On-prem AI Controller. Coming soon.
Your AI, on a box you own.
Every employee gets their own private AI Host, running on hardware in your building. Their laptops pair with the appliance. Their files stay where they are. You decide which models run locally and which requests are allowed out.
Privatae supplies the image, the updates and the certificate authority. Your hardware reseller supplies the server. You supply rack space, power, an uplink and the identity provider your people already sign in with.
Two sizes, one image
Single Node
One server for small and mid-size teams.
- Form
- One server. Rack-mount, or a tower for offices with no rack.
- Grows by
- Replacing the server.
- If it fails
- Restore the image, restore the snapshot. Storage is mirrored on the box; snapshots go to a target you supply.
- GPU
- One card for local inference. A no-GPU option for teams that route to a provider.
Cluster
Three or more servers on one rack, for organizations that need to grow without replacing the box.
- Form
- Three servers to start, the same class as the Single Node. Add one at a time.
- Grows by
- Adding a server and running the join command.
- If one fails
- The cluster stays up. The control plane runs on the first three.
- GPU
- Any number of GPU servers, added separately. Inference scales on its own.
What every appliance includes
- The appliance imageA scripted install that turns certified hardware into a working controller. On the Cluster it installs the control plane on the first three servers and joins the rest.
- A private AI Host for every employeeEach person gets their own Host with its own memory, its own tools and its own storage allocation. Hosts are isolated from one another on the appliance.
- The bastion agent on every employee machineTheir laptop or workstation pairs with the appliance. Their files stay on their machine; the Host reaches them through the pairing, never through a copy in the cloud.
- Model choiceRun models on the appliance's own GPU, or route to an outside provider through the appliance's egress controls. You decide, per Host, which is allowed.
- The certificate authorityPrivatae issues the certificates that make the appliance trust its own users and machines. Revoke, rotate and renew without running your own public-key infrastructure.
- Signed updatesImage updates are pulled by the appliance on your schedule. Nothing is pushed without your approval window.
Certified hardware, through your reseller
We publish a certified hardware list: exact servers and configurations the image is tested on. Your reseller sells you one of those. We never ship hardware ourselves, and the image is not supported on hardware that is not on the list. Server-class parts throughout: ECC memory, mirrored NVMe storage, two network ports so management traffic is separate from your people's traffic, a management controller for remote recovery, and a TPM for measured boot of the signed image.
The list, the ship date and the sizing guidance are published when a real unit has been through certification. Until then this page names the class of machine and not the part number, on purpose.
It does not send your data anywhere. The appliance has no path to Privatae except the one it uses to pull signed updates and renew certificates, and you can watch that path. There is no telemetry subscription, no usage reporting, and no per-token charge. If you route a Host to an outside model provider, that is a decision you make in the appliance's egress rules, per Host, and one you can reverse.
Tell us about your environment
The form asks what we would have to ask you anyway: where the appliance would live, how your people sign in, whether outbound access to model providers is allowed, who manages your IT, and who you already buy hardware through. Answer what you can. It commits you to nothing, and we will come back with whether the Single Node or the Cluster fits and when it ships.