Skip to content
Feerasta Sovereign · Private AI

Private AI on your own ground.
Your data stays inside your boundary.

Private AI built around your infrastructure and operating requirements. Start with an assessment, then agree the deployment, controls and support with your team.

On your infrastructure No data sharing You own it outright
The path every deployment takes

Assessed, agreed, then deployed.

Start with an assessment, agree the deployment with your team, then four stages.

Assessed, agreed, then deployed on your ground You take the free sovereignty self-check. The Sovereignty Assessment, from $5,000 at a fixed fee, produces a deployment plan. You agree the deployment, controls and support with your team. Four stages follow: for regulated clients the right paper is signed before any data is touched, the AI is deployed on your own infrastructure, your security and compliance teams review its configuration and evidence, and your team is trained. All four done hands you a system you own and run. If the paper is not signed, no data is touched and the plan is yours to keep. FOUR STAGES, INSIDE YOUR BOUNDARY START PLAN PROCEED NOT SIGNED ALL FOUR DONE The free self-checksovereignty self-check Sovereignty Assessmentfrom $5,000, fixed fee You agree the deploymentdeployment · controls · support STAGE 1The right paper, signedfor regulated clients, beforeany data is touched STAGE 2Deployed on your groundon-prem or private cloud,behind your access controls STAGE 3Your teams review itconfiguration and evidence,against your requirements STAGE 4Your team is trainedprompts and workflowsthat fit your practice No data is touchedthe plan is yours to keep A system you own and runon your hardware, your control

Pick a scenario, or any box.

Scroll the diagram sideways to see the whole path.

The problem

Public AI means your data leaves.

Every prompt you send to a public AI tool is a copy of your work leaving your walls.

Your IP walks out

Contracts, case files, patient records, financials, source code, now sitting on someone else's infrastructure.

Compliance breaks

HIPAA, GDPR, attorney-client privilege, financial confidentiality. Most public AI tools were never built to honour them.

You lose control

Retention, training on your inputs, vendor access. The terms can shift under you at any time.

What we build

AI that runs where your data already lives.

The intelligence comes to your data, not the other way around.

Private assistants

Drafting, research, summarisation, Q&A over your own documents, running fully inside your walls.

On-prem workflows

Review, intake, classification and document workflows, with nothing routed to a public API.

Your infrastructure

Your servers, your private cloud, or air-gapped hardware.

How private is private

Choose your ground. Three tiers of sovereignty.

Same capability, different perimeter.

Private cloud

A dedicated environment inside your own cloud account. Single-tenant, your keys, your region.

On-premise

On your servers, behind your firewall. Nothing crosses your perimeter.

Air-gapped

No internet at all. The system runs entirely disconnected, updated by hand on your schedule.

It runs on an open-weight model on your hardware, so you are not tied to any one AI vendor.

The detail
  • Private cloud: fastest to stand up, and enough for most data-residency rules.
  • On-premise: the model and your data sit side by side under your roof.
  • Air-gapped: for controlled, classified, or absolute-secrecy work.
  • You can swap or upgrade the model without rebuilding.
  • Your data never trains anyone's model but yours.
Solutions we build

Private AI, productized for regulated work.

The systems we deploy inside your walls, each one built around a job your compliance team can sign off on.

Private legal AI

Your matters, precedents, and filings, searchable and draftable by AI, with privilege preserved and nothing sent outside.

The detail
  • Matter-aware retrieval over privileged documents
  • Drafting with citation and quotation integrity
  • Isolation by matter, client, and practice group
  • Audit log of every query and generation

Clinical documentation AI

A private medical scribe that turns the visit into structured notes, with protected health information that stays inside your boundary.

The detail
  • Drafts structured clinical notes
  • PHI processed and stored on-premise only
  • Built to HIPAA and PHIPA expectations
  • No data trains a shared model

Compliance-ready RAG

Retrieval and drafting over controlled, sensitive documents, for defense suppliers and any business holding regulated data.

