Private AI Deployment Decision Matrix
Use this to choose a deployment pattern by data sensitivity and operational capacity.
Data Classification
| Data class | Examples | Candidate boundary to evaluate |
|---|---|---|
| Public | Published pages, public docs | Approved service with verified terms and output controls |
| Internal | Internal notes, minimized or properly de-identified examples | Approved enterprise service or controlled deployment after data-flow review |
| Confidential | Customer data, contracts, source code, financials | Legal/security-approved design after complete data-flow, access, retention, logging, and recovery review |
| Restricted | Health, legal privilege, HR investigations, regulated records | Qualified legal/security/domain review; AI may be prohibited or require a purpose-specific controlled design |
| Credentials/secrets | Passwords, API keys, private keys, session tokens | Exclude from model input, retrieval, prompts, ordinary logs, and generated output |
Pattern Comparison
| Pattern | Boundary evidence to verify | Capability | Cost | Ops burden | Candidate fit |
|---|---|---|---|---|---|
| Consumer SaaS | Current terms, training/use, retention, deletion, support access, subprocessors, transfers | Measure on task | Verify current pricing and switching cost | Usually lower, still needs ownership | Public or expressly approved low-risk work |
| Enterprise SaaS | Contract, tenant isolation, admin controls, logs, data paths, deletion, support and subprocessors | Measure on task | Contract plus implementation/oversight | Shared with vendor | Approved organisational workloads within contract |
| VPC/private cloud | Every model, control-plane, log, support, backup, network and fallback path | Measure on task | Capacity/service plus engineering and controls | Medium/high | Defined cloud boundary after end-to-end verification |
| Self-hosted inference | Hosting, model artifacts, telemetry, updates, operator access, logs, backups, supply chain | Measure on task | Hardware/capacity plus full operations | High | Control-sensitive/custom workloads with capable operators |
| Local-device model | Device security, model/app telemetry, updates, backups, sync, physical access | Measure on task | Device plus support and lifecycle | Variable | Narrow offline-capable tasks after device/data-flow review |
Decision Questions
- What data enters the model?
- What data reaches retrieval, embeddings, model services, tools, logs, traces, support, backups, and fallbacks?
- What output impact exists?
- What quality is required?
- What latency is required?
- Who operates it?
- What proof do customers or regulators need?
- What is the fallback if the private model is not good enough?
- Which routes fail closed, and can any client bypass the policy gateway?
- How are credentials kept outside every model-visible route?
Routing Rule
| Use case | Data | Output impact | Chosen boundary | Owner |
|---|---|---|---|---|
| Draft / recommendation / action / decision |