For organisations
ClawAI inside your own network
A private deployment of the whole platform on your infrastructure, running open-weight models on your own hardware. No prompt, document or conversation leaves your network — because there is nowhere outside it for them to go.
This is a scoped engagement, not a plan you can buy online. Cost depends on your hardware, your model requirements and how far the integration needs to go.
Last reviewed 2026-07-25
Who this is for
Organisations that want modern AI tooling but cannot accept sending their data to a third-party model provider.
- Government and public sector
- work covered by national data rules, where processing has to stay inside a designated boundary.
- Healthcare
- clinical notes, patient records and research data that cannot be handed to an external processor.
- Financial services
- positions, client files and internal models, where leakage is a regulatory event rather than an embarrassment.
- Legal
- privileged material and client confidentiality obligations that make third-party processing a non-starter.
- Defence and critical infrastructure
- classified or export-controlled environments, including networks with no internet egress at all.
- Data residency requirements
- organisations that must keep processing inside a specific country or region, and be able to prove it.
What a private deployment includes
The same platform described everywhere else on this site, deployed into infrastructure you control.
- The full platform
- all eighteen services, the databases, the event bus and the web app, deployed into your data centre or private cloud.
- Models on your hardware
- open-weight models served on your own GPUs. No external provider calls, no third-party processing, no egress required.
- Your identity provider
- single sign-on against your existing directory, with your groups mapped onto ClawAI roles and permissions.
- Your policies
- routing rules, retention periods, what may be uploaded and who may use which model, all configured to your requirements.
- Your audit trail
- every request, decision and administrative action recorded inside your environment and exportable to your existing log platform.
- Single tenancy
- a deployment dedicated to your organisation. Nothing is shared with another customer, because there is no shared instance.
The models we can run on your hardware
Open-weight families that run well on customer GPUs. Which specific models make sense is decided during scoping, because it is bounded by the memory and throughput you actually have.
Model families
- Qwen
- Strong general and coding models across a very wide range of sizes — usually the easiest family to fit to a given GPU budget.
- GLM
- Capable bilingual reasoning models with explicit thinking modes, at close to frontier quality.
- DeepSeek
- Mathematics, algorithms and step-by-step reasoning, with dedicated reasoning variants.
- Llama
- Widely deployed general-purpose models with mature tooling and predictable behaviour.
- Mistral
- Efficient models that punch above their size, useful when GPU memory is the binding constraint.
- Gemma
- Small, fast models well suited to classification, routing and high-volume everyday requests.
- Phi
- Very small reasoning-focused models that run on modest hardware, including edge deployments.
We size the model set against your actual hardware during scoping. A single workstation GPU and a rack of accelerators lead to very different answers, and we would rather tell you that before a purchase order than after one.
If some external models are acceptable
Not every organisation needs a fully closed deployment. Some are comfortable using external providers for low-sensitivity work and need isolation only for the material that matters.
That configuration is supported, with the boundary enforced by policy rather than by user discipline. Local is the default; anything else has to be explicitly permitted.
- Explicit allow-lists
- external providers are unreachable unless an administrator adds them. Nothing is enabled by default.
- Policy-driven routing
- rules decide what may leave — by user, by group, by content classification, by workspace or by conversation.
- Local by default
- if no rule permits an external model, the request is served on your own hardware. A misconfiguration fails closed, not open.
- Visible egress
- every request that goes to an external provider is recorded with who sent it, which policy allowed it and what left the network.
Hosted or private
Two different products for two different problems. Most organisations should start with the hosted app and move only if a requirement forces it.
ClawAI hosted
Sign up online, from $5 a month.
- Every frontier cloud model — Claude, GPT, Gemini, Kimi, GLM, Qwen, DeepSeek, Grok and Bedrock.
- Running in minutes. Nothing to install and no hardware to buy.
- New frontier models appear as providers ship them.
- Requests are processed by the model provider under their terms.
- Plan-based allowances, billed monthly or yearly.
ClawAI private deployment
On your infrastructure, scoped per engagement.
- Open-weight models served on your own GPUs. No external provider calls at all.
- Deployed inside your network, including networks with no internet egress.
- Your identity provider, your roles, your retention rules, your audit trail.
- Model quality is bounded by your hardware, not by the frontier.
- Scoped, deployed and handed over with our team.
The honest trade-off: a private deployment gives you complete data isolation and costs you access to the frontier models, which cannot be run on-premise at all. If your work does not require that isolation, the hosted app will give you better answers for less money.
What we do
A private deployment is a project, not a download. This is the work it involves.
- Deployment
- installing and configuring the platform on your infrastructure, around your networking, storage and GPU topology.
- Integration
- connecting your identity provider, your internal tools and any existing systems the platform needs to reach.
- Model selection and tuning
- choosing the model set your hardware can serve, benchmarking it on your actual workload, and configuring routing around it.
- Policy configuration
- access rules, retention periods, upload restrictions and, where relevant, the egress policy for external models.
- Handover
- documentation, runbooks and training, so your team can operate, upgrade and troubleshoot it without us.
- Ongoing support
- an optional support agreement covering upgrades, new model onboarding and incident response.
Compliance, stated honestly
ClawAI holds no compliance certifications today. Not SOC 2, not ISO 27001, not HIPAA. Anyone claiming otherwise on our behalf is wrong, and we would rather lose a deal than imply an assurance we do not have.
What we can do is describe the mechanisms precisely — encryption at rest and in transit, role-based access control on every endpoint, full audit logging, configurable retention, single tenancy — and let your security team assess them against your framework. A private deployment also removes third-party processing from the picture entirely, which is often the hardest requirement to satisfy any other way.
If your procurement process requires specific controls, evidence or contractual commitments, raise them early. We scope them per engagement, and we will tell you plainly when something is out of reach rather than letting you discover it during an audit.
How to start
Three steps, and the first one costs nothing but a conversation.
- 1
Tell us what you need
your constraints, the hardware you have or plan to buy, and what the deployment actually has to do.
- 2
We scope it
a concrete proposal: model set, infrastructure requirements, integration work, timeline and cost.
- 3
We deploy and hand over
installation, configuration, benchmarking against your workload, documentation and training for your team.
Tell us your sector, your constraints and roughly how many people would use it. That is enough for a useful first conversation.