Deployment models
We pick the deployment from your threat model and your regulator, not from what's easiest for us to host. Every option comes with the same guarantees: proof of secure execution where the hardware supports it, immutable logs, and code you own.
On-premises and air-gapped
Maximum control. Open-weight models and your software run on your own servers and GPUs, inside your network.
- Air-gapped if required: no outbound calls and no telemetry. Updates arrive as signed artifacts that you verify and import.
- You trust your own facility and staff, and the hardware vendor. No cloud or model provider is in the path.
- Best for: defense-adjacent work, core IP, sites with strict residency rules, and labs that already have GPU capacity.
- Trade-off: you own the hardware lifecycle. We can manage it remotely under your access controls.
Colocation
Your hardware, in the jurisdiction you choose, without running a data center. We source the GPUs and servers and place them in a professional facility in the region your data has to stay in, then run them under your keys. See GPUs, hardware and colocation.
Confidential cloud
Scale without having to trust the cloud. Your workloads run in hardware-isolated confidential VMs, with encrypted memory the cloud operator can't read.
- CPUs: AMD SEV-SNP and Intel TDX confidential VMs on the major clouds, in the regions that offer them
- GPUs: NVIDIA confidential-computing mode (Hopper and Blackwell class) for model inference and training on sensitive data
- You verify the attestation before any data is sent, and keys are released only to attested workloads.
- You still trust the silicon vendor and the cloud's availability. You no longer trust its staff, hypervisor or host OS with your data.
- We'll tell you plainly where a platform's trust model differs. Some enclave technologies rely on the cloud's own signed hypervisor rather than on the CPU vendor, and we flag that in the design.
Hybrid
The best of both. Sensitive steps stay on your hardware, and heavy or bursty work runs on attested confidential capacity.
- A routing policy you can read decides where each request runs, based on data classification.
- No silent fallback. If the attested endpoint fails verification, the request stops. It never quietly goes to an unverified one.
Managed by Yaya Tech
Sovereignty as a service. We operate any of the above for you. You keep the root keys, our access is scoped and logged, and you can leave at any time. See Managed deployments.
Choosing
| If you need… | Start with |
|---|---|
| Nothing leaving your building | On-premises / air-gapped |
| Your own GPUs, but no data center of your own | Colocation |
| Cloud scale for regulated or proprietary data | Confidential cloud |
| Both, with different data classes | Hybrid |
| Any of the above without building a security-ops team | Managed |
Not sure? That's what the free call and the hardware and deployment plan are for. We compare the options on your threat model and your budget.