Private AI — you choose the model and hardware, ASG tunes, benchmarks and manages it on sovereign nodes

Private AI

You choose the stack. We tune it and stand behind it.

Name the open-weight model and the hardware you want — we build it, tune it and benchmark it on your own data. Prefer to start from a recommendation? The worked examples below are ours. Either way it runs under a managed contract, on your premises or in an ASG data centre.

AnyOpen-weight model you choose
AnyVendor-neutral hardware combination
2Deployment models, one security standard
0Shared GPU, disks, keys or logs
Example pairings

Worked examples, not a fixed menu.

These four are combinations we have already licence-reviewed, tuned and benchmarked, so we can show you real specifications rather than a brochure. They are starting points — bring your own model, your own hardware preference, or a workload none of these fit, and we will design and tune for that instead.

Measured performance Frozen benchmark — pinned model revision, pinned runtime digest, fixed prompt set, warm-up excluded
How to read this.
What is running, and on what The full build record — revisions, checksums, runtime digests and acceptance thresholds — is issued with your As-Built pack

Model

Hardware

Compliance as a deliverable

How we actually do compliance.

Most vendors treat compliance as a badge on a website. We treat it as a monthly deliverable with a named owner. First, where your equipment physically sits and what that makes us legally. Then the mechanism behind each claim — every one maps to a numbered step in a published runbook, so your auditor can trace it.

A On your premisesNot a processor
YOUR PREMISES Your model · your keys · your logs JIT gate ASG outside your boundary
LocationYour server room, clinic, office or edge site
AssetYou own it outright
IdentityYour own tenant and licences
Our legal roleNot a data processor. We never touch your data boundary — support arrives only through a time-boxed, ticketed gate
You may say“Data and models never leave our facility”
B ASG data centreContracted processor
ASG FACILITY YOUR DEDICATED NODE SIGNED DPA
LocationYour dedicated node in ASG’s facility — never a shared pool
AssetASG holds it, with a purchase option at term
IdentityFederate your tenant, or take an isolated scope
Our legal roleContracted data processor under a signed DPA naming location and access
You may say“Data stays on our dedicated equipment inside ASG’s facility, with location and access set by contract”

Nothing is pooled. Ever.

Dedicated CPU, GPU, memory, system disk, data disk, keys, logs and admin rights per customer. The only things shared are our tooling and processes.

  • Cross-customer pooling is contractually prohibited, not merely discouraged
  • Proven at acceptance: one customer reaching another must fail at tenant scope, routing, DNS and firewall — all four

Identity first, network never

No implicit trust from network position or asset ownership. Every session revalidates user, device, resource, role and time limit.

  • Default deny, and no public management port anywhere — confirmed by an internet-facing scan
  • Our engineers need a privileged workstation, hardware MFA, a ticket number and a time-boxed grant

Version-locked and reproducible

Cloud APIs deprecate and upgrade models on the vendor’s schedule. For clinical, legal or financial review that is a defect.

  • Pinned model revision, weight checksum and pinned runtime image digest
  • Blue/green switching keeps the previous version live, so a regression is one reload away from undone

Evidence generated, not assembled

The monthly pack is produced by the fleet platform and arrives whether or not anyone asks for it.

  • Availability against SLA, incidents, changes, access review and capacity trend
  • A sampled backup restore is performed monthly and the checksum comparison is attached

We do not read your prompts

The gateway logs metadata and nothing else. This is a configuration we ship, not a policy we assert.

  • Logged: user, model version, token counts, latency, status, request ID
  • Bodies logged only on your written instruction, after a documented impact review

Exit is designed in advance

A sovereignty claim you cannot walk away from is not sovereignty. The exit procedure is in the contract on day one.

  • Contractual export with manifest and checksums, then erasure across storage, caches, snapshots, backups and logs
  • Returned hardware is wiped, re-imaged and re-numbered before it may serve anyone else
Where it goes to work

No two deployments
look alike. Every one is
built the same way.

The shapes below are ones clients bring us, and where we would start — open any of them to see how the work actually runs. The list is not the boundary. Anywhere a document gets read, a decision gets recorded, or a queue waits on a person, this can be embedded. What never varies is how it is delivered: a licence review before we quote, a benchmark on your own data before anything is committed, and an As-Built pack when it goes live.

WorkloadModel class and precisionHardware and footprint
27–35 B mixture-of-experts, 4-bitSingle compact node, ~240 W, no server room
Long-context MoE, 4-bitCompact node, or two linked for the largest models
27 B dense, FP8, fixed seed for reproducibilityDiscrete Blackwell workstation with ECC
70 B dense, FP8 — latency irrelevantRack server, single large GPU
27 B quantised, fully offlineRuggedised compact node, smart PDU
Something not on this listTell us the constraintVendor-neutral — NVIDIA, Dell, HP, Lenovo, Supermicro. If you have a hardware standard we work inside it
Where we stop. We serve inference and fine-tuning, not large-scale pre-training. We also will not quote a model we have not licence-reviewed, or a throughput figure we have not measured on the hardware you are actually buying.

Bring us your
hardest constraint.

Send us the workload, the data boundary and the audit requirement. We will benchmark a certified pairing on your own sample data and hand back the numbers — including the ones that do not flatter us.

Request a benchmark →