data-sovereignty requirements, and verified before it goes live.

  • No data ever leaves your network
  • No external API calls, nothing phones home
  • Runs fully offline and air-gapped
  • On your hardware, behind your firewall
  • A complete audit trail inside your perimeter
  • Built to your compliance and sovereignty rules
✳︎ Questions

On-prem, answered.

What does "on-premise" actually mean here?
The entire virtual employee, including the AI model that powers it, runs on hardware you own and control, inside your own network. There is no external service in the loop: the intelligence lives where your data lives.
Can it really run fully air-gapped, with no internet?
Yes. A deployment can run with zero connection to the outside world: no inbound, no outbound, nothing phoning home. Everything the employee needs runs inside your perimeter.
Is the local model as capable as a cloud one?
We right-size the model to the work. A focused role runs well on a compact local model; harder, multi-step work runs on a larger model and more compute. We scope the deployment to hit the quality bar the role needs, then grow it as the work grows.
What hardware do we need?
It depends on the role. A simple single-task employee can run on one modest server; a full role typically wants a GPU; a coordinated team of employees runs on a GPU cluster. We size it with you up front, on your hardware or in your private cloud.
Is any of our data ever sent to JustWork or a third party?
No. In an air-gapped deployment, no data ever leaves your network. There are no external API calls and no telemetry. Every action is logged inside your perimeter for your audit and compliance teams.
How do you update or improve it without internet access?
Updates are delivered and applied through your own controlled process: reviewed, staged and installed inside your environment on your schedule, with nothing reaching out on its own.
Who is this for?
Regulated and classified environments where the work can't go to the cloud: banking and finance, government and defense, insurance, healthcare, critical infrastructure, and legal and compliance.
How long does an on-prem deployment take?
We start with a secure briefing to map the role, your environment and your compliance rules, then scope the model and infrastructure. Timelines depend on your security review and hardware, and we plan them with you from the first conversation.
✳︎ Request a briefing

Scope your secure deployment.

Tell Onyx about your environment and the work you'd hand off. Onyx will talk through how it runs securely inside your perimeter and line you up with the right specialist, and a real person replies within one business day.

Confidential · no spam · a real person replies within one business day.