Feature × Audience

How does government use Model Fusion with Plugsky?

Government teams use Plugsky Model Fusion to blend model tiers inside controlled environments: low-sensitivity work runs on cheap models while sensitive analysis escalates to stronger tiers, with a fixed model override wherever determinism is required. Fusion runs in-cloud with region pinning or fully air-gapped on-prem, and every routing decision is logged for oversight.

Key facts

Router modelmodel="plugsky-fusion" selects and blends models per request (live)
DeploymentRegion-pinned cloud, VPC, on-prem Helm and fully air-gapped bundles
DeterminismExplicit model names bypass routing for sensitive or repeatable flows
Strategiescost_saver, balanced, max_quality, custom; set per workspace, key or request
Decision logModel, strategy and rule recorded per request; exportable to SIEM
Data handlingNo-PII, detect-only and passthrough modes for prompt content
ResidencyData never leaves the pinned region; sa-central-1 available on Enterprise
RoadmapClassifier routing /v1/plugsky/route (model=auto) is coming soon

TL;DR

  • Run fusion in the deployment model your classification level demands.
  • Use cheap tiers for public-facing services and escalate sensitive analysis.
  • Pin a fixed model wherever repeatability matters more than optimisation.
  • Log every routing decision and export the trail to your SIEM.
  • Keep a human owner for any decision the system influences.

How it works, step by step

  1. Classify workflows by sensitivity and map each to an allowed model tier.
  2. Choose the deployment topology per workload: region-pinned cloud, VPC, on-prem or air-gapped.
  3. Set strategies per workspace and add deterministic overrides for repeatable or sensitive flows.
  4. Configure PII handling before any citizen or case data reaches a prompt.
  5. Export routing, key and admin events to your SIEM and define who reviews them.
  6. Pilot on an internal service, document the evaluation results, then extend to public-facing workflows.
1Classify workflowsby sensitivity andmap each to an2Choose thedeployment topologyper workload:3Set strategies perworkspace and adddeterministic4Configure PIIhandling before anycitizen or case5Export routing, keyand admin events toyour SIEM and6Pilot on aninternal service,document the

Try it yourself

Open the AI workload router simulator →

Sovereignty first, optimisation second

For government workloads, where the model runs outranks which model runs. Plugsky supports region-pinned cloud deployments, VPC inside your own account, on-prem Helm installations and fully air-gapped bundles shipped on physical media with monthly model refresh by courier. Fusion operates inside all of them.

Once the boundary is set, tiering becomes a lever rather than a risk. Public information services can run on cheaper tiers while case analysis, policy drafting and investigative summaries escalate to stronger models — all within the same controlled environment.

Determinism, oversight and the audit trail

Some government processes must be repeatable: a decision that reproduces differently on Tuesday than Monday invites appeals. For those flows, send an explicit model name to bypass routing and hand the choice back to policy. For everything else, fusion's decision log gives oversight a readable chain — which model answered, under which strategy, triggered by which rule.

  • Export: routing and inference events stream to Splunk, Sentinel, QRadar or Chronicle via webhook or Kinesis/Firehose.
  • PII: no-PII mode auto-redacts, detect-only tags, passthrough leaves controls to your agency.
  • Keys: BYOK and HSM integrations let you hold the encryption keys.

Procurement and evidence

Sovereign AI procurement asks for evidence, not adjectives. Plugsky publishes its data regions, retention behaviour, audit logging and deployment topologies, and enterprise contracts include a DPA and the option to specify in-region routing. Start the pilot against a documented evaluation: a fixed case set, agreed success criteria and a review of the routing log.

The commercial shape is also simpler to defend: flat self-serve plans carry no per-token charges, so multi-model patterns do not create unpredictable spend, and enterprise agreements are priced to deployment and volume rather than metered inference. See the live pricing page for current options.

Honest comparison

ConcernPlugsky Model FusionPublic cloud AI APIsAgency-built stack
DeploymentCloud, VPC, on-prem, air-gappedVendor regions onlyOwn data centre
Routing controlStrategies plus deterministic overridesLimitedCustom router
Decision loggingModel, strategy and rule per requestVendor logsOwn implementation
Key controlBYOK and HSM optionsUsually vendor-heldAgency-held
Time to pilotWeeksWeeks to monthsQuarters

Frequently asked questions

Can fusion run fully air-gapped?

Yes. Air-gapped bundles ship on physical media with no internet connectivity and a monthly model refresh by courier.

Can sensitive work avoid model blending entirely?

Yes. Send an explicit model name to bypass routing on any request or endpoint.

How is a routing decision audited?

Each request records the chosen model, strategy and matching rule, and those events can be exported to your SIEM.

Who decides which tier a workload may use?

Your agency does, through strategy configuration per workspace or key, plus deterministic overrides where policy requires them.

Is citizen data used for training?

Prompts and completions are not used to train models, and request bodies are not retained. No-PII mode adds automatic redaction before inference.

Does the platform meet public-sector procurement requirements?

Enterprise contracts include a DPA, region-specific routing options and audit exports; sovereign packages are scoped to deployment, security and volume.

How should a pilot start?

Choose one internal service, define evaluation criteria, run on the free tier or a trial workspace, then review the routing log before expanding.