Key facts
| Deployment | Plugsky cloud, your VPC, on-prem or air-gapped |
| Capacity | Dedicated GPU capacity with custom rate limits (no shared pool) |
| Key custody | Customer-managed keys (BYOK) via KMS or HSM |
| Audit and governance | Audit-log export to SIEM and right-to-audit clauses |
| Legal | DPA with EU SCCs and custom sub-processor terms |
| Support | Custom SLAs, quarterly business reviews and a named CSM |
| Compliance | BAA available; SOC 2 Type II and ISO programs; FedRAMP Moderate in process |
| Commercials | Annual contracts quoted per deployment — see the live pricing page |
TL;DR
- Enterprise is the production-grade edition: dedicated capacity and custom limits.
- Deploy on Plugsky cloud, in your VPC, on-prem or fully air-gapped.
- BYOK, audit export, right-to-audit and custom sub-processor terms are standard.
- Support includes custom SLAs, quarterly reviews and a named CSM.
- Pricing is quoted per deployment; there are no public list prices for Enterprise.
How it works, step by step
- Define the deployment model your regulator or risk team requires.
- Collect the compliance evidence you need: BAA, SOC 2 report, residency terms.
- Scope capacity, rate limits and model access for your expected traffic.
- Agree security controls: BYOK, audit export, SSO, SCIM and mTLS.
- Negotiate legal terms — DPA, SCCs, sub-processor restrictions and SLAs.
- Run a pilot or proof of value, then move to an annual contract.
Try it yourself
Open the private LLM cost estimator →
Deployment options
Enterprise customers pick the topology that matches their obligations. Plugsky Cloud with a pinned region is the fastest path and supports region-locked data planes. VPC deployment runs the control plane inside your AWS, Azure or GCP account with no public ingress and customer-managed KMS. On-premises uses a Helm chart or an air-gap installer for your data center. Air-gapped deployments remove internet connectivity entirely, with signed update bundles delivered on physical media.
The same API serves all four topologies, so applications do not change when the deployment model does.
Capacity, keys and governance
Enterprise contracts include dedicated capacity with custom rate limits that do not share a pool with self-serve traffic, which keeps production latency predictable during peak demand. Customer-managed keys are supported through AWS KMS, Azure Key Vault, HashiCorp Vault and on-prem HSMs, and zero-knowledge mode is available where the threat model requires it.
- Audit-log export to Splunk, Sentinel, QRadar or Datadog.
- Right-to-audit clauses and custom sub-processor restrictions.
- Quarterly business reviews and a named CSM with a direct channel.
Compliance and legal
Enterprise is where regulated buyers get the paperwork that matches the architecture: a DPA with EU SCCs, a BAA for healthcare workloads, SOC 2 Type II reports under NDA, ISO 27001/27017/27018 programs and PDPL alignment for the GCC. FedRAMP Moderate is in process with a targeted Q4 2026 milestone, so federal teams should treat it as pending and validate current status.
Commercials are annual contracts quoted per deployment, security requirements and volume. The live pricing page shows self-serve plans; Enterprise pricing comes from a scoping conversation.
Scoping an Enterprise engagement
The fastest path to a decision is a deployment plan rather than a feature list. Bring your data-residency mapping, the controls your auditors expect, expected tokens and concurrency, and the deadline you are working against. That lets the team size dedicated capacity and confirm which compliance artifacts are available now versus later.
Start with a pilot on the production topology, not just plugsky.com cloud. Half the value of Enterprise is proving the integrated controls — keys, logging, network and identity — before you commit.
Honest comparison
| Requirement | Plugsky Enterprise | Self-serve plans | Building an internal platform |
|---|---|---|---|
| Data residency | Region-locked planes, VPC, on-prem, air-gapped | Region choice on cloud plans | You build it |
| Capacity | Dedicated GPU, custom rate limits | Shared fair-use limits | You buy and run GPUs |
| Key custody | BYOK via KMS or HSM | Vendor-managed keys | You operate the HSM |
| Compliance artifacts | BAA, DPA/SCCs, SOC 2 under NDA, audit clauses | Standard terms | You certify yourself |
| Support | Custom SLA, named CSM, QBRs | Ticket and community support | Your own team |
| Time to production | Pilot in weeks | Days | Quarters |
Frequently asked questions
Can Plugsky run in our own cloud account?
Yes. VPC deployment installs the control plane in your AWS, Azure or GCP account, with private networking and customer-managed KMS keys.
Is air-gapped deployment available?
Yes. Air-gapped deployments run with no internet connectivity, and updates arrive as signed bundles on approved physical media.
Can we use our own encryption keys?
Yes. BYOK is an Enterprise feature, with support for AWS KMS, Azure Key Vault, HashiCorp Vault and on-prem HSMs.
Do Enterprise plans have dedicated capacity?
Yes. Enterprise contracts include dedicated capacity and custom rate limits rather than sharing the self-serve pool.
What support is included?
Custom SLAs, a named CSM, quarterly business reviews and a direct channel; incident-response targets are defined per P1/P2/P3.
How do we handle procurement and compliance?
Banks and government teams typically combine the DPA with SCCs, a BAA where needed, SOC 2 Type II under NDA, residency documentation and right-to-audit clauses.
How is Enterprise priced?
Pricing is quoted per deployment, security and volume on an annual contract. See the live pricing page for self-serve plans and contact sales for an Enterprise quote.
Is FedRAMP authorization available?
Not yet. FedRAMP Moderate is in process with a targeted Q4 2026 milestone; confirm current status before committing federal workloads.
Plugsky (2026). “Plugsky Enterprise — Sovereign AI and Custom SLAs”. Plugsky. Available at: https://plugsky.com/articles/enterprise (last updated 2026-09-25).