Air-gapped boundary: chaotic data blocked on the left, clean orderly flows protected on the right

Enterprise

Your company is already using AI. The question is "Do you control it?"


Private, no-egress AI infrastructure deployed into your AWS account.

Frontier models inside a boundary with no route to the public internet.

Six independent isolation layers. Client-owned KMS. Full audit custody.

No standing access. Break-glass only, customer-approved, time-boxed.

Managed software deployed into your AWS account. Not a box. Not an appliance.

The landscape

The numbers your board already knows

It sounds like you are being asked to approve AI without a boundary you can defend. You are not alone. Here is what the numbers look like.

$4.4M

Average cost of a data breach

Cost of a Data Breach Report, 2025

25-75%

Prompt injection success rates in published evaluations

International AI Safety Report, 2026

$200K+/mo

Opportunity cost of not using AI

100 seats at $100/hr, 5 hours saved per week

Banning AI does not stop your people from using it. It just stops you from knowing how. The alternative is approving something defensible.

The architecture

Six independent isolation layers. No single point of failure.

Every layer is independently enforced. Disabling one does not weaken the others. There is no accidental path out.

Six independent isolation layers stacked as defense in depth, with threats deflected at each layer

Defense in depth: to exfiltrate data, an attacker must defeat all six independent controls. Disabling one does not weaken the others.

1

VPC boundaries

Dedicated VPC with private subnets only. No internet gateway. No NAT gateway. No public IP addresses anywhere in the environment.

2

Network ACLs

Stateless deny-all rules at the subnet level. Only explicitly allowed traffic between internal services passes through.

3

Security groups

Stateful firewall rules on every resource. Tightly scoped ingress and egress rules per service. No default "allow all" posture.

4

Route tables

No route to 0.0.0.0/0. Traffic can only reach internal endpoints and AWS services via VPC endpoints. There is no path out.

5

VPC endpoints

All AWS service communication stays on the AWS backbone via private endpoints. Bedrock, KMS, S3, CloudWatch. None of it touches the internet.

6

Service control policies

Organization-level guardrails that prevent accidental egress. Opening the boundary requires explicit org-admin action and leaves an audit trail.

Public AI vendors

"We won't look."

A policy. Enforced by policy and access controls inside a third-party boundary. Revocable at any time.

Totally Private AI

"We can't look."

An architectural constraint. Enforced by infrastructure. Your keys, your account, no path in for us.

Deployment

Your cloud. Your keys. Our software.

Your infrastructure

You own

Your boundary

AWS account in your organization. You pay AWS directly.

KMS keys generated in your account. Totally Private AI never has access to your key material in production.

VPC and networking. Private subnets, no internet gateway, your route tables.

Audit logs. CloudTrail, VPC Flow Logs, application audit trail. All in your account.

User access. VPN, Direct Connect, or PrivateLink. You decide how users reach the environment.

Identity and provisioning. SAML SSO, Okta, Azure AD, or your existing IdP. You control who gets in and how.

We maintain and protect

We manage

The application

Deployment and updates. We install the platform and push updates through a controlled pipeline.

Application monitoring. Uptime, performance, and anomaly detection on the application layer.

Model access. Frontier models via Amazon Bedrock, routed through private VPC endpoints.

Support and training. Onboarding, user training, and ongoing technical support.

Custom integrations. API work, workflow automation, and legacy system connections as needed.

Break-glass and incident response. Customer-approved, time-boxed, fully audited. Covered in detail below.

Enterprise deployment moves the environment into your AWS account. During a Proof of Concept, we host in our account so you can go live in days. Same boundary principles and security posture. Enterprise adds customer-owned account, keys, and audit custody.

What changes

The business case is not just risk avoidance. It is productivity at scale.

Work that took hours compressed into minutes, with freed capacity growing as value

5+ hrs/week

Back per professional, measured

Drafting, summarizing, research, and analysis that used to take hours now takes minutes. That capacity goes straight back into billable work and client service.

Weeks

Go-live, not quarters

Not months. Not years. We deploy into your AWS account and your people are working with AI the same week. A DIY build takes 18 to 36 months and requires a dedicated engineering team.

500%+

ROI by Year 2

The productivity gains outpace the investment before the first quarter ends. By year two, you are operating at multiples of your deployment cost.

Zero

Internal platform build required

No platform team. No model hosting. No security review of a homegrown solution. We build, deploy, and maintain the infrastructure. Your engineers stay on their roadmap.

Run the numbers for your organization:

Interactive ROI calculator Build vs. Buy brief

Access controls

Zero standing access. Every entry is earned.

1

Request submitted

Engineer submits a break-glass request with a documented reason and scope.

2

MFA required

Multi-factor authentication before any temporary credential is issued.

3

Client approval

Your designated contact must approve the access request before it is granted.

4

1-hour max, auto-audit

Credentials expire automatically. Every action is logged. A full audit record is available to you.

No one at Totally Private AI has standing access to your production environment. Break-glass only: customer-approved, time-boxed, fully audited. If we need in, you know about it, you approve it, and it expires automatically.

All chat data is encrypted per-user with your KMS keys. Software updates do not access the database. Your enterprise admins retain full access to organizational data through your own controls.

Evidence and compliance

Architecture alignment you can evidence, not checkbox compliance

We publish evidence packs for every region. Architecture diagrams, data-flow documentation, responsibility splits, and regulatory alignment summaries. Your compliance team reviews artifacts, not marketing claims.

United States

HIPAA, NYDFS 500, SOC 2, NIST 800-53, SEC, FINRA

Evidence pack →

European Union

GDPR, DORA, NIS2, EU AI Act, ISO 27001

Evidence pack →

GCC

PDPL (Saudi/UAE), SAMA, NCA ECC, CBUAE, DIFC/ADGM

Evidence pack →

Asia-Pacific

MAS TRM, APRA CPS 234, PDPA, PDPB, FSA/FISC, PDPO

Evidence pack →

Certification roadmap

ISO 27001

In progress

SOC 2 Type II

Planned

ISO 27701

Planned

ISO 42001

Planned

What is in the evidence pack

Architecture diagram and data-flow documentation

Boundary proof checklist: egress controls, encryption, key custody, logging

Regulatory alignment summary for your jurisdiction

Shared responsibility matrix (what you own vs. what we operate)

Pre-filled security questionnaire answers

The math

The cost of not using AI is over $200,000 a month

Without AI

$200K/month

In lost productivity alone. Your professionals spend 5+ hours per week on work AI completes in minutes. That time has a dollar value.

100 seats x $100/hr x 5 hrs/week x 4.3 weeks = ~$215K/month in recoverable capacity

With Totally Private AI

500%+ ROI by Year 2

Payback begins in the first month. Even with installation costs, the productivity gains outpace the investment before the first quarter ends.

Installation pays for itself in weeks, not months

Building it yourself?

Read the brief →

DIY cost (Year 1)

$1.5M - $2.5M

Plus $3.87M in opportunity cost while your team builds instead of ships. 18 to 36 months before production. And a "server in a closet" does not scale past 100 seats.

TPAI Enterprise (Year 1)

Talk to us

Production-ready in weeks. No internal engineering team required. Your people use AI on day one, not year two.

Your data. Your cloud. Your keys.

Start with a conversation. We will walk you through the architecture, share the evidence pack for your region, and answer the hard questions your compliance team will ask.

Or email us directly at enterprise@totallyprivate.ai