LEAF Advisory · Confidential AI

AI on infrastructure you control.

For organizations that cannot send confidential data to third-party AI services. We work with your IT and security teams to assess the options, co-design private AI on-premises or in isolated environments, and put it into practice together, with LEAF Labs engineering support where needed.

Explore it with us
What It Is

Private inference, designed as architecture.

Confidential AI means running models on systems you control, so that data, prompts, outputs and logs stay within boundaries you define. It is not a product you install: it is an architecture decision that touches infrastructure, identity, networking and governance, and we work through it with you as a consulting engagement.

Architectures can be designed to support customers operating under specific regulatory, security and data-residency requirements. Together with your security, legal and IT teams, we translate those requirements into concrete technical choices that fit your processes.

Deployment Models

Where the models run

Together we assess which option fits your data, your constraints and the teams who will operate it.

On-premises inference

Models served from your own servers and GPUs, in your data center, integrated with your existing network and operations.

Private cloud

Dedicated infrastructure in a cloud environment you control, in the region you choose, without sending data to shared third-party AI APIs.

Isolated and air-gapped

Environments with no external connectivity, where models and updates enter through controlled transfer procedures.

Hybrid with clear boundaries

Confidential workloads stay private while less sensitive tasks use external services, with explicit rules on which data may cross the boundary.

Hardware we have worked with in client engagements

Sized to the workload, from compact edge hardware to multi-GPU data-center infrastructure. Hardware is selected with you for each engagement rather than by default.

Compact and edge

Raspberry Pi 5 with a Hailo AI accelerator for on-device camera and video inference, keeping visual data on site.

Team and department

NVIDIA DGX Spark (GB10) for private inference, RAG and model adaptation serving a team, on a desk or in a server room.

Data center

NVIDIA servers with dual H200 GPUs for larger models, more concurrent users and heavier document workloads.

Security & Governance

What we work through together

Access control

Who can use which model, on which data sources. Integration with your identity provider and role-based permissions that mirror the ones already in place.

Auditability

Logging of queries, administrative actions and model changes, retained according to your policy and kept in your environment.

Data residency

Clear knowledge of where data, embeddings, caches and logs are stored and processed, including backups and temporary files.

Security architecture

Network segmentation, encryption, secrets management and hardening of the serving stack, designed with your security team.

Model supply chain

Verified model sources, license review, version tracking and a controlled process for introducing new models or updates.

Enterprise governance

An inventory of AI use cases, owners and approvals, so the architecture fits your existing risk management and change processes.

How We Work

Side by side with your teams.

Scout, Connect, Unlock: the LEAF method, applied with your IT, security and compliance teams from the first assessment to everyday use.

01

Understand and assess

Together we map use cases, data classification, threat model, regulatory and data-residency requirements, and existing infrastructure.

02

Co-design

Deployment model, model selection, hardware sizing, access and logging, defined with your teams in a shared architecture proposal.

03

Pilot together

A pilot on your infrastructure, built with your IT team and LEAF Labs engineering support where needed, to validate quality, performance and controls on real workloads.

04

Embed and adopt

Runbooks written with your IT team to embed the result in your processes, and LEAF Academy helping the people who will use it.

Explicit Limits

What private AI does not solve on its own

  • Running models on your infrastructure does not make an organization compliant. Compliance depends on processes, people and controls that are assessed by you and your auditors.
  • LEAF does not present itself as holding security or compliance certifications for this service.
  • Models that can be hosted privately may differ in capability from the largest proprietary cloud models. We evaluate them with you on your tasks before recommending one.
  • Hardware, operations and model updates become your responsibility, or that of a partner you choose. We plan for that together from the start.
FAQ

Questions & Answers

Common questions about Confidential AI.

Ask Us Anything

Confidential AI is AI deployed on infrastructure the customer controls, such as on-premises servers, a private cloud environment or an isolated network, so that confidential data, prompts and outputs do not have to be processed by third-party AI services. At LEAF it is an Advisory consulting service: we work with your IT and security teams to assess the options, co-design the architecture, pilot it together and embed it in your processes, with LEAF Labs engineering support where needed.

With a public AI API, data leaves your environment and is processed under the provider's terms. With Confidential AI, inference runs inside boundaries you define, and you control access, logging and retention. The trade-off is that you take on hardware, operations and the model lifecycle, and the models you can host yourself may differ in capability from the largest proprietary cloud models.

Yes. Architectures can be designed for isolated or air-gapped networks, where models, dependencies and updates are brought in through controlled transfer procedures instead of network access. This requires planning for updates, monitoring and model evaluation without external connectivity.

No. LEAF does not present itself as holding security or compliance certifications for Confidential AI. Architectures can be designed to support customers operating under specific regulatory or compliance requirements, such as GDPR obligations on personal data or data-residency rules. Compliance is assessed by the customer and its auditors across the whole organization, not by the AI system alone.

Models whose weights can be hosted locally under their license terms, including language, embedding, vision and speech models. Selection considers license conditions, performance on your tasks and languages, and the hardware available. Together with your team we evaluate candidate models on your data before recommending one.

It depends on the models, the number of users and the type of workload, for example interactive assistants, document processing or batch analysis. In client engagements LEAF has worked with a wide range of hardware: from a Raspberry Pi 5 with a Hailo accelerator for on-device camera and video inference, to NVIDIA DGX Spark (GB10) for team-scale use, up to NVIDIA servers with dual H200 GPUs. Together we size hardware from workloads measured during a pilot rather than from generic estimates.

The architectures we design with you can integrate with your existing identity provider, apply role-based permissions per use case and data source, and log queries and administrative actions according to your retention policy. Logs stay in your environment. These controls are designed together with your security and compliance teams.

Yes. Retrieval and conversational interfaces over internal documents and databases can run inside the same private boundary and respect existing permissions. This is the focus of our Talk with Your Systems engagements.

With a joint assessment of your use cases, data classification, regulatory and data-residency requirements, and existing infrastructure, following the Scout, Connect, Unlock method. The outcome is an architecture proposal and a pilot plan agreed with your teams. The pilot is then built together with your IT team, with LEAF Labs engineering support where needed, and LEAF Academy helps the people who will use and operate it.

Need AI without sending data outside your boundary?

Tell us about your data, your requirements and your infrastructure. We will work out with you whether a private setup fits, and how to design and adopt it together.

Start the conversation