The detail
  • Aligned to CMMC 2.0 and federal handling rules
  • Controlled-unclassified-information aware
  • Runs in your perimeter, or air-gapped
  • Full access controls and logging

Document & knowledge intelligence

Search, summarise, and draft across your own files, with answers grounded in your documents, not the public internet.

The detail
  • Answers grounded in your own files
  • Search and draft over years of documents
  • Connected to the systems you already use
  • Nothing routed to a public API

On-prem automation

Intake, classification, and review workflows, without exposing the data.

The detail
  • Document intake and classification
  • Automated first-pass review and routing
  • Wired into your current tools
  • Human-in-the-loop where it matters

Retained advisory

Ongoing cross-border AI governance and risk guidance, as a fixed annual engagement.

The detail
  • US and Canada cross-border guidance
  • Governance, risk, and policy support
  • Documentation for your compliance review
  • A fixed annual engagement
Who it's for

Built for the organizations AI usually locks out.

If your data is privileged, protected, controlled, or bound to a jurisdiction, the public cloud was never an option. This is.

Law firms Healthcare & clinics Finance & accounting Defense & government suppliers IP-heavy & R&D
How it works

Assess. Deploy on your ground. Train your team.

Assess

We map your data, your compliance lines, and your hardware, then design the right private deployment.

Deploy on your ground

We stand up the AI on your own infrastructure, locked behind your access controls.

Train your team

We onboard your people and hand you a system you own and run.

Sovereignty by design

You own it. Nothing is shared.

Sovereign isn't a setting we toggle, it's the architecture.

Data never leaves

Your documents, prompts and outputs stay inside your network.

No data sharing

Nothing is used to train outside models. Nothing is sent to a vendor.

You own the system

The deployment lives on your hardware under your control.

Security & data handling

The controls we build, not promises.

Sovereignty is enforced by how the system is built.

▢

Deployment

  • On-premise, on your own servers
  • Your private cloud, AWS, Azure or GCP
  • Fully air-gapped where required
⛨

Encryption

  • Encryption at rest on storage you control
  • Encrypted in transit
  • Keys held inside your boundary
⊞

Access

  • Named accounts, invited by an owner you appoint
  • Role-based access control (RBAC)
  • Full audit logging of every action
∅

Training

  • Nothing trains on your data
  • Enforced by architecture, not policy
  • No data leaves to improve a vendor model
◷

Retention

  • You set the retention rules
  • You can purge on your own schedule
  • We can't see it, there's nothing to retain on our side
⇄

Network

  • No outbound calls to public model APIs
  • No third-party logging or telemetry
  • Egress locked to what you allow
§

Compliance posture

Architected to support HIPAA, GDPR, and attorney-client-privilege obligations. The deployment is designed to sit within your existing controls. Your security and compliance teams review its configuration and evidence against your requirements.

Architected to support HIPAA Architected to support GDPR Designed for attorney-client privilege Designed for financial confidentiality
Where your data lives

Your data never crosses the line.

The model and your data are co-located inside your boundary.

Public internet, outside
Public model APIs✕ Third-party logging✕ Vendor servers✕
Your boundary
Inside your boundary
◆ The model Runs on your hardware or private cloud
⇄
▤ Your data Documents, records, prompts & outputs
⇄
⊞ Your team Behind your own access controls
Your data never crosses the line.

Start with the Sovereignty Assessment.

Begin with the Sovereignty Assessment, fully credited toward your deployment if you proceed. The plan is yours to keep, and yours to act on with anyone.

Fully credited if you build · The plan is yours to keep
For law firms

The one profession where private AI isn't optional.

Most firms simply cannot put matter files into public AI tools. So we built the version that never leaves the firm.

The detail

Confidentiality rules, client consent requirements, and the very public risk of AI-invented citations mean most firms simply cannot put matter files into public AI tools.

Answers from your matters, with citations

Answers grounded in the firm's documents, each one citing the source file it came from.

