Any cloud, your own region, on-premises, or fully air-gapped.
The same platform in every one of them, on standards your team already runs. For estates where a hosted service is ineligible before the feature comparison starts.
DataByte runs entirely inside a perimeter you own. It deploys to your own cloud account, to a specific region, to your own data centre, or fully air-gapped with no route to the public internet, and it is the same platform in each case, built on Apache Spark, Kubernetes and Open Policy Agent. The AI models are self-hosted alongside it, so the copilots work with no connection to a model provider. Data leaves only when someone exports it, and that export is authorised and recorded like any other action.
Four boundaries. One platform.
Which one applies to you is a procurement and regulatory question rather than a technical one, and it is settled before anything is installed.
Your cloud
AWS, Azure or GCP, in your own account and your own VPC, on Kubernetes your team already knows how to run.
Your region
US, EU or APAC. Data stays in the chosen region unless an explicit export action moves it, and that action is written to the audit trail.
On-premises
Your own data centre, your own hardware, your own network boundary, with the same platform and the same release train.
Fully air-gapped
No route to the public internet at all. The platform, the modules and the models all run inside the perimeter.
An air-gapped deployment stays air-gapped when you add AI to it.
Plenty of platforms deploy on-premises. Far fewer keep that property once an AI layer is switched on, because the agent calls a hosted model provider and the boundary quietly acquires a hole in it that nobody wrote down.
The models are self-hosted
They run on your own infrastructure alongside the rest of the platform. An air-gapped deployment stays air-gapped on the day you add AI to it.
No prompt leaves the perimeter
A copilot reads live platform metadata inside your boundary. There is no call to a hosted model provider, so there is no question about what was sent.
Agents inherit the boundary
All 41 copilots and anything built in Agent Studio run under the same constraint. The AI layer is not an exception carved out of the deployment model.
How the agent layer is governed once it is inside the perimeter is on the AI governance page.
What you give up, honestly.
Cutting a platform off from the network costs something. Three things, and they are the same three for anyone who does this properly.
Updates arrive in batches
A connected deployment picks up improvements continuously. An air-gapped one takes them as reviewed, signed artefacts on a schedule your security team controls, which means you are deliberately behind and you decide by how much.
Nothing is learned from anyone else
Models and detections improve from your estate alone. That is exactly the point for a sovereign deployment, and it does mean a pattern common across other customers has to be met here for the first time.
We cannot see it to help
No telemetry leaves, so support works from what your team exports and shares. Diagnosis takes longer than on a deployment we can observe, and that is a round trip to plan for rather than a surprise during an incident.
Six deployment questions, answered plainly on the FAQ: what fully air-gapped means, whether DataByte receives anything, and how residency is enforced.
Bring your network diagram.
A working session with an engineer who has deployed inside this kind of boundary before.