Markdown

Private AI Deployment Decision Matrix

Use this to choose a deployment pattern by data sensitivity and operational capacity.

Data Classification

Data classExamplesCandidate boundary to evaluate
PublicPublished pages, public docsApproved service with verified terms and output controls
InternalInternal notes, minimized or properly de-identified examplesApproved enterprise service or controlled deployment after data-flow review
ConfidentialCustomer data, contracts, source code, financialsLegal/security-approved design after complete data-flow, access, retention, logging, and recovery review
RestrictedHealth, legal privilege, HR investigations, regulated recordsQualified legal/security/domain review; AI may be prohibited or require a purpose-specific controlled design
Credentials/secretsPasswords, API keys, private keys, session tokensExclude from model input, retrieval, prompts, ordinary logs, and generated output

Pattern Comparison

PatternBoundary evidence to verifyCapabilityCostOps burdenCandidate fit
Consumer SaaSCurrent terms, training/use, retention, deletion, support access, subprocessors, transfersMeasure on taskVerify current pricing and switching costUsually lower, still needs ownershipPublic or expressly approved low-risk work
Enterprise SaaSContract, tenant isolation, admin controls, logs, data paths, deletion, support and subprocessorsMeasure on taskContract plus implementation/oversightShared with vendorApproved organisational workloads within contract
VPC/private cloudEvery model, control-plane, log, support, backup, network and fallback pathMeasure on taskCapacity/service plus engineering and controlsMedium/highDefined cloud boundary after end-to-end verification
Self-hosted inferenceHosting, model artifacts, telemetry, updates, operator access, logs, backups, supply chainMeasure on taskHardware/capacity plus full operationsHighControl-sensitive/custom workloads with capable operators
Local-device modelDevice security, model/app telemetry, updates, backups, sync, physical accessMeasure on taskDevice plus support and lifecycleVariableNarrow offline-capable tasks after device/data-flow review

Decision Questions

Routing Rule

Use caseDataOutput impactChosen boundaryOwner
Draft / recommendation / action / decision