It refuses to invent authority

Ask it about a case that doesn't exist in your records and it says exactly that: "I don't find that in the firm's records." No fabricated citations, no invented holdings, by design.

Privileged stays privileged

The whole system, models, documents, and questions, runs inside the firm's own boundary, with access set by your firm.

We run this system ourselves and demo it live on our own hardware, using a fictional firm's files. Watch it cite real sources and refuse a fake case before you trust it with yours.

Security FAQ

The questions your security team will ask.

The same answers we'll put in front of your CISO and your auditors.

Where does the model actually run?

On infrastructure you control, your own servers on-premise, your private cloud tenant (AWS, Azure or GCP), or air-gapped hardware. The model is co-located with your data inside your boundary. There is no public endpoint in the path.

Can Feerasta see our data?

No. The system runs inside your environment, behind your access controls. Your documents, prompts and outputs stay on your infrastructure. We don't operate a shared service that your data passes through, so there is nothing for us to see and nothing for us to retain.

What happens to our data if we stop working with you?

Nothing changes, because the data was never ours to hold. The deployment lives on your hardware and the data stays where it always was, inside your boundary. There is no vendor copy to delete and no account to wind down.

Is it air-gap capable?

Yes. For the most sensitive environments we deploy fully air-gapped, no inbound or outbound internet path at all. Updates in that mode are delivered through your own controlled, offline process rather than over the network.

What hardware do we need?

It depends on the models and workloads you choose. We size this precisely during the Sovereignty Assessment, from a single GPU server for a focused assistant up to a small cluster for heavier, organization-wide use. We'll fit the deployment to hardware you have or specify exactly what to buy.

How do updates work without touching our data?

Updates apply to the model and software layer, not your data. New model versions and improvements are deployed into your environment under your change control, your data is never moved, copied or exposed to do it. In air-gapped deployments, updates are staged through your offline process.

Engagements

Built to your ground, priced to your scale.

Every sovereign deployment is scoped to your data, hardware and compliance needs. These are the typical starting points.

Sovereignty Assessment

From $5,000 · fixed fee

A fixed-scope study under NDA. Fully credited toward your build.

Most engagements start here.

The detail

A fixed-scope study under NDA: data map, governance and risk review, compliance review, hardware fit and a deployment plan you can act on with anyone. Fully credited toward your build.

Best when you need certainty before you commit.

Most chosen

Private Deployment

Scoped to your build

A private AI assistant and core workflows deployed on your infrastructure, with team training and handover.

One-time build on your hardware or private cloud. You own the result.

Managed Sovereign

Custom

Ongoing operation, tuning, new workflows and on-call support, while everything stays inside your walls.

For enterprise & regulated organizations

The same sovereignty, governed and managed at scale.

For mid-market and enterprise teams that cannot ship AI on a public endpoint, Sovereign scales into a fully governed program.

Governance, not just a model

Most of the work is control: deployment boundaries, encryption, access, retention, and the evidence to prove it.

Embedded delivery

We work alongside your technical and compliance teams and hand over a system your people can run and govern.

Attested operation

Risk map, controlled build, and an operated system with the monitoring and documentation your CISO, board, and regulators sign off on.

We do not claim a certification on your behalf

Deployments are designed to sit inside your own controls for HIPAA, PHIPA, GLBA, CMMC 2.0, Quebec Law 25 and GDPR. Your auditors audit your deployment; we do not claim a certification on your behalf.

The right paper, signed before any data is touched

For regulated clients we sign the right paper before any data is touched: a HIPAA Business Associate Agreement or Ontario PHIPA agreement for healthcare, GLBA service-provider terms for finance, and our data processing agreement, signed on request, for every engagement.

Export-controlled work is scoped case by case

Export-controlled (ITAR/EAR) work is scoped case by case with counsel.

Enterprise engagements begin with the Sovereignty Assessment: from $5,000, fixed fee, under NDA, credited to the build.

Get started

Put AI to work, without giving up your data.

One call. We'll show you exactly how private AI runs on your own ground, and what it takes to deploy it.