Your data never leaves your business. We prove it.

Private AI, inside your own Azure tenant.
You're in control. Not your AI provider.

This is the managed tier: the same measured stack as our Private AI Appliance, engineered into your own architecture by us, then kept current for you. Your data never leaves the company, and you can audit the logs, the network traffic, the power button. You own everything, there's no upfront hardware, and you switch it off when you're done. Built in a day, then looked after.

On the demo we build one live, in front of you, and destroy it before we hang up.

Microsoft Partner

If your business runs on someone else's model, someone else holds your off-switch.

February 2026

The US government walked away from a leading AI model after a standoff with its provider.

June 2026

A frontier model was switched off overnight over a security issue. Not deprecated, switched off.

August 2026

Anthropic began embedding an invisible watermark in everything its new models write, worldwide. Text generated through a provider can now carry their mark.

Every day

Staff paste confidential material into public chatbots, banned or not. A ban isn't a plan. A private lane is.

The Managed Private AI Build

Everything below is deployed in one day, inside your own Azure account.

A private AI endpoint, in YOUR Azure account

Deployed into your own subscription, under your policies. Served by llama.cpp as standard, or we set up vLLM where your workload needs sustained throughput. It is your property. We hand over the keys.

Hardened by default

Isolated network, no public access, no outbound traffic, Microsoft Entra sign-in, spending cap, auto-destroy timer. We can tailor it to your architecture, or drop in our own landing-zone pattern.

A private service your security team can monitor

A safe place for the work your staff currently do in ChatGPT, banned or not.

Ephemeral by design

Spin it up, work on the sensitive material, destroy the whole system. Nothing left to breach, leak, or subpoena.

The right model, chosen with evidence

Picked from our own lab benchmarks, internal testing, and public benchmarks, not a vendor brochure.

Training, then the Care Plan

30-minute team session, the runbook, spin-up and tear-down scripts you keep, and the first month of the Care Plan, which is where the managing happens: tested model updates, quarterly zero-egress re-proof, and respins on us.

What managed means here

The build is one day. The looking after is the rest of it, and it is the part that keeps a private stack from quietly going stale six months in.

New models land tested, not hoped for

Open models move fast. We put each new release and each security update through our own benchmark before it goes anywhere near your box, so you are never the one discovering that an upgrade broke your workload.

Zero-egress re-proved every quarter

The signed proof pack is not a one-off. We re-run it quarterly against the live system and hand your compliance team a fresh signed report, because an assurance from launch day answers nothing about today.

Respins are part of the deal

A bigger box, a cheaper region, a different model, a new team: we do the work. Placement is our problem, and the map above is the data we do it from.

Managed, but still entirely yours

We look after the stack. We do not hold your data: inference never runs on Caleta infrastructure, there is no copy of anything on our side, and the system sits in your tenant under your policies throughout. If you ever want to take it in house, everything we deploy is already yours and the runbook is already written. The Care Plan is cancellable at any time, and the first month comes with the build.

The Zero-Egress Proof Pack

Every deployment ends with a live run on a confidential document while we capture the network logs, then a signed report showing no data left your tenant. Your compliance team keeps it. Your clients can see it.

Your clients are already asking what you do with their data and AI. Give them a better answer than “we banned it.”

In the pack:

  • Network flow logs from the live run
  • Hardening checklist, itemised
  • Architecture one-pager
  • Signed by the engineer who built it

We pick the model with evidence, not a brochure

The stack we deploy for you is the one we benchmark. Every model we would put in front of you has a published speed with the box and the date it was measured on, and the ones we have not measured say so rather than guessing.

If your use-case needs frontier-grade reasoning, we will tell you on the first call and save us both the pilot.

We place it. Here is what we place it on.

Choosing a region is not your problem on a managed build, but you should be able to audit the choice. This is the same placement data we use: every region a size is priced in, the regions the hardware actually exists in, and the ones we would pick, ranked on eviction risk then price. Updated daily.

Loading spot and hardware data for NC24ads_A100_v4...

If your data has to stay in a particular jurisdiction, use the sovereignty filter: that constraint drives the build, and we would rather find out on the first call than after it. The same view, with the full supported size list, is on VM sizes and regions.

A fixed price, agreed up front

Every build is different, so we scope it on the demo call and quote a fixed price before any work starts. No day rates, no open-ended engagement. US and EU companies welcome, invoiced in your currency.

  • Delivered in one day, in your own Azure tenant
  • You own everything we deploy
  • Zero-Egress Proof Pack, signed
  • Team training + 30 days of support
  • First month of the Care Plan included
The guarantee: you approve the signed zero-egress proof pack, or you don't pay.
Book the 15-minute live demo

The questions security teams ask

We already use Azure OpenAI / Copilot. Why this?
Keep them, for everything that can go there. This is the private lane for the material that can’t, and the fallback for the day a provider changes the rules. Twice in 2026 a frontier model became unavailable overnight. A model running in your own tenant, on weights you hold, cannot be switched off from outside.
Our provider’s enterprise terms already protect our data.
Perhaps. But your clients and your auditors ask a simpler question: can the data leave your tenant? With this, the answer is no, and we give you the network logs that prove it.
Are open models actually good enough?
For frontier-grade reasoning, not yet, and we will say so on the call if that’s your use-case. For document Q&A, drafting, summarising and coding assistance, the best open models are genuinely close to the frontier. Every model we deploy is measured on the exact image we ship; the model catalogue publishes the numbers. You choose with your eyes open.
We don’t have GPU quota in Azure.
You don’t need it. We can deploy a CPU-only configuration the same day (including on Azure Cobalt Arm sizes, which rarely have quota issues), or a low-cost GPU slice, and upgrade when your quota lands. Quota is never the blocker.
Our security team will want to review it.
Good. Everything lands in your tenant under your policies, and we bring a one-page architecture and hardening checklist for their review. If you prefer, your engineer runs our deployment while we direct on a screen-share, and we never touch your environment at all.
What does the fixed price assume?
That your side is ready: a subscription and empty resource group, access agreed (a one-day Contributor role, or your engineer runs our deployment on a screen-share), and any internal approvals already done. Our pre-flight checklist covers it, and most companies clear it in one short call. If your change process needs security reviews, architecture boards, or bespoke integration first, that is a different engagement, and we will say so on the demo rather than surprise you later.
Are you insured?
Yes. £5M professional indemnity cover, and we work under a signed order form with the guarantee in writing.
What happens after day one?
The Care Plan starts, and that is the managed half: we test new models and security updates on our own benchmark before rolling them to you, re-prove zero-egress quarterly for your auditors, and do the work on any respin. The first month comes with the build and you can cancel at any time. If you would rather take it in house, you can: it is your property, and it ships with the dashboards, the runbook and the spin-up and tear-down scripts. Both are fine by us, which is why we sell it either way.

Prefer to run it yourself? The same private AI as a ready-to-deploy Azure Marketplace image.

See the Private AI Appliance

Want the evidence first? Every model we deploy is benchmarked on real Azure VM sizes.

Browse the measured catalogue