Key facts
| Deployment | On-prem and air-gapped tiers; no external dependency for inference |
| Models | Open-weight models that can be inspected and vetted offline |
| Key custody | BYOK via KMS or on-prem HSM |
| Audit | Local audit logging and SIEM export inside the perimeter |
| Identity | SSO/SCIM and RBAC operating within your environment |
| Accreditation | Architecture and control documentation provided; formal accreditation is completed with your security team |
| API contract | OpenAI-compatible across cloud, VPC, on-prem and air-gapped tiers |
| Compliance posture | SOC 2 Type II and ISO 27001 readiness in progress (not yet certified) |
TL;DR
- Prefer open-weight models you can inspect, version and re-evaluate offline.
- Vendor documentation supports accreditation; the authority's decision stays with your security team.
- Design the media intake process for weights, updates and patches before the first delivery.
- Plan offline evaluation, monitoring and incident response from day one.
- Define the support model for restricted environments in the contract.
How it works, step by step
- Document the classification and connectivity policy for each environment.
- Select open-weight models and record version, licence and provenance.
- Design the intake process for models and updates with verification and staging.
- Deploy identity, key custody and audit controls entirely inside the perimeter.
- Build offline evaluation suites for quality, safety and language coverage.
- Prepare accreditation artifacts with your security authority.
- Exercise incident response and recovery, including media-handling procedures.
Try it yourself
Open the private LLM cost estimator →
Architecture for restricted environments
The operating pattern is consistent: GPU infrastructure inside the accredited boundary; open-weight models loaded from verified media; an OpenAI-compatible inference endpoint reachable only from approved networks; identity, keys and audit operating locally. Plugsky provides the deployment architecture — on-prem or air-gapped, with BYOK and audit logging — and the same API surface used in its cloud tiers, so workloads can be developed in one environment and moved into the restricted one. Specific accreditation is completed with your security team and authority. Keep a signed decision record for each admitted model version so future audits can trace provenance.
Model vetting and provenance
- Record the model family, version, licence and checksum for every artifact.
- Review training-data and licensing statements where available.
- Run your own evaluations for accuracy, safety and language coverage — including Arabic and other mission languages.
- Maintain a version matrix so you can reproduce results and roll back.
- Schedule re-evaluation when a new version is admitted.
Update and support logistics
Air-gapped systems age at the speed of their intake process. Define who approves a transfer, how media is scanned, where staging happens, and how rollback works. Security patches deserve priority lanes; model upgrades can follow a slower cadence tied to evaluation. Support must be specified too: remote assistance is usually impossible, so agree on documentation, spare parts, on-site visits and response targets in the enterprise agreement.
Common pitfalls
- Treating the air gap as the entire security case; physical and insider controls still matter.
- No evaluation environment, so quality is discovered in production.
- Intake bottlenecks that delay critical security patches.
- Undefined support boundaries leading to extended outages.
- Accreditation artifacts assembled late instead of during design.
Honest comparison
| Capability | Plugsky | Hyperscaler AI platform | Building in-house |
|---|---|---|---|
| Air-gapped deployment | On-prem and air-gapped with open-weight models | Very limited offline options | Native |
| Model vetting | Open-weight catalogue with versioning | Vendor-controlled models | Full control |
| Accreditation support | Architecture and control documentation | Mature compliance programs | You produce everything |
| Key custody | BYOK via KMS or HSM | Cloud KMS and HSM | You operate the HSM |
| Offline evaluation | Your tooling on your data | Limited | You build it |
| Certifications | SOC 2 / ISO 27001 readiness in progress | Completed audits in many regions | Your own programme |
Frequently asked questions
Does Plugsky provide accreditation for classified environments?
Plugsky provides the architecture and control documentation — on-prem, air-gapped, BYOK, audit. Formal accreditation is completed with your security team and the relevant authority.
Which models are suitable for air-gapped government use?
Open-weight models from the catalogue such as Nemotron, Llama, Qwen and Mistral families. Record provenance and licence for each, and evaluate on your mission data.
How are updates delivered?
Through your controlled intake process: verified media, scanning, staging and approved rollout. Define a priority lane for security patches.
Can we evaluate Arabic-language quality offline?
Yes. Plugsky is Arabic-first with multilingual embeddings, and you can run your own Arabic evaluation suites entirely offline.
What support is possible without connectivity?
Documentation, on-site assistance and defined response targets. Specify the model in the enterprise agreement because remote support may not be permitted.
Is an air gap required for all government AI?
No. Many government workloads are served by in-region or private VPC deployments. Reserve the air gap for environments where policy forbids external connectivity.
How does this interact with data residency?
Residency determines where data may be processed; air-gapping removes external connectivity entirely. Both should be documented together in your control